A colleague and I were recently debating whether it's an OK policy to allow wireless access based on users MAC addresses. He has a small office where most people are wired, but a few are wireless and are part of that notorious gang that can't be bothered with passwords.
He also said that basing authentication on MAC address gets rid of network misidentification problems on the client end.
I say malarky, and whatever benefits he's seeing aren't worth the security risks if a spoofer comes in and sees what's going on.
Am I just old fashioned, or is he opening up a hole the size of a barn?
Software/Hardware used:
ASKED:
March 22, 2010 2:44 PM
UPDATED:
April 1, 2010 12:06 AM
you only have to input the wireless network key once and the machines will remember the network configuration the next time it tries to connect. How difficult can that be?
Sounds like more of a user problem than a wireless network problem. MAC address spoofing is well-documented and relatively easy to overcome if other controls such as WPA2 are not in place.