Re: Private WiFi in hotel room; security/interference issues
Haudy Kazemi <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.general |
|---|---|
| Message-ID | <[email protected]> |
>> The WRT54G (avoid v5, G serials CDFBxxxx and GS serials CGN60xxxx) can do >> MAC address filtering and WPA (linksysinfo.org can point you to 3rd party >> firmware). In my area, the local Sam's Clubs have a decent stock of the >> older units (CGN10, CGN30). > >The only model my Sam's has (that's not for USB hookup) is the >WRT54GS-BP, with "SpeedBooster" (Item 136295). Is this one that >you'd recommend? Does the SpeedBooster really help? I've purchased a few of these -BP units from Sam's in the past, and inside the package the router was identical to the non-BP packages. I think the -BP refers to 'bubble pack', as the packaging is clear plastic rather than a cardboard box. You can still read the serial numbers of the routers on these packages, so be sure to avoid any WRT54G units beginning with CDFB or WRT54GS units beginning with CGN60 (AFAICT Sam's currently only carries the WRT54GS). Another wireless forum had postings suggesting that the 'best' of the preferred versions are CGN00, CGN10, and CGN40. For details on the various versions, see http://www.linksysinfo.org/modules.php?name=Content&pa=showpage&pid=6 >> >Also, I assume that the laptops will be running some version of windows >> >- if XP - DON"T let windows autoconfigure - manually set it up & it >> >can't accidentally roam to another network. > >We'll be running Linux most of the time, but thanks for the warning. > >> BTW, hidden SSIDs make it easier for your Windows PCs to 'roam' to another >> network, away from the hidden network. (I don't recommend the hidden SSID >> route.) > >Interesting! /Insecurity/ through obscurity ... per the link sent by Gary, http://web.archive.org/web/20050310225841/http://www.tisc2001.com/newsletter s/416.html : 'The SSID of a WLAN is readily exposed in the normal operation of MOST WLANs, even when the APs are configured to 'hide' the SSID. It is the actions of the STAs that exposes the SSID. When SSIDs are 'hidden', there is additional WLAN management traffic that adversely effects the WLAN's and a roaming STA's performance. SSIDs are not passwords; they are community labels that any device can assert to claim membership in a WLAN community. Attempts to hide the SSID are a false sense of security, and should not be pushed by the security professional. This practice adds to the workload of the already over-worked security and network administrators, while not returning any real benefit for their labors.' http://www.extremetech.com/article2/0,1697,760477,00.asp 'XP keeps a list of all the access points to which it has ever connected. Then, when it starts up (or if it's out of range of any access point), it sends out inquiries to find out which ones are in range. Since the inquiries contain the SSID of each access point, it's easy to sniff out the hidden SSID.' http://www.practicallynetworked.com/networking/122905wireless_sanity.shtml 'By default, most access points broadcast their SSID. This allows your connection manager to see their presence and tell you, "Hey, buddy: this access point is in range." Some people prefer to hide their SSID by configuring their access point not to broadcast. In this case, you manually set the SSID in your connection manager to link the connection. The problem with Wireless Zero Configuration occurs if a second AP is also within range. If that AP is broadcasting its SSID, WZC will attempt to connect to it even if youve told it that your AP with the hidden SSID is your preferred network. Whether or not WZC can establish a connection with the more promiscuous AP, its attempts can cause instability in your link. Disabling SSID broadcasting is sometimes suggested as a security precaution. The theory is that your AP wont advertise its presence to nearby snoops. In fact, this doesnt provide much security at all. Whether or not it broadcasts its SSID, the AP includes the SSID in transmission packets which are easily sniffed out. In reality, disabling your SSID is no more secure than taping a broom handle across your steering wheel, hoping that thieves will mistake it for The Club. Secure your access point with WPA, or a MAC address filter. Enable SSID broadcasting, and WZC will treat you better.' (While disabling WZC is a way to work around this XP behavior regarding hidden SSID's; I maintain my stance on not hiding the SSID in the first place.) _______________________________________________ Talk mailing list [email protected] http://seattlewireless.net/mailman/listinfo/talk