Re: ALERT: WPA can be less secure than WEP



On Fri, 27 Jan 2006 09:32:38 -0800, in alt.internet.wireless , Jeff
Liebermann <jeffl@xxxxxxxxxxxxxxxxxxxxxx> wrote:

(don't get me wrong, I totally agree with the principle of better
preconfigured wireless security schemes, I just happen to consider
what you've said so far to be simplistic and possibly disengenuous)

>Mark McIntyre <markmcintyre@xxxxxxxxxxx> hath wroth:
>
>>On Fri, 27 Jan 2006 01:37:23 GMT, in alt.internet.wireless , Jeff
>>Liebermann <jeffl@xxxxxxxxxxxxxxxxxxxxxx> wrote:
>
>>>Wouldn't it be easier for the manufactures to ship their products
>>>secure by default rather than insecure?
>>Indeed, but probably impractical.
>
>Impractical? 2wire.com can do it on every wireless router they ship.

requiring an extra step (ie cost) in manufacturing and packaging...

>They attach a label to the bottom of the router with the router
>password, unique SSID, and WEP encryption key.

Excuse me while i snort into my coffee. They stick a label on the box
with the password written on it? And this is considered secure ?

Remind me, is it currently recommended security practice to write your
password on a post-it note on the underside of your keyboard?

>However, if the cost of an additional label will cause the wireless
>manufacturers undue financial harm, it can be done in firmware by
>changing the default setup:
>1. Upon a hard reset or as shipped, the router will not work until
>the user assigns a unique router password.
>2. Upon a hard reset or as shipped, the wireless is disabled until
>the user sets the SSID and either sets up WEP/WPA, or intentionally
>disables encryption.

I agree, this is what should happen. But this is precisely what you
pooh-pooed in your earlier mail when you said that it was wrong to
expect the user to run hrough a setup process.

>Yep. See 2wire.com They've only been doing exactly that since the
>beginning.

And they're right up there with linksys, cisco, 3com, netgear, in
terms of units shifted, cost comparison etc... :-)

>>And indeed some of the information seems positively
>>misleading - the suggestion that you can get instant secure links
>>without typing in any passphrase for instance.

>Huh? I think they're referring to the router being secure, not the
>clients or the entire system.

Here's what they say:

"Our exclusive FullPass instant connection technology enables any
computer, and other service provider supported wireless devices, to
automatically connect to the correct wireless network with the highest
level of Wi-Fi security available."

Sounds to me like a claim to be able to reconfigure client devices.
Mark McIntyre
--

----== Posted via Newsfeeds.Com - Unlimited-Unrestricted-Secure Usenet News==----
http://www.newsfeeds.com The #1 Newsgroup Service in the World! 120,000+ Newsgroups
----= East and West-Coast Server Farms - Total Privacy via Encryption =----
.



Relevant Pages

  • Re: A home computer is a forensic evidence room
    ... A security plan that first covers recovery, and data protection is key. ... Anyone within range of your wireless transmission could connect to your network and use it or capture your computing sessions. ... reset the wireless router to factory: press and hold reset 20 seconds. ...
    (alt.2600)
  • Re: Router/Wireless Install
    ... >> in when you connected to the wireless. ... SBS Standard is just allowing the outbound connection to the Internet ... >> - Best security is WPA2 with IAS authentication. ... > SBS or the router to correct the problem. ...
    (microsoft.public.windows.server.sbs)
  • Re: Network adapter question
    ... compatability (security and speed) if you use all your components from the ... I have a small home network and I want to go wireless. ... decide which adapter I should get. ... Do you mean that you will be using a linksys wireless router? ...
    (alt.comp.hardware.pc-homebuilt)
  • RE: [Full-Disclosure] Wireless ISPs
    ... If they put WEP in, that's one more thing for customer to do and they'll ... Therefore end-user security ... Im using this venue to influence several wireless ISPs ... >> All transactions done via secure websites are ...
    (Full-Disclosure)
  • Re: ALERT: WPA-TKIP isnt secure - use WPA2 instead
    ... Do you know anyone that changes their wireless WPA/WPA2 ... 20 non-random keys aren't secure! ... security is far more demanding than the local coffee shop. ... There's always a risk of code ...
    (alt.internet.wireless)