Open Wireless and the Illusion of Security

he will kill u

Secure: one-time pads are crackable in reality… just not in theory. :slight_smile:

its as good as it gets tho afaik, you are right.

you need to transmit the decoding info… how does that get encrypted? with another one time pad? ad infinitum…

i take that back. cos i just showed how its crackable in theory. nm, eh?

reductio ad absurdem. :slight_smile:

I never thought my security was strong. I see it like a lock ona door. the determined hacker can force it open but the passerby will not try not knowing the risks involved. of course if the door is wide opened well I am kind of asking for people to come in and take what is mine. In this case my capped bandwidth. And since all my neighbors have default named networks I am not worried.

If I wanted it to be better I’d set something to attack back at intruders, like an alarm system or a guard dog. As they say if they come in my house uninvited I have the right to shoot then ask questions.

A true one time pad is actually 100% unbreakable. The problem is meeting the conditions for OTP… truely random, only used once. And, of course, the biggest problem is key distribution. If you have a secure channel for delivering the key, why not just deliver the message over that channel?

An open network is still worse than a WEP-protected network. If your neighbor finds your network asks for a password, he probably won’t try to crack the encryption. He will try another of the 20 wireless networks in the neighborhood, and quickly find an idiot who left it open. Simple.

I recently went near a friend’s house, grabbed my iPod touch, connected to his completely open wireless network, connected to MSN Messenger using a web-based service, and told him hey look out the window. That was fun :slight_smile: Now, imagine it was WEP-protected, with a password of ā€˜qwerty’. No wireless-cracking software for the iPod touch; and I wasn’t about to start bruteforcing by typing passwords on the tiny keyboard.

@GuiguiBob:

…I have the right to shoot then ask questions.

In your fucked-up war-centric country, maybe.

Oh and I recently had somebody get into my open network (I used to have it secured, but changed router and forgot to re-secure). I just got into his Windows shared folders, deleted everything I found, then set up MAC filtering. There’s still no password, and I haven’t had another intruder since.

I’d have more fun if I was using an old Linux computer as wireless AP instead of an off-shelf router with an antenna on it. You know, like redirecting all HTTP traffic to goatse.

I would have to disagree that WEP or any encryption protocol is the same as having an open network. Unless you live in a neighborhood that is super rich in knowledgeable hackers, chances are pretty small that anybody is going to crack your WEP.

Obviously a better protocol is going to be… better… but any basic security protocol is going to stop most of the people who would steal your bandwidth, which makes it much better than none at all.

I do not do networks. They move data faster than I can think and that slows down my writing. No wonder I am still in the fascicle mode after 25 years of longhand.

thoughts?

I use a 63-character WPA2 passphrase. Yeah, keying that into my Wii wasn’t much fun.

here is a fun solution to wireless security…

Foil Wireless Poachers and Have Fun Doing It
January 9, 2007
By Carla Schroder

http://www.enterprisenetworkingplanet.com/netsecur/article.php/3653006

@Jesper - While the default version of XP does not connect to WPA-2, that functionality can be added with a download from MS (http://support.microsoft.com/kb/893357).

I have no doubts that my network is breakable. However, its not going to be easy for the average joe/jane who lives in/around my network. I have 2 routers, 1 wired (hardware firewall with deep packet inspection) only and 1 wireless only. I use MAC filters, limited IP’s, static IP’s, Isolation (no wireless device may talk to another wireless device which is not a problem in my network), 40 key WPA-2 Personal and lastly, I turn off wifi when I’m not using it. Yeah, I pull the power cable out. Tada!

Of course if the router has a security flaw then all this amounts to zilch.

@Nicolas

too bad that’s what you got out of my post, what I was meaning to say is we aren’t taking the right approach to network security…

to expand my metaphor, if we built houses like we want to build our networks we would end up with a immense door with an unbreakable lock, of course they’ll be able to go through the window. What we need is a way to be notified when someone want to enter the network and say yes or no (go awnser the door). next we need an alarm system when we’re not there or a guard dog that would attack the intruder trying to sneak in. we end up by placing sticker warning people that if they enter they will trigger our alarm system and open themselves for retaliation. We know this won’t be able to deter the best hackers in the world but as always it is a matter of how much is your security worth.

re: Peopleware vs TAOCP

Peopleware is about a much more important (and under-explored) topic than TAOCP, but Knuth rules my heart 4-ever. TAOCP is placed in relation to its subject a better book. I long for the TAOCP-level book about social processes. That’s not intended to knock Peopleware.

re: WEP vs open

I’ve shamelessly piggybacked on open networks but WEP, if nothing else, gives the hint that the person didn’t intentionally leave the network open. It’s a flimsy, unglued envelope vs a postcard.

I just use WEP and turn of SSID for a little extra security, mainly because I have a couple of computers with old wireless cards that don’t support anything but WEP. I also have all my machines in a domain with strong passwords.
I don’t worry much about getting hacked, especially after I realized that four of my neighbors have completely open WiFi routers happily broadcasting themselves everywhere. I figured a hacker would just hop on one of theirs instead of bothering to look for mine.

Nicolas -

re: …war-centric country… - which of the countries that our bleeped-up country sacrificed lives and treasure to safeguard/liberate do you come from?

How much of your nation’s treasure did not go into fending off Soviet aggression in the second half of the 20th century?

I desperately want to protect the thin sliver of upstream bandwidth my provider allows me.

You know there’s this thing called QoS…

Most people use passwords. Some people use passphrases. Bruce Schneier uses an epic passpoem, detailing the life and works of seven mythical Norse heroes.

Nicolas,

I think you are wrong. While I am not personally a fan of guns, I completely agree with the idea that, if someone is busting into your house, you can assume they are malicious and possibly intent on killing you. Shoot first is a reasonable policy in that instance. A security response should be appropriate for the level of threat.

That’s the house though. A wireless network is different.