<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Corner &#187; Wireless</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-corner/tag/wireless/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-corner</link>
	<description></description>
	<lastBuildDate>Fri, 14 Jun 2013 13:06:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>WPA-TKIP Now Vulnerable to Attack</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/wpa-now-vulnerable-to-attack/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/wpa-now-vulnerable-to-attack/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 03:00:05 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Secure Computing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[Wireless security]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/wpa-now-vulnerable-to-attack/</guid>
		<description><![CDATA[In my How to Secure Your Computer series of articles, I issued Maxim #13, &#8220;WiFi Security–The Only Way is WPA&#8220;. However, TKIP&#8211;which is one of the protocols used under the WPA certification standard&#8211;is now vulnerable to attack, so I feel it prudent to modify my stance a bit and shed a little light on the [...]]]></description>
				<content:encoded><![CDATA[<p>In my <em>How to Secure Your Computer</em> series of articles, I issued Maxim #13, <a href="http://itknowledgeexchange.techtarget.com/security-corner/wifi-security-the-only-way-is-wpa/" rel="bookmark" title="Permanent Link to WiFi Security–The Only Way is WPA">&#8220;WiFi Security–The Only Way is WPA</a>&#8220;. However, TKIP&#8211;which is one of the protocols used under the WPA certification standard&#8211;is now vulnerable to attack, so I feel it prudent to modify my stance a bit and shed a little light on the subject. Certain media reports would have you believe that WPA has been cracked; this isn&#8217;t the case. (See &#8220;<a href="http://wifinetnews.com/archives/008502.html" target="_blank">WPA Not Cracked, But Still Vulnerable</a>.&#8221;) Steve Gibson&#8217;s latest episode (#170) of <a href="http://www.grc.com/securitynow"><em>Security Now!</em></a> explains in great detail the TKIP hack and why it&#8217;s much to worry about&#8211;at least, not yet.</p>
<p>Under the WPA/WPA2 standards, a wireless access point or router can use either TKIP (<a href="http://www.tech-faq.com/tkip-temporal-key-integrity-protocol.shtml" target="_blank">Temporal Key Integrity Protocol</a>) or AES-CCMP (<a href="http://www.pcmag.com/encyclopedia_term/0,2542,t=AES-CCMP&amp;i=37582,00.asp" target="_blank">Advanced Encryption Standard, Counter Mode/CBC MAC Protocol</a>). TKIP is an enhancement of <a href="http://www.tech-faq.com/wep-wired-equivalent-privacy.shtml" target="_blank">WEP</a> that utilizes the <a href="http://www.tech-faq.com/rc4.shtml">RC4</a> <a href="http://www.tech-faq.com/block-stream-cipher.shtml">stream cipher</a> with 128-bit keys for encryption and 64-bit keys for authentication; CCMP provides much stronger protection because it uses <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard" target="_blank">AES</a> (Rinjdael) encryption.</p>
<p>Two German researchers, Martin Beck and Erik Tews, recently found a way to crack TKIP. They use what is called a <a href="http://www.aircrack-ng.org/doku.php?id=korek_chopchop" target="_blank"><em>chopchop attack</em></a>, which attempts to decrypt packets byte by byte. You can read all about it in their white paper, &#8220;<a href="http://windowssecrets.com/links/qivu6yl5kstcd/da03adh/?url=dl.aircrack-ng.org%2Fbreakingwepandwpa.pdf">Practical attacks against WEP and WPA</a>&#8221; so I won&#8217;t go into the details here.</p>
<p>While there doesn&#8217;t appear to be much an attacker can do at this point, the attack is a harbinger of things to come and now would be a good time to log into your wireless router and see what&#8217;s up. I discovered that mine doesn&#8217;t support AES-CCMP, only TKIP, so I need to upgrade the firmware. I recommend that everyone do one of the following: 1. Switch your current WPA configuration to AES-CCMP if it&#8217;s supported; 2. Upgrade the firmware in your router so it supports WPA2 with AES-CCMP;  3. If neither of those is possible, or, heaven forbid, your router only supports WEP, replace it with one that&#8217;s WPA2 compliant and use AES-CCMP.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/wpa-now-vulnerable-to-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WiFi Security&#8211;The Only Way is WPA</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/wifi-security-the-only-way-is-wpa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/wifi-security-the-only-way-is-wpa/#comments</comments>
		<pubDate>Fri, 20 Jun 2008 01:02:08 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security maxim]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/wifi-security-the-only-way-is-wpa/</guid>
		<description><![CDATA[Please note: since this article was posted, WPA-TKIP has been found to be vulnerable. See my post of 2008.11.13 entitled &#8220;WPA-TKIP Vulnerable to Attack&#8221; for more information. It&#8217;s far too easy to set up WiFi for your home or business; all you have to do is go to your local electronics superstore and pick up [...]]]></description>
				<content:encoded><![CDATA[<p><em><strong>Please note: since this article was posted, WPA-TKIP has been found to be vulnerable. See my post of 2008.11.13 entitled &#8220;<a href="http://itknowledgeexchange.techtarget.com/security-corner/wpa-now-vulnerable-to-attack/" target="_blank">WPA-TKIP Vulnerable to Attack</a>&#8221; for more information.</strong></em></p>
<p>It&#8217;s far too easy to set up <a href="http://www.webopedia.com/term/w/wi_fi.html" title="WiFi" target="_blank">WiFi</a> for your home or business; all you have to do is go to your local electronics superstore and pick up a <a href="http://www.linksys.com/servlet/Satellite?c=L_Product_C1&amp;childpagename=US%2FLayout&amp;cid=1115416939789&amp;pagename=Linksys%2FCommon%2FVisitorWrapper&amp;lid=3978991233B02" target="_blank">wireless router</a>, plug it in to your network, and connect to it. The default configuration of most consumer products&#8211;completely open with no security enabled&#8211;will allow you to connect without having to enter any configuration information into your wireless PC. That&#8217;s why in any given neighborhood you&#8217;ll see multiple unsecured wireless network connections available. Most <a href="http://wi-fiplanet.webopedia.com/TERM/h/hotspot.html" target="_blank">public WiFi hotstpots</a> are also unsecured, open connections. If you just surf the web and send an occasional email, you might be OK (besides the fact that anyone in range can connect to and use your Internet connection), but the moment you start using your PC for banking, making purchases, and paying bills online, that wireless connection absolutely must be secured. It must be done right, and there&#8217;s really only one right way to do it. Before I explain that, let me tell you what <em>not</em> to do:</p>
<p>1. <strong>Don&#8217;t rely on SSID hiding</strong>. I&#8217;ve seen numerous articles that tout <a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=ssid" target="_blank">SSID</a> hiding as a <a href="http://netsecurity.about.com/od/quicktip1/qt/qtwifinossid.htm" target="_blank">security measure</a> (and one <a href="http://en.wikipedia.org/wiki/CISSP" target="_blank">CISSP</a>, no less, is recommending it!) While this technique may serve to hide your network from casual view, there&#8217;s nothing secure about it: the SSID is transmitted in clear text in every packet and is easily sniffed by wireless packet sniffers. For example, <a href="http://netsecurity.about.com/od/securitytoolprofiles/p/aaprnetstumbler.htm" target="_blank">Network Stumbler</a> will identify the SSIDs of any network within range, regardless of whether or not the wireless access points are broadcasting.</p>
<p>2. <strong>WEP is broken</strong>. <span>Using 40,000 to 100,000 packets, which can be captured in about a minute, you can crack a WEP key in about three seconds on a Pentium M 1.7 GHz PC. Don&#8217;t believe me? Check it out: <a href="http://www.google.com/search?q=how+to+crack+wep&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a" target="_blank">This list</a> even provides video tutorials on how to do it. Sure, it provides a small measure of security and it&#8217;s better than nothing, but why use something that&#8217;s already been proven inferior? Would you feel more secure knowing the garage where your store that vintage <a href="http://www.musclecarclub.com/musclecars/chevrolet-corvette/chevrolet-corvette-history-1.shtml" target="_blank">Corvette</a> is protected by a <a href="http://www.masterlock.com/" target="_blank">Master</a> lock or one you bought at an everything-for-a-dollar store? Your personal information is much more valuable than that car. </span></p>
<p>3. <strong>Don&#8217;t bother with MAC address filtering </strong>.  I don&#8217;t know why so many people are <a href="http://www.google.com/search?q=mac+address+filtering&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a" target="_blank">recommending this</a>. <a href="http://en.wikipedia.org/wiki/MAC_address" target="_blank">MAC address</a> filtering is equivalent to SSID hiding&#8211;it&#8217;s virtually useless, except to keep a casual user from inadvertently connecting to your wireless network. Like the SSID, MAC addresses are sent in clear text within the network packets and can easily be discovered and spoofed by anyone sniffing your network.</p>
<p>So, what&#8217;s the <em>right</em> way? <a href="http://www.wi-fi.org/knowledge_center/wpa/" target="_blank">WiFi Protected Access</a>, known by its acronym, WPA. There are two versions: WPA-Personal and WPA-Enterprise. WPA-Personal relies on a pre-shared key (PSK), while WPA-Enterprise requires a special authentication server and is therefore more suited to corporate environments. WPA implements 128-bit encryption and as long as you create a strong, <a href="http://www.davescomputertips.com/newsletters/2008/080201.php#3" target="_blank">unguessable passphrase</a>, it&#8217;s completely secure. Configuring WPA-PSK on a given wireless router depends on the brand, but you can find a general tutorial at <a href="http://www.wi-fiplanet.com/tutorials/article.php/3552826" target="_blank">this site</a>.</p>
<p>And that, my dear reader, is Maxim #13 in the <em>How to Secure Your Computer</em> series of articles:</p>
<blockquote><p>When it comes to securing a WiFi network, the only way is WPA.</p></blockquote>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/wifi-security-the-only-way-is-wpa/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wireless Headset Security Nightmare</title>
		<link>http://itknowledgeexchange.techtarget.com/security-corner/wireless-headset-security-nightmare/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-corner/wireless-headset-security-nightmare/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 18:58:08 +0000</pubDate>
		<dc:creator>Ken Harthun</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-corner/wireless-headset-security-nightmare/</guid>
		<description><![CDATA[Being a Ham Radio operator, I&#8217;ve always understood the risk inherent in using radio signals to transmit sensitive information: anyone with the right equipment can receive and record anything transmitted over the air. These days, I&#8217;m noticing a lot of people in various offices walking around with these cute wireless headsets hooked up to their [...]]]></description>
				<content:encoded><![CDATA[<p><img src="http://kennyhart.com/images/headset1.jpg" alt="Wireless headset" align="left" height="177" width="146" />Being a Ham Radio operator, I&#8217;ve always understood the risk inherent in using radio signals to transmit sensitive information: anyone with the right equipment can receive and record anything transmitted over the air. These days, I&#8217;m noticing a lot of people in various offices walking around with these cute wireless headsets hooked up to their office phones.</p>
<p>Ever wondered what kind of security risk these things might pose to your company? Yeah, me too. So, did the folks at <a href="http://www.securenetworkinc.com/" target="_blank" title="Secure Network Technologies, Inc."><font><font>Secure Network Technologies</font></font></a> as evidenced by their article <a href="http://www.darkreading.com/document.asp?doc_id=143779" title="Article" target="_blank">&#8220;Hacking Wireless Headsets&#8221;</a> that appeared Jan. 22, 2008 at <a href="http://www.darkreading.com">DarkReading.com</a>, a site that provides in-depth security news and analysis. Here&#8217;s an excerpt:</p>
<blockquote><p>To perform the work, we purchased a commercially available radio scanner. These devices are available at any local electronics retailer at prices ranging from $80 to several thousand dollars. We chose a scanner capable of monitoring frequencies from 900-928 Mhz and the 1.2 Ghz ranges, which is where many of the popular hands-free headsets operate.</p>
<p>We took a position across the street from the facility and started up the scanner. Within seconds of turning on the device we were able to listen to conversations that appeared to be coming from our client&#8217;s employees. Several of these conversations discussed the business in detail, as well as very sensitive topics. After some careful listening, we determined that the conversations were indeed coming from our customer.</p></blockquote>
<p>See the nightmare coming? With the right information you can then use social engineering techniques to get your tentacles very deep into the company. And that&#8217;s exactly what they did:</p>
<blockquote><p>Our plan was to assume an identity of an employee who had never been to the office we were testing. Using that identity, we would enter the building, commandeer a place to sit and work, then see how long we could stay inside the building. After zeroing in on a particular employee, we gathered as much intelligence on him as we could. To prepare for the entry into the facility, we printed a business card with our assumed identity. I put on my best suit, and then went to work.</p></blockquote>
<p>In all, they spent three days &#8220;working&#8221; in the company, gaining access to all sorts of information, technology, and resources. Not only that, but they also discovered that the headsets acted as bugging devices; even when disconnected, the headsets continued to transmit. The impersonators were able to listen in on conversations carried on by the wearers.</p>
<p>Be afraid. Be very afraid <img src='http://itknowledgeexchange.techtarget.com/security-corner/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  Seriously, read the article and if your office uses these things, do your own tests to find out where you&#8217;re leaking. Then, plug the leaks.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-corner/wireless-headset-security-nightmare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
