Open Wireless and the Illusion of Security

WEP, the original encryption protocol for wireless networks, is so fundamentally flawed and so deeply compromised it should arguably be removed from the firmware of every wireless router in the world.
The MacBook Air has firmware support for booting over wireless, and no it does not have WEP support, only WPA and WPA2 are supported.

gex wrote:
Shoot first is a reasonable policy in that instance

Unless it happens to be somebody you know and merely mistake for a robber, which is probably a more likely scenario, given the number of people you know and the number of robbers you expect.

You have to love how the Nintendo DS only supports WEP :frowning:

http://www.joystiq.com/2005/10/16/nintendo-ds-wi-fi-uses-obsolete-wep-security/

If all cars have no locks, then your car with a lock is much less likely to be stolen
If all cars have locks, then your car with an alarm is much less likely to be stolen
If all cars have alarms, then your car with an immobiliser is much less likely to be stolen
If all cars have mechanical locks, then your car with a electronic immobiliser as well as a lock, means that the only way to steal your expensive, new car is to hit you very hard and take the key.

You’re actually less safe this way ;). It’s all a matter of security/convenience and every individual has to make their own call on it.

I profoundly disagree with the proposition that given a sufficiently motivated attacker, every wireless network is crackable. This might be true with any implementation of WEP, or a hashed-passphrase variant of WPA (although WPA is optimized against passphrase-guessing attacks), but if you use a proper 256 bit randomly generated key (the 64 hexadecimal digits variant in your wifi network setup) that simply isn’t crackable with today’s technology. So long as no breaks in AES exist, an exhaustive search through a 256 bit keyspace simply isn’t possible with any conceivable technology current or future.

Of course, if you said a sufficiently motivated attacker will find some kind of way into your network this is more likely to be true – but if you use the strongest variant of WPA, this will involve techniques like bugs and breakins, not subverting the security of your encryption itself. All the indications are that WPA does what it says, and secures your network.

Pardon my ignorance, but wouldn’t mac address white-listing be a good enough solution together with WPA encryption? Granted WPA can be brute forced, and a mac address can be spoofed, but it would take a very good ammount of resources, time and well crafted social engineering to get to base with all of the above. If your connection and data roaming within is so important, then don’t use wireless altogether!

@Michael

I agree with Jeff on this one. The greatest algorithm in the world won’t save you from a team where everyone hates each other.

The dirty secret of this industry is that a well gelled team of the much maligned mediocre developers will totally outclass a team of geniuses that can’t work together.

Simon.

But what about those of us who do have something to hide? I work mainly as a consultant, and my clients would not be pleased to hear that I’m handing their confidential data over to random people who have no particular obligation to protect it, much less the skills to keep it safe. In fact, they could sue me for that, and probably win.

That aside, everybody has something to hide. We all almost certainly have stuff on our HDDs that law enforcement or others could use to prosecute or sue us, should they really want to. It’s the nature of life. Law enforcement being ‘fair’ depends much more on discretion than you seem to think it does. Ask any lawyer and they’ll tell you that that’s a very strong reason not to go around giving them the ability to come after you.

1 Like