Full Newsletter   Newsletter Archives

  Stambaugh Ness    SN Business Solutions               



Printable version 

By Kenneth Saxe, MCSE, MCSA, MCPS, MCNPS, CNE
Senior Technical Consultant
Stambaugh Ness Business Solutions, LLP

Wireless use has skyrocketed over the last 24 months. Not only is wireless available in libraries, coffee shops, hotels, fast food restaurants, but many cities now offer free wireless in their downtown areas.

In addition, many homeowners have added wireless Internet access in their homes for the flexibility for themselves and their children. While driving through most neighborhoods it is not uncommon to have 802.11 wireless-enabled PDAs or cell phones dinging and bleeping to signal their owners that wireless is nearby.

Unlike its wired counterpart, 802.11 wireless is considered to be inherently less secure. So most early wireless routers came with WEP. Developed in the 1990's, WEP is short for Wired Equivalency Privacy and it is a security protocol for many Wi-Fi networks. It wasn't long after its introduction that rumors arose that WEP was easy to crack. Shortly thereafter at security conferences worldwide these cracks were successfully demonstrated. Today there are many easily downloadable WEP hack and crack programs that make accessing a WEP secured wireless network accessible in just a few minutes.

In an effort to offer additional security to wireless networks, wireless router manufacturers began including WPA and WPA2 (Wi-Fi Protected Access). Supposedly WPA and WPA2 certified wireless routers were impermeable to hackers.

However, over the last week the mainstream media has reported that two researchers, Erik Tews and Martin Beck, have found a way to crack WPA in only 15 minutes. There was mayhem in the technology community. Those that thought they were secure with WPA or WPA2 were now very concerned. 

When you peel back the onion of Tews' and Beck's research, several truths come to light. The conclusion is this panic was unnecessary and unwarranted. The bottom line is this WPA crack is not a major concern at this point and can be easily rectified.

First: The crack will only work on certain types of wireless routers. For the crack to be possible to attempt, your router must support QOS (quality of service). Many home and small business wireless routers do not support QOS. However, if your router does, simply disable it. Unless you are running Voice over IP through your wireless router, you typically would not be using QOS anyway.

Second: The crack revolves around TKIP. TKIP stands for Temporal Key Integrity Protocol and is an encryption protocol included as part of the IEEE 802.11i standard for wireless LANs. In most cases, TKIP can be disabled or an alternate protocol can be selected thereby making the crack completely useless against your wireless router.

The bottom line is this: If you disable QOS and TKIP this supposed WPA crack should be of no concern to you or your wireless security.

If you or your organization have not yet benefitted from the expertise of the SNBS staff, please take your concerns to Ken at 717-757-6999 or 800-745-8233, or send him an email by using the form below.

Along with the many technical services they offer, SNBS provides Internet and website consulting services.

IT STAFF PROVIDES COMMUNITY SERVICE

Our Business Solution folks do more than work with machines and software - they work with people, too. Check out two of their latest Community Service adventures in these past articles:

SN's Technology Professionals Plug into Katrina Restoration Effort (January 23, 2008 issue)
SN Volunteers assist with Convoy of Hope (July 23, 2008 issue)



 Save article  Email Firm  Email to a Friend
Is this item worthy of implementation? Yes No Maybe
Is this item worth sharing with other associates? Yes No Maybe
Did this item present value to you and your business? Yes No Maybe
Comments:

Our firm provides the information in this e-newsletter for general guidance only, and does not constitute the provision of legal advice, tax advice, accounting services, investment advice, or professional consulting of any kind. The information provided herein should not be used as a substitute for consultation with professional tax, accounting, legal, or other competent advisers. Before making any decision or taking any action, you should consult a professional adviser who has been provided with all pertinent facts relevant to your particular situation. Tax articles in this e-newsletter are not intended to be used, and cannot be used by any taxpayer, for the purpose of avoiding accuracy-related penalties that may be imposed on the taxpayer. The information is provided "as is," with no assurance or guarantee of completeness, accuracy, or timeliness of the information, and without warranty of any kind, express or implied, including but not limited to warranties of performance, merchantability, and fitness for a particular purpose.

IRS Circular 230 Notice: To ensure compliance with requirements imposed by the IRS, we inform you that any US tax advice contained in this communication is not intended or written to be used, and cannot be used, for the purpose of avoiding penalties under the Internal Revenue Code.