Featured New Release
Box cover for Elegant Beauty Needs Passionate Sex
Elegant Beauty Needs Passionate Sex
Studio: Vixen
Release date: 7/26/2026


all new releases
All Forums > Tech Talk > Tech Talk Forum Page 35 > Home Networking
AuthorPost
jayo All-Star Supporter
All-Star Member


2117 Posts
7/04
Posted - Apr 18 2007 : 8:34PM
Thought I'd ask here since I trust your opinions as much as anyone's:

We were discussing wireless network security on another thread, namely the public access hotspots like you get at Starbucks, and a lot of people said they weren't secure.

What about a home network? I was thinking about setting up a wireless router so I could share a DSL connection with a couple of computers. Can I set it up to be secure (provided I make the effort), or am I asking for trouble?

croy
Platinum Member

Discovry
4574 Posts
3/04
Posted - Apr 18 2007 : 10:24PM
Not my thing, but there are security features you can use. Because it is your network and you don't intend to make it public, you can and should use these to keep most others out.
The more puzzling thing is why some offices, which don't mean to be public, don't use basic features.
Sensi
Deactivated User

106 Posts
4/07
Posted - Apr 18 2007 : 10:30PM
It is true -- public hotspots are not secure. But also remember even "secured" WiFi connections can be cracked easily. It's important to remember in addition to having a secured wireless network to have:

1. Strong firewall protection
2. Regular password changes for WiFi
3. Encryption software
4. Proxies (So that websites, people you e-mail or IM, can't determine your IP along with other things)
5. Patched OS

Wireless 802.11ABG using WEP, WPA, WPA2, etc can be attacked using packet sniffers to determine:

1. Your network key.
and eventually,
2. What you are doing online.

WEP is part of the IEEE 802.11 and uses RC4 for encrypting and CRC-31 (If I remember) for the authenticity. It's network key is cracked in about 5 minutes -- not matter the password length.

WPA2 is a good bet.

I can help you out with setting up your wireless. First: What kind of router do you have?
---------------------------------


Remember me? Spew...[SonyVAIOFE790]C2D2.33ghz. 2GB RAM. Nvidia GO 7600. Linux.

Edited by - sensi on 4/18/2007 10:33:28 PM

justalurker
Member

241 Posts
8/03
Posted - Apr 18 2007 : 10:45PM
The most secure thing you can do is disable broadcast SSID. This disables it from broadcasting what it's name is to anyone who may be listening, if they don't know you are there they most likely won't even try to to get in. Setting a password with strong encryption is still recomended. And change the default name of your router to something only you would know.

Edited by - justalurker on 4/18/2007 10:58:38 PM

Sensi
Deactivated User

106 Posts
4/07
Posted - Apr 18 2007 : 10:55PM
Disabling SSID broadcasting is not the most secure thing you can do.

I can run several programs through Linux/Windows(AirJack, Kismet, etc) and find your SSID in 3 seconds.

Remember: Hiding the SSID means the computers who you allow to connect DISPLAY the SSID in cleartext to the packet sniffer. In addition with SSID broadcasting disabled it is much easier to set up a disassociate frame to grab hold of the entire network key at once in the first place.

In addition: Hiding your SSID actually requires your router to send out more packets to the computers it needs to communicate to. Hence, making cracking the network key a whole lot faster.

Post edit: Another way to look at it is this. The router has the SSID broadcast off. Yet when you turn on your laptop to connect to your home network -- the SSID name and other important information -- is sent unencrypted to the router. All it takes is someone to run a packet sniffer 24/7 to nag your logins, SSID, and more.
-------

Remember me? Spew...[SonyVAIOFE790]C2D2.33ghz. 2GB RAM. Nvidia GO 7600. Linux.

Edited by - sensi on 4/18/2007 11:00:21 PM

Edited by - sensi on 4/18/2007 11:04:25 PM

 
justalurker
Member

241 Posts
8/03
Posted - Apr 18 2007 : 11:23PM
No network other than closed ones are failsafe secure. For home networking most any of the security measures will prevent unauthorized access. Even WPA2 has not been proof against a determined attacker. The problem happens when people setup their networks and they leave everything in default, where any pre-school level kid can gain access.
Sensi
Deactivated User

106 Posts
4/07
Posted - Apr 18 2007 : 11:30PM
Exactly. Anyone (and that happens to be a lot of people) who knows a few programming languages, networking, OS and software exploits, can easily gain access to your home network.
This is true -- but it is the easiest and also happens to be one of the better options for most current routers. Not many people could afford or know how to operate a CP let alone setup 802.1X or LEAP -- among other things.
jayo All-Star Supporter
All-Star Member

2117 Posts
7/04
Posted - Apr 18 2007 : 11:46PM
Don't have one yet. This is part of my research phase.

Suggestions?

justalurker
Member

241 Posts
8/03
Posted - Apr 18 2007 : 11:58PM
In my neighborhood I have five people who run their networks wide open, and three of them never bother to change the name. If I was going to hack someone, I would waltz into their domains before looking for anyone else. And I never keep anything on my machine of a personal nature ever.
Sensi
Deactivated User

106 Posts
4/07
Posted - Apr 18 2007 : 11:58PM
That depends on what you want to do with it, pretty much.

But to help you out really quick before I sign off:

Although there is debate right now about Draft N (the new high speed wireless) it is probably in your best interest to avoid it, for now. But if you are interested these are good choices: D-link DIR665 or LinksysWRT350N.

For not Draft N wireless (leaving you ABG): LinksysWRT54G or GX is a decent one. Some complain. There really isn't any "perfect" router.

If you want to play video games obviously you need better routers.

Yes. Thank you.
---------
Remember me? Spew...[SonyVAIOFE790]C2D2.33ghz. 2GB RAM. Nvidia GO 7600. Linux.

Edited by - sensi on 4/19/2007 12:00:40 AM

jayo All-Star Supporter
All-Star Member

2117 Posts
7/04
Posted - Apr 19 2007 : 9:14PM
I surf the net. The biggest bandwidth website is probably YouTube. I don't stream video, audio, etc, and I don't play games online. Might want to put up a couple of wireless security cameras, though.

jayo All-Star Supporter
All-Star Member

2117 Posts
7/04
Posted - Apr 19 2007 : 9:21PM
I guess part of the question I should have started with was more about the likeliness of being hacked. A talented thief can steal almost any car, but a Toyota Corolla is infinitely more likely to be stolen than a Buick Skylark.

Sensi
Deactivated User

106 Posts
4/07
Posted - Apr 19 2007 : 9:53PM
It's very hard to say honestly. It depends on the people with such knowledge in your wireless range. There is no way to actually determine the answer of how linkly you are.

There are ways to greatly reduce the chance -- and by this we mean eliminating the people who are good hackers from the genius hackers. There is an expansive difference between the two.

Always remember: Wireless is a riskier than wired.

If you choose wireless: Change network keys often, firewall, proxies, PGP, and use the best security model your router allows.

cobalt60
Knuckle Dragger

2046 Posts
2/03
Posted - Apr 20 2007 : 11:45AM
A list of MAC addresses ("allowed stations") and not broadcasting the SSID is good enough for 99 out of 100 home networks. In general: a decent firewall, strong passwords, and encryption of sensitive/private data. Regular data backups. DriveXML or g4u images for fast reloads. Virus and malware scanning using lots of different engines, both local and online. And if you're really paranoid, not only don't do anything online you wouldn't do off, but don't buy shit, don't talk about anything you wouldn't talk about in a room full of people, and don't delude yourself that you aren't being keylogged or packet sniffed somewhere along the way.

The only true network security: a hard wired network that is not connected to the Internet. And lock your doors and windows.

justalurker
Member

241 Posts
8/03
Posted - Apr 20 2007 : 8:23PM
That about sums it up. Only thing I would add, is limit your channels to the maximum number of devices you will have connected at any given time. Won't make it any more secure, but at least if you have all the channels full they can't get in, or if you find you can't connect it will give you an idea for more investigation.



Jump To: