Showing posts with label Wireless Security. Show all posts
Showing posts with label Wireless Security. Show all posts

How Likely Are You For Wi-Fi Theft?

Wi-fi theft, as in the act of stealing someone’s internet connectivity by breaking into a wireless network, has been around ever since we first started using wireless routers.

Before covering the topic of how likely you are for wi-fi theft, I’ll first say that wi-fi security has never been that good. If one is desperate enough to steal your signal, there’s always a way. After all, anything that is transmitted can be intercepted. And as far as cracking the password is concerned, it truly is not that difficult given the right tools.

The best way to protect yourself from wi-fi theft is to:

  1. Know your wireless router’s admin program thoroughly.
  2. Take steps to be less of a target.

Know your wireless router’s admin program thoroughly

Login to your admin program via the web browser for your router and go thru every setting so you get familiarized with what you can do in there. Then follow the steps below.

Remember that for every wireless router manufactured there is a downloadable PDF manual for it (as far as I know) if you lost your printed copy. Perform a Google search for your make/model of router with the word "manual" in the search term and you should be able to locate the PDF version easily.

Taking steps to be less of a target

Use WPA2 if available with a long password

The WPA2 access password can be up to 63 characters long. If you use a long password with mixed case letters, numbers, spaces and symbols, it will be very difficult to "brute force" the password out of it.

Limit connectivity to specific MAC address(es)

This is usually labeled as MAC Address Filtering within the admin program. Every modern network card has a MAC (Media Access Control) address. If you limit allowed clients to specific MAC addresses, this greatly decreases the chance of wi-fi theft.

Most wireless router admin programs allow you to directly copy the MAC address from the connected PC into the allowed client list, so there’s usually no copy/paste involved.

Note: If you use virtual PCs, they have virtual MAC addresses that the router considers real. If setting up MAC address filtering, include your virtual machines as well.

Additional note: MAC addresses can be spoofed. But someone would have to specifically know one of the allowed MAC addresses in your wi-fi network and apply it to their computer in order to break in.

Limit number of connections

If you have three computers in your house and only allow for three assigned IP addresses via the router, the only way another system can get in there is to kick one off the network first.

Once again, be mindful of virtual PCs if you use them, because they use literal IPs (if network enabled); each counts as a separate unique network connection as far as the router is concerned. If you have three real PCs and two virtual ones that are network enabled, you will need to have your router be able to assign 5 IP addresses.

Do not allow remote administration

All wireless routers to the best of my knowledge come with this feature disabled by default, so you shouldn’t have to worry about it.

Other questions answered

Does IP Lease Time affect security at all?

No. My only suggestion would have the Lease Time not set to "forever", especially if you have people in and out of your house using the wi-fi routinely. This is done strictly for convenience’s sake. Some of you out there may prefer to have IPs cleared from the DHCP list, especially for temporary assignments (such as a friend visiting and using his or her wi-fi enabled laptop).

Does disabling the broadcasting of the SSID help?

It does offer a little bit of extra security, but MAC address filtering is much more effective.

Will periodically changing my SSID deter break-ins to my wireless network?

Not really, because all that has to be done is a re-scan of the available networks.

I do, however, suggest a non-generic name to make you less attractive as a target. For example, many people have Linksys routers simply labeled as "linksys". This literally announces, "I never changed this setting in my router", and that’s not good.

At least with a custom name, whoever is trying to break into a wi-fi network will target the "easy looking" ones first, and that includes SSID names like "linksys", "belkin" and the like.

Final notes

Taking action to be less of a target is your best defense against a wi-fi break-in.

Of course, the best defense is simply shutting the router off when not in use. This may be inconvenient, but nobody can break into your network via wireless if the router is off.

Four wireless security tips to share with clients

Susan Harkins says you should help your clients protect their wireless access. She offers four simple mandates that can go a long way.
—————————————————————————————————————
You probably work hard to protect your clients’ networks, but wireless technologies take security to a completely new level — a lot of which is out of your control. Your best efforts simply aren’t enough.
If your clients are going to utilize wireless technologies, they need knowledge, and they need to take responsibility for engaging that knowledge. You can’t promise them 100% protection, 100% of the time, but you can help them help themselves. Most likely, they’ll be connecting hardware at will without your guidance. When they do, they should follow these four security measures.
#1: Use encryption codes
Encryption codes won’t stop a dedicated hacker, but they’ll send most packing without even trying. Instruct clients to enable encryption on all new Wi-Fi products when prompted during installation.
#2: Change passwords
Most new equipment relies on a built-in, default password for installation. Clients should immediately change the default password after installing the equipment. Then, they should send the username and password to their in-house administrator or you, as appropriate.
#3: Enable firewalls
Clients with a bit of knowledge can disable a firewall — which is a perfect example of a little information being dangerous in the wrong hands. Enable the firewall and check it often. Better yet, have the system alert you if someone attempts to disable it or actually does so. Tell clients not to disable the firewall without your knowledge. Good luck enforcing that, but try just the same.
#4: Restrict outside equipment
This item gets boos and hisses — you just can’t please everyone all the time! Honestly, you don’t want to tie anyone’s hands, but wide-open Wi-Fi is dangerous. Totally block unknown devices from sharing access. Initially, the setup will take a bit of time, but it’s worth it. Force clients to contact you when they want to access the network via new equipment.
Now, in a perfect IT shop, you’d be in total control, and there’d be no problem, but we all know that’s seldom the case. With a little education, you can help users avoid security mishaps where wireless access is concerned.
What are you doing to educate your users with regards to wireless security?
Get weekly consulting tips in your inboxTechRepublic’s IT Consultant newsletter, delivered each Monday, offers tips on how to attract customers, build your business, and increase your technical skills in order to get the job done. Automatically sign up today!
Susan Sales Harkins is an IT Consultant, specializing in Desktop Solutions. Previously, she was Editor in chief for The Cobb Group, the world's largest publisher of technical journals.

 
 
 
 
Copyright © PcBerg