Wireless Security
I am reading the the Today newspaper and there's an article on wireless security. "Go wireless, but keep intruders away", it says. All's well and good, till one reads the contents:
Summary of contents
- Router placement: Place in the centre of the house
- Router password: Change admin password
- Disable SSID: Disable SSID broadcast
- Add a filter: Enable MAC filtering
- Limit the connection lines: Limit DHCP connections to the number of actual computers connecting
- Enable security: Use WEP at the minimum, WPA if possible
Disable SSID broadcast? Add a MAC filter? Enable WEP security?!? Hello, these DON'T work!!! SSID and MAC is easily discovered via packet sniffing. MAC addresses can be easily spoofed. And the latest WEP crack published last week managed to crack it within 60 seconds.
Geez, when will proper security advice be given from the mainstream press.
Proper advice:
- Configure your wireless using a wired connection.
- Change the admin user and password, using a good long password.
- Give your network a unique name (no, "linksys", "default" are not unique).
- Leave SSID broacast on. SSID broadcast off only gives connection headaches with no gains in security.
- Restrict by MAC address if you want to, no harm done, not much gain either.
- And most importantly, use WPA-TKIP encryption (WPA2 is even better) with an extremely long, and good passphrase consisting of UPPER, lower, numb3rs, and maybe even $ymb0ls.