PDA

View Full Version : Secure your wireless network


Mr. Natural
April 14th, 2004, 05:33 pm
Your wireless network is wide open to anyone passing your home unless you secure it.
Linkage:
http://www.extremetech.com/article2/0,3973,1312950,00.asp
http://www.practicallynetworked.com/support/wireless_secure.htm

This is from a microsoft web site:

SUMMARY
Wireless networks can be vulnerable to a malicious outsider gaining access because of the default settings on some wireless hardware, the accessibility that wireless networks offer, and present encryption methods.

The concepts that are presented in his article are general suggestions, and may help make your wireless network more difficult for a malicious outsider to gain access. For more specific information about the implementation of these suggestions, see the documentation for your wireless network hardware or contact the hardware vendor.

The 802.11b standard permits Wired Equivalent Privacy (WEP) encryption. Depending on the manufacturer and the model of the network adapter and access point, there are two levels of WEP typically available: 64-bit encryption based on a 40-bit encryption key, and a 24-bit initialization vector, and 128-bit encryption based on a 104-bit key and a 24-bit initialization vector. In addition to enabling WEP, there are other steps that you can take to make your home local area network (LAN) more secure.
MORE INFORMATION
Making your Wireless Home Network More Secure
Enable the highest level of WEP that your hardware provides. WEP provides some security and is effective in deterring casual attempts by outsiders to infiltrate your network. Most 802.11b certified products can use basic 64-bit WEP encryption. By default, however, 64-bit WEP encryption may be disabled.
Change the default Service Set Identifier (SSID) and passwords for your network devices. Access points/wireless routers ship from the manufacturer with default SSID and passwords which is the same on all devices made by that manufacturer. Leaving these at default makes it easy for a malicious outsider to gain access.
Do not change the SSID or password to reflect your name, address, or anything that would be easy to guess. Use upper and lower case letters, numerals and symbols for the password, if the hardware supports this.
As you survey your home for access point deployment, think about locating the access point toward the center of your home instead of near the windows. Plan your coverage to radiate out to the windows, but not beyond. If the access points are located near the windows, a stronger signal will be radiated outside your home making it easier for those outside the building to locate your network.
Take a notebook computer that is equipped with a wireless network adapter, and go outside your home and survey what range you get in moving around your property or neighborhood. You may be surprised how far the signal radiates. If you can connect from three or four houses away, so can someone else.
Some access points allow you to control access based on the media access control address of the network adapter trying to associate with it. If the media access control address of your adapter is not in the table of the access point, you will not associate with it. If your access point has this feature, enable it and add the media access control addresses of the network adapters you use.
If your access point is also a wireless router, think about assigning static IP addresses for your wireless adapters and turn off DHCP. By not automatically assigning IP addresses to clients who access the network, it makes it a little more difficult for an outsider to gain access. Also consider changing the IP subnet to a different subnet that does not route on the Internet. Many wireless routers default to the 192.168.1.0 network and use 192.168.1.1 as the default router.
Purchase access points and network adapters that support 128-bit WEP. Some products only support 64-bit (40 bit key) WEP, and are not as secure. Note that some adapters may only require a driver upgrade to attain 128-bit WEP capability.
Purchase an access point that has a flashable firmware. There are a number of security enhancements that are being developed, and you want to make sure that you can upgrade your access point as these become available.
Some products support additional security features that are either not defined by the 802.11b standard, or not mandated by the standard. Products that use a propriety security method will only work with products from the same manufacturer, but can enhance the security of your network.

brepurbuche
December 7th, 2009, 08:37 am
Either way, getting a cheap linksys router with the option for either is the way to go. Its as simple as plug and play if you just want an open network. Unless you have douchebag neighbors stealing internet from you theres really no reason to have an encrypted home wireless network anyway.

shizakapayou
December 7th, 2009, 12:31 pm
That's terrible advice - it takes minimal effort to secure your wireless network and can save you lots of trouble later on.

Also, note this thread is ancient, so while the original advice was good at the time, things have come a long way. Don't use WEP for anything these days.

mandrake
December 7th, 2009, 09:55 pm
no doubt.
I think I'm using WPA2 Personal.
There's only one home network I set up with no security and that was my parents, who live so far back in the sticks that they have no neighbors within a mile to steal their internet anyway!

shizakapayou
December 8th, 2009, 08:46 am
Yeah, I did the same with my parents - no house close enough, if someone is close enough there are bigger problems and the dog's probably out there killing them for it. I'll probably add it sometime just because I don't like leaving it open.

Rob
December 8th, 2009, 10:09 am
I have stolen internet on a few occassions. Not drive around until I find something, but when we have moved to a new apartment and I was waiting for mine to be connected, I would hop on, and when I visited the inlaws before they had their own. When I was living in the dorms, it was just a matter of hitting the network button in the Start Up menu to enter hundreds of unsecured computers. I started placing a READ ME for INTERNET SECURITY file in their documents folder with detailed instructions on how to protect their PC. Not sure if anyone did it.

Even out in the country Mandrake, I would still set up a secure network. Not like it would hurt anything.