CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer
image Security HeadLines: Key to Wi-Fi Security image
Wireless
By Glenn Fleishman & Ephraim Schwartz

Conventional wisdom says wireless LAN access to an enterprise adds enormous risk because the broken security model at the heart of Wi-Fi networking allows crackers to break encryption , snoop traffic, insert packets, and associate at will. WLAN access points must be outside the firewall, with VPN connections tunneling through. No exceptions.

Enter the Wi-Fi Alliance, with members that include Microsoft (Nasdaq: MSFT) , Intel (Nasdaq: INTC) , Cisco (Nasdaq: CSCO) and Apple (Nasdaq: AAPL) . Seeking to quell consumer and enterprise concerns about Wi-Fi security holes, the group has essentially lifted the construction engineer's drawings for the work-in-progress IEEE 802.11i security draft and started to pour and smooth the macadam that leads to the golden city on the hill: full 802.11i completion and ratification. This ad hoc engineering project comes with member approval; the move isn't as radical as it seems.

The alliance's new WPA (Wi-Fi protected access) standard uses most of the current 802.11i draft to repair problems in WEP (wired equivalent privacy), the first line of defense for Wi-Fi networks. WEP's goal was to encrypt packets in transit at the data link layer to deter unauthorized network access.

WEP failed in its attempt, however, through several cryptographic flaws that resulted in rapid key reuse. These flaws leave the link layer unprotected by Wi-Fi, and thus banished it outside the firewall where protection is provided at higher network layers by VPN, SSH, or other tunneled encryption methods.

WPA solves the problem by abandoning WEP in favor of 802.11i's vastly improved TKIP (temporal key integrity protocol). WPA ensures that TKIP keys vary for each packet through key mixing. WPA also increases part of the keyspace and adds encrypted packet integrity to reject inserted packets. Current Wi-Fi puts weak integrity outside the encrypted payload.

WPA includes full support for server-based authentication using the 802.1x protocol and EAP (extensible authentication protocol), both part of the interim 802.11i draft.

Although EAP lacks a built-in encryption method -- it's merely a generic messaging method -- three overlays that embed EAP inside an encrypted tunnel have emerged to solve different parts of the problem.

An early version, EAP-TLS (transport layer security), required a client-side public-key certificate to be preinstalled before the first wireless session. Although this was the method that Microsoft uses for its campuswide WLAN, EAPTLS is complicated because an enterprise must establish a PKI.

Instead, vendors are focusing on two methods: EAP-TTLS (tunneled TLS) and PEAP (protected EAP), both of which build a tunnel within a tunnel. The outer tunnel is entirely anonymous, allowing a second tunneled session to begin inside it, which itself encapsulates EAP or other protocols. This approach avoids client certificates but still allows for them.

Microsoft and Cisco have backed PEAP. Although virtually identical in principle to EAPTTLS, PEAP handles only EAP and MS-CHAP V2. Microsoft has offered PEAP clients for Windows XP and 2000 for free and plans a full Win32 rollout for Windows 98, NT 4, and Me.

Neither company representatives nor industry observers can explain the necessity for both EAPTTLS and PEAP, the main difference between the two being the latter's lack of legacy authentication support. It's easy to assume that Microsoft and Cisco's agenda was to push enterprises to upgrade to newer authentication servers, but PEAP could wind up as widely available as EAP-TTLS.

Both EAP-TTLS and PEAP are passing through the IETF (Internet engineering task force) process toward hopeful reconciliation or at least standardization. During this process, two man-in-the-middle attacks have been theorized that must be addressed before the standards can be deployed with absolute security.


Article source and further details: Wireless.NewsFactor.com
Posted on Friday, 31 January 2003 @ 11:30:00 UTC by cj (2021 reads)
[ Trackback ]
image

"Security HeadLines: Key to Wi-Fi Security" | Login/Create an Account | 2 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Key to Wi-Fi Security (Score: 1)
by shikehal  on Saturday, 31 May 2008 @ 16:05:52 UTC
(User Info | Send a Message)
Great article, keep up the good work. ----------------------------------------------------
برامج نت [www.bramjnet.com]| free software [www.tt5r.com]| افضل المواقع العربية [top.tt5r.com]| منتدى برامج نت [www.bramjnet.com]| العاب فلاش - العاب بنات [games.bramjnet.com]| برامج [soft.bramjnet.com]| دليل المواقع [dir.bramjnet.com]| عيادة طب [med.bramjnet.com]| الأرشيف [www.bramjnet.com]| برامج مشروحة [www.bramjnet.com]| برامج ترجمة [soft.bramjnet.com]| برامج الفاكس [soft.bramjnet.com]| برامج طباعة [soft.bramjnet.com]| برامج تحرير [soft.bramjnet.com]| برامج التقاط الصور والشاشات [soft.bramjnet.com]| برامج سطح المكتب [soft.bramjnet.com]| برامج البريد الالكتروني [soft.bramjnet.com]| برامج خدمات البريد الاكتروني [soft.bramjnet.com]| برامج القوائم البريدية [soft.bramjnet.com]| برامج ادوات البريد الاكتروني [soft.bramjnet.com]| برامج مكافحة الرسائل المزعجة [soft.bramjnet.com]| برامج الإنترنت [soft.bramjnet.com]



Re: Key to Wi-Fi Security (Score: 1)
by shikehal  on Saturday, 31 May 2008 @ 16:06:39 UTC
(User Info | Send a Message)
برامج مشاهده القنوات الفضائيه [soft.bramjnet.com]| برامج تسربع الانترنت [soft.bramjnet.com]| برامج تحميل الملفات والصور [soft.bramjnet.com]| برامج المحادثة [soft.bramjnet.com]| برامج ماسنجر [soft.bramjnet.com]| اتصال دولي - الرسائل القصيره [soft.bramjnet.com]| إدوات خدمية وتعاريف قطع جهاز [soft.bramjnet.com]| برامج نسخ الأحتياطي [soft.bramjnet.com]| ادارة الملفات [soft.bramjnet.com]| تقارير الاداء [soft.bramjnet.com]| ضغط وفك ضغط الملفات [soft.bramjnet.com]| الصيانة والمعالجة [soft.bramjnet.com]| ادارة النظام [soft.bramjnet.com]| برامج تحرير الذاكره [soft.bramjnet.com]| الحفظ الاحتياطي [soft.bramjnet.com]| برامج الاداره والتحكم [soft.bramjnet.com]| برامج شبكات [soft.bramjnet.com]| برامج الحماية [soft.bramjnet.com]| برامج مكافحة الفايروسات [soft.bramjnet.com]|Read the rest of this comment...


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Microsoft
· Intel
· HotScripts
· Apple
· W3 Consortium
· More about Wireless
· News by cj


Most read story about Wireless:
First Ever GSM Cellphone Exploit

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer