WEP, WPA/WPA2, and the associated authentication methods are designed to keep invaders out. However, it has become increasingly easier to crack WEP encrypted networks and cracking WPA/WPA2 networks is difficult, but feasible. These methods help keep external users from being able to access sensitive data, but what about internal, authenticated users?
Internal wireless security is important when utilizing networks of hundreds of users. Say I have a WPA2 AES encrypted network. A normal user will connect to the network and be granted access to the internal wireless network. Unlike wired networks, wireless networks do not have switches to direct traffic to the right ports (users), therefore, every authenticated user can see everybody else's traffic. Now, with a network of hundreds of users, this can pose a problem. Once somebody is authenticated, they are free to sniff traffic, perform man-in-the-middle attacks, etc. It doesn't matter what encryption method (WEP, WPA/WPA2) was used because each authenticated user is using the same key as everyone else to encrypt their data.
For example, many universities are now creating wireless networks around campus which hundreds of students may be connected to simultaneously. What is preventing one student from logging onto the wireless and sniffing all traffic from the gateway until he gets some passwords? Information like that can be used to access someone's email account and once your email account is compromised, you're hosed (hint, "Forgot Password?")
The standard solution to this problem is VPN tunnels. Here's an example, a user joins an open access point provided by the company. When he opens his browser, he is redirected to a page where he needs to download and install the VPN client. After installation, the user will login and the VPN client sets up an encrypted, independent tunnel. Now, he is safe from both external and internal hackers because every bit of his data goes through this tunnel and is encrypted. You could do a man-in-the-middle attack, but all you'll get is encrypted packets.
However, the implementation may not be an option for universities or companies who give 2 cents about user friendliness. Establishing a VPN tunnel requires a client program. That's one more program users need to install on their computers; one more program that users DO NOT want to install. Not only that, the VPN client is yet another product the IT department must support and it also creates an additional level of failure. Some product's installation procedures are less than stellar and can cause more headaches than smiles. You also have to look at how easy it will be to implement over the existing system, support options, delivery of the client, and finally, compatibility. With Windows Vista and it's dreaded UAC, installation of a VPN client has become even more of a hassle that some vendors are trying to overcome for the sake of user friendliness.
A simple solution would be to issue different, unique keys to each user. This encrypts their data with different keys and would act like a VPN tunnel. You could "MacGuyver" it and create an access point with a different key for each user, but that relies on IT "manual labor" and is vastly inefficient. However, if each user got a different key, there would be no client program (a plus for user friendliness) and no additional hardware needed if the software lies on the access point or controller.
Visit http://www.IsYouGeekedUp.com for more details
AP - Dead is the word when "The L Word" returns.
Jul 8, 2008 Jul 9, 2008 Jul 12, 2008 Jul 13, 2008 Jul 15, 2008 Jul 16, 2008 Jul 19, 2008 Jul 22, 2008 Jul 26, 2008 Jul 29, 2008 Jul 30, 2008 Jul 31, 2008 Aug 1, 2008 Aug 4, 2008 Aug 6, 2008 Aug 9, 2008 Aug 13, 2008 Aug 14, 2008 Aug 15, 2008 Aug 17, 2008 Aug 19, 2008 Aug 22, 2008 Aug 24, 2008 Aug 26, 2008 Aug 31, 2008 Sep 2, 2008 Sep 4, 2008 Sep 5, 2008 Sep 6, 2008 Sep 7, 2008 Sep 8, 2008 Sep 9, 2008 Sep 13, 2008 Sep 14, 2008 Sep 19, 2008 Sep 21, 2008 Sep 22, 2008 Sep 23, 2008 Oct 2, 2008 Oct 3, 2008 Oct 6, 2008 Oct 7, 2008 Oct 8, 2008 Oct 9, 2008 Oct 10, 2008 Oct 11, 2008 Oct 12, 2008 Oct 13, 2008 Oct 14, 2008 Oct 15, 2008 Oct 16, 2008 Oct 17, 2008 Oct 18, 2008 Oct 19, 2008 Oct 20, 2008 Oct 21, 2008 Oct 22, 2008 Oct 23, 2008 Oct 24, 2008 Oct 25, 2008 Oct 26, 2008 Oct 27, 2008 Oct 28, 2008 Oct 29, 2008 Oct 30, 2008 Oct 31, 2008 Nov 1, 2008 Nov 2, 2008 Nov 3, 2008 Nov 4, 2008 Nov 5, 2008 Nov 6, 2008 Nov 7, 2008 Nov 8, 2008 Nov 9, 2008 Nov 10, 2008 Nov 11, 2008 Nov 12, 2008 Nov 13, 2008 Nov 16, 2008 Nov 17, 2008 Nov 18, 2008 Nov 19, 2008 Nov 20, 2008 Nov 21, 2008 Nov 22, 2008 Nov 23, 2008 Nov 24, 2008 Nov 25, 2008 Nov 26, 2008 Nov 27, 2008 Nov 28, 2008 Nov 29, 2008 Nov 30, 2008 Dec 1, 2008 Dec 2, 2008 Dec 3, 2008 Dec 4, 2008 Dec 5, 2008 Dec 6, 2008 Dec 7, 2008 Dec 8, 2008 Dec 9, 2008 Dec 10, 2008 Dec 11, 2008 Dec 12, 2008 Dec 13, 2008 Dec 14, 2008 Dec 15, 2008 Dec 16, 2008 Dec 17, 2008 Dec 18, 2008 Dec 19, 2008 Dec 20, 2008 Dec 21, 2008 Dec 22, 2008 Dec 23, 2008 Dec 24, 2008 Dec 25, 2008 Dec 26, 2008 Dec 27, 2008 Dec 28, 2008 Dec 29, 2008 Dec 30, 2008 Dec 31, 2008 Jan 1, 2009 Jan 2, 2009 Jan 3, 2009 Jan 4, 2009 Jan 5, 2009 Jan 6, 2009 Jan 7, 2009