Sunday, March 16, 2008
WEP is worthless. Don't use it.
Is WEP wireless security better than no security at all? Probably, but not by much. Don't use WEP for Wi-Fi security, researchers say. It will prevent casual crackers from hacking into your network as they drive by, but if they stop for a traffic light, or to roll down the window and point the Pringles can at your WiFi router, they are in.
Instead, use WPA security to encrypt your wireless traffic. For details, see my post on How To Secure a WiFi Router for the Best Wireless Security. To better understand what all the letters & numbers mean (WPA, WEP, PSK, 802.11b, etc.), see Keith's post on 802.11 Alphabet Soup.
Connect a Mac (Tiger 10.4) to a WPA Wireless Network
In my previous post, I reviewed the best settings to secure my wireless network. Now it's time to connect my Mac laptop, gforce, running Tiger (OS X 10.4.11), to my WiFi (802.11g) wireless network. Boot up, and follow these steps:
The Closed Network dialog. Enter the SSID here.

After you select WPA, you can enter the password.

Tips
- Turn on AirPort. I use the AirPort menu to do this, on the right side of the menu bar. The "fan" icon changes from a hollow outline to grayed-out "radio waves".
- Select Other... network from the AirPort menu. This is required because I turned off SSID broadcasting when I secured my WiFi router.
- In the Network Name field, type the secret but memorable SSID.
- Select WPA Personal from the Wireless Security drop-down menu. Note: the specific WPA security protocol is set by the wireless router; you need to match the setting on the router with this menu pick.
- Enter your fearsomely strong password. Tip: unless you think someone is spying on you with high resolution optics, you can check Show password. It certainly reduces the typos.
- Click [OK].
The Closed Network dialog. Enter the SSID here.

After you select WPA, you can enter the password.

Tips
- If you can't see the AirPort menu, you can turn it on here: System Preferences > Network tab; select Show: AirPort; check Show AirPort status in menu bar.
- Also, while you are making changes to the AirPort preferences, you should consider selecting By default, join: Preferred networks. If this doesn't work as expected, select the line corresponding to the SSID you selected, move it to the top of the list, and click the [Edit...] button to ensure the WPA password is set correctly.
- If you think you might be having problems with interference or a poor signal, perform these steps right next to the wireless router to bathe your AirPort card in the strongest signal possible..
- Save your WPA password in your Keychain, where it will be safely encrypted, so you don't have to enter it every time.
How To Secure a WiFi Router for the Best Wireless Security
What is best setting to secure my wireless network? What's the safest way to secure my Wifi enabled router? The steps below describe what to do for most routers that support WiFi 802.11g or better.
- Connect your network, wired only: connect the router to your (cable/fios/phone) modem, which is of course connected to your ISP's wire. Note: in some case, the router & modem are the same device. Connect a properly-configured computer to your router, probably with a Cat-5 Ethernet cable. Check the LEDs on the computer, router, & modem, if required.
- Boot up and open a browser. Can you connect to the Internet? Test with a quick trip to your favorite search page. If you can't connect wired-only, you'll never get the wireless working!
- Log into your router's web interface using your web browser. If you know your computer's IP address, the router is usually the same address, except the last number after the right-most dot is a "1" -- for example, 192.168.2.1 (the 1 at the end is your router's address in your LAN's address space).
- Enter your password to access your router's administrative features. If you didn't need a password, or you used the default password, change it now to a safe password!
- Go to the Wireless section on your router's administrative pages. Your browser may use different terms, like WiFi instead of Wireless.
- Change the SSID (or Network Name) to something memorable, besides the default. This isn't a password, so you can use the name of your dog, or other dictionary words. If someone guesses this, they still have to get past your impossible to guess password to use your WPA network.
- If possible, turn off the option to broadcast the SSID.
- Apply or Save the changes. For my Belkin router, that means the router needs to reboot and I have to log in.
- Select WPA as your security/encryption mode (also WPA2-Personal PSK)
- I recommend WPA-PSK authentication & TKIP encryption. Make sure these selections are compatible with your wireless card (AirPort for Macs).
- Set an fearsomely strong password.
- Save/Apply your changes.
- Turn off remote management. If you turn this on, chances are that you will be owned eventually.
- Turn off UPNP (Universal Plug 'n Pray -- I mean, Play). If one of your devices requires this, your network can't be considered secure.
Wednesday, March 12, 2008
Wireless hack = heart attack
Worried that your notebook is vulnerable to wireless hackers? Did you feel like you were having a heart attack when you realized that hackers had gained access to your gmail account? At least it was just a feeling, and not the real thing. But not for long: according to the New York Times, A Heart Device Is Found Vulnerable to Hacker Attacks. The researchers "were able to reprogram it to shut down and to deliver jolts of electricity that would potentially be fatal — if the device had been in a person" -- people like Vice President Dick Cheney, who is one of the most notable users of the Medtronics device.
Fortunately, you don't need a Secret Service detail equipped with WiFi jammers and automatic weapons to protect you from this threat. "The experiment required more than $30,000 worth of lab equipment and a sustained effort by a team of specialists" and the equipment used for the hack had to be within two inches of the pacemaker -- basically, you'd have to press it against the victim's chest to be within range. If you got that close, more traditional methods of interrupting the victim's heartbeat might be utilized.
This is, however, a perfect example of how:
- Wireless transmission capabilities, with connections to the Internet, are appearing in all kinds of devices, and not just your laptop/cell phone/PDA.
- No one is thinking about securing these devices.
Thursday, March 6, 2008
Wireless Trends for 2008
For some great information on 802.11n and other wireless trends, AirWave's webcast Wireless Trends 2008 - What You Need to Know is available on Airwave's Webcast Library page.
Some highlights from the webinar:
- 802.11n will be ratified in Q3 of 2009
- It's safe to purchase 802.11n devices now. These devices will "with just the slightest doubt" be compatible with the final standard.
- With 802.11n, you can expect performance of 4-6x times that of 802.11g
- Note that Gigabit Ethernet is a requirement, otherwise your wired LAN will be slower than your wireless link.
- There will be no need to replace your 802.11g equipment
- Don't try to run 802.11g and 802.11n at the same time in the same channel
Mobile Smartphone Users Targeted by Trojans
McAfee has an article on Symbian mobile users in China being targeted with a Trojan that targets users of the QQ network. (QQ is a very popular Instant Messaging network in China).
McAfee notes that the Trojan contains a number of different pieces of malware. Also, they note that it was written to make a profit, not to forward the notoriety of the hacker.
McAfee also has some information on a Trojan targeting Windows CE devices that was recently discovered as well. The software, WinCE/InfoJack, was created to report information about the phone's OS and version back to a website. It also disables some of the phone's security, allowing unsigned applications to install without warning.
With the growing popularity of smart mobile phones, this activity will only increase. Users should be careful where they download software and applications from. If you get any suspicious SMS messages to your phone, don't start clicking the links.
Subscribe to:
Posts (Atom)