Wi-Fi is a security magnifying glass

If there's a hole in your network, Wi-Fi will show it up

Wi-Fi security has come a long way since two 20-somethings sat in the parking lot of a Lowe's store in Southfield, Michigan, hacked their way into Lowe's data centre in Wilkesboro, North Carolina, and downloaded customer credit card numbers. Two years on and many companies are still as vulnerable today as Lowe's was then.

Most experts agree that the weakest link in the enterprise today results from a failure to upgrade to the latest encryption and authentication technologies (read our wireless LAN security glossary for details of terms mentioned here, and read our parts list ).

Soft encryption, old authentication
"Early on a lot of wireless devices were simplistic at best, with a 40-bit WEP key and no support for authentication," says Richard Rushing, chief security officer for AirDefense.

In addition to WEP, another limited legacy approach to security is LEAP (Lightweight Extensible Authentication Protocol), originally a Cisco protocol for transporting authentication data. Cisco is now phasing out LEAP and other approaches in favor of PEAP (Protected Extensible Authentication Protocol), developed jointly by Cisco, Microsoft, and RSA Security.

In addition, most newer Wi-Fi networks now deploy 802.1x with stronger password-protection functions and AES (Advanced Encryption Standard) authentication.

Can you add features without upgrading?
But for many large companies a Wi-Fi network involves a multiyear rollout, which often precludes going back to square one and upgrading APs and client devices every time a newer technology is introduced.

If a company can't migrate to AES, which requires faster processors in the AP, then the company should consider using a VPN in house for its Wi-Fi network, says Roger Sands, vice president of enterprise development at Colubris Networks.

"Or at least use TKIP [Temporal Key Integrity Protocol], which is better than a static WEP key," Sands says.

A wireless network is an Ethernet jack outside the door
The truth is that wireless technology in general has an inherent weakness not shared by a wired network: A physical barrier can't protect wireless .

When wireless leaves the building it is the same as putting an Ethernet connection outside the door, Rushing says.

Because almost all of the basic gambits hackers used three years ago, such as the Evil Twin, DoS, and taking down all APs in order to put in a rogue AP when the system reboots, are still possible, the only real defense is to monitor and scan the airwaves for intruders, says Rich Mironov, a vice president at AirMagnet (as you might guess, he makes a scanner - AirMaget is reviewed here).

Security is commonsense
Despite all the high-tech gadgetry used by both good guys and bad, many security rules are commonsense, says Jack Gold, a principal at JGold Associates.

"Make sure people log out, don't leave devices hanging around, and make sure people aren't looking over your shoulder," Gold says.

All the experts spoken to for this article agreed that wireless is a magnifying glass, and if there is a security hole in your organization, wireless will magnify it.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Mobile & Wireless news

Chip makers push Google Android devices

ARM and MIPS aim to put mobile OS everywhere

Sony struggles to ship ebook readers before christmas

Reader Daily Edition may miss holiday season

Organisations offered build-your-own iPhone app service

BuildAnApp looks to take grunt work away.

Microsoft updates Windows Mobile Marketplace

Enhances security, releases desktop PC client



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *