Author |
Message |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
Hey folks, one of my neighbours got visited recently by the Police 'cos their connection had been used to do some highly illegal stuff. So I decided to beef up our wireless security. Here's what I did: - Changed encryption from WPA to WPA2[PSK]
- Set up an access control list of specific MAC addresses
- Disabled SSID broadcast
- Set new decent & different passwords for the wireless access key and the administrator interface.
The problem is that my iPod Touch refuses to reconnect to the network if it locks the screen and the network is not broadcasting an SSID - I have to set up the connection manually again. Is there a way to fix this or am I going to have to re-enable SSID broadcast?
|
Sun Apr 04, 2010 6:24 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
Hiding the SSID doesn't increase security, so it doesn't matter if you have to re-enable it. There is no advantage to having it hidden.
One other thing you could do for better security is reduce the transmit power as far as you can without disturbing your network.
_________________
|
Sun Apr 04, 2010 7:03 pm |
|
 |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
I couldn't see an option to do that, but I'll have another look, thanks  .
|
Sun Apr 04, 2010 7:46 pm |
|
 |
JJW009
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 6:58 pm Posts: 8767 Location: behind the sofa
|
It actually reduces security by increasing the chatter with active clients thus making the WPA2 encryption easier to crack.
_________________jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly." When you're feeling too silly for x404, youRwired.net
|
Mon Apr 05, 2010 1:02 am |
|
 |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
Fair enough, I'll just re-enable SSID broadcast then. 
|
Mon Apr 05, 2010 1:37 am |
|
 |
nvj1662
Occasionally has a life
Joined: Tue May 05, 2009 6:15 pm Posts: 175
|
Because you mention neighbours, I assume you are speaking of a domestic network? If so, then consider switching the wireless off when not in use and keeping a log. The MAC address is broadcast in ARP traffic so it is possible to sniff both the SSID and the MAC address from a legitimate session.
|
Wed Apr 07, 2010 12:10 pm |
|
 |
okenobi
Spends far too much time on here
Joined: Thu Apr 23, 2009 6:59 pm Posts: 4932 Location: Sestriere, Piemonte, Italia
|
Ooh, ooh, ooh!! Was just gonna start a new thread on a related topic. Mind if I jack?
Just setting up a Linksys AP at work which will be for the exclusive use of my guests. It's on a separate ADSL line and is not connected to any of my hardware. Do I need anything better than WEP? We wouldn't get many passing leaches as we're in the middle of nowhere, but obviously I want some security and I may yet charge a small amount to my captive audience.
In the setup it talks about WPA2 etc. but I'm used to a proper network with wires, so I don't have a clue about this wireless nonsense. It's offering me WEP (64 or 128bit), WPA Personal, WPA2 Personal, WPA Mixed. I've had a look around Wiki, but still haven't figured about the difference. Any ideas.....?
|
Wed Apr 07, 2010 3:39 pm |
|
 |
nvj1662
Occasionally has a life
Joined: Tue May 05, 2009 6:15 pm Posts: 175
|
WEP is almost useless against anyone but casual passers-by as tools are readily available that will crack it in minutes (sometimes less). You will cause yourself the trouble of configuring it and the hassle of ensuring that your users have it configured, ruling it out of any troubleshooting etc, etc. If you do not consider your installation to be a target, don't bother. If you're concerned, use WPA2. I don't know what linksys model you have but have a butch here: http://www.linksysbycisco.com/?search_keyword=WPA+Mixed&x=0&y=0&pagename=LBC%2FCommon%2FDynamicWrapper&site=UK&ppath=search&c=Page&lang=en
|
Thu Apr 08, 2010 11:50 am |
|
 |
big_D
What's a life?
Joined: Thu Apr 23, 2009 8:25 pm Posts: 10691 Location: Bramsche
|
There is only one level of security that should be used, WPA2. WEP is harder to configure and is less secure. It should only ever be used if you have a legacy device which can't be upgraded and you cannot live without it being in your network - although you might as well save yourself the hassle and run an unencrypted network in that case.
WEP can be cracked in a couple of minutes, WPA in a couple of hours. WPA2 is currently unhacked and only susceptible to a dictionary attack - you should always use a key of at least 21 characters.
_________________ "Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari
Executive Producer No Agenda Show 246
|
Sat Apr 17, 2010 8:39 am |
|
 |
Amnesia10
Legend
Joined: Fri Apr 24, 2009 2:02 am Posts: 29240 Location: Guantanamo Bay (thanks bobbdobbs)
|
I have heard WEP can be cracked in under 30 seconds. Though as you have said it will be enough to keep out the casual attempt. I would recommend a randomly generated password, so that dictionary attacks are impossible and brute force attacks much harder.
_________________Do concentrate, 007... "You are gifted. Mine is bordering on seven seconds." https://www.dropbox.com/referrals/NTg5MzczNTkhttp://astore.amazon.co.uk/wwwx404couk-21
|
Thu Sep 09, 2010 8:43 am |
|
 |
forquare1
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 6:36 pm Posts: 5150 Location: /dev/tty0
|
I've had a setup identical to yours (less the MAC address filtering) and my iPod Touch worked fine...
|
Thu Sep 09, 2010 10:47 am |
|
 |
rustybucket
I haven't seen my friends in so long
Joined: Thu Jun 18, 2009 5:10 pm Posts: 5836
|
My router won't connect any wireless client until you hold down a button on the back of the router.
It can be a PITA sometimes but I wouldn't want to be without it.
_________________Jim
|
Thu Sep 09, 2010 12:23 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
Do you mean connect for the first time, or connect full stop?
If you mean every time then I really couldn't be doing with it, but if it's only for the initial connection then that sounds like a really good feature.
_________________
|
Thu Sep 09, 2010 5:42 pm |
|
|