Skip to content
Why is a raven like a writing desk?

Thoughts both confusing and enlightening.

Why is a raven like a writing desk?

Thoughts both confusing and enlightening.

wireless (in)security

elbeno, 13 March, 2007

It's amazing what you can glean just from listening to the ether. Armed with an old laptop, wireless card, Kismet, and quarter of an hour, I can tell you the following about my neighbourhood:

There are 3 open wireless access points, 4 WEP-protected ones, and 5 or 6 WPA protected ones. One open point is run by a router with the default admin username and password. Several networks have their SSIDs hidden (but of course I still know them – “hidden” SSIDs mean little to Kismet). I also know (using MAC address vendor lookup) the make of each router and most of the stuff connected to it – for instance that several people use Apple computers, and one person has a wireless TiVo. Nobody except me has a Wii hooked up wirelessly :). Also, looking at the SSIDs of many of the networks, I can cross-reference with the phone book and find out exactly where the routers are (since many people put some variant of their surname in as the SSID).

So: hidden SSIDs mean nothing to an attacker (although they do stop random machines trying to automatically connect). MAC filtering again means very little to an attacker. WEP can be easily broken (say in half an hour) with monitoring and packet injection tools. And WPA(-PSK) can be subjected to a dictionary attack with information gleaned by the same tools.

My setup? Nothing out of the ordinary – just reasonable security. A strong admin password on the router. SSID “hidden”. I don't bother with MAC filtering because with the number of wireless devices I have in circulation, it's more inconvenient for me than for an attacker :). WPA encryption. A strong WPA password (not one that is susceptible to a dictionary attack). I estimate that a brute force attack on my password, testing a million keys a second, would take approx 50,000 years to succeed.

If you have a wireless network, don't wait until you see this on the pavement outside.

Uncategorized

Post navigation

Previous post
Next post

Related Posts

Miscellanea

14 April, 200814 April, 2008

Sorry for the relative blog silence recently. Here’s what I’ve been doing lately: Buying stuff at the local library book sale last weekend. Old maths textbooks FTW! Puzzling over how to approximate spirals with Bézier curves. Or otherwise thinking of a way to draw them. Having lunch with Gary. He…

Read More

Movies I have seen recently

28 March, 2005

Wimbledon. Not bad. An enjoyable 90 minutes. But a) I don't think that's the way to Brighton from London, and b) nobody runs 10 miles during a tournament, even less so while wearing Converse All Stars! Clueless. I'm a sucker for teen movies. Plus, it's got Alicia Silverstone in it;…

Read More

Superbowl XXXIX

7 February, 2005

Adverts this year = teh l4m3. That one with the cat just raised a chuckle. The highlight was the beatmania tune (“Jaques Your Body”) they used in that one advert for the… well I can't remember what it was for. Something like an iPod shuffle, but not – it featured…

Read More

Comments (5)

  1. sylvene says:
    13 March, 2007 at 5:30 pm

    Heh. I have the same setup as you do. A hidden SSID and a strong admin password on the router.

    (http://livejournal.com/users/sylvene)

  2. elbeno says:
    13 March, 2007 at 5:32 pm

    WPA with a strong password is the important bit though.

    (http://livejournal.com/users/elbeno)

  3. sylvene says:
    13 March, 2007 at 5:36 pm

    WPA vs WEP Ya know… I set it up 3 years ago. I don't remember… now I'm going to have to check when I get home.

    Bah!

    (http://livejournal.com/users/sylvene)

  4. elbeno says:
    13 March, 2007 at 6:01 pm

    Mine used to be WEP until I upgraded my router. WPA didn't used to be well supported by older routers and network cards. If you have to use WEP, 128-bit is better than 64-bit – it takes about 3 times longer to crack. But even so it's still crackable in reasonable time.

    But hey – if you can't be bothered with fiddling, another approach is to do a neighbourhood scan and see what's around. You probably only need to be more secure than the easiest target.

    (http://livejournal.com/users/elbeno)

  5. sylvene says:
    13 March, 2007 at 7:12 pm

    Haha. I know I'm more secure than the easiest target because I've logged into the neighbor's network while mine was down. *snicker*

    (http://livejournal.com/users/sylvene)

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

©2026 Why is a raven like a writing desk? | WordPress Theme by SuperbThemes