WiFi Security for Small Businesses

This Blog is about WiFi Security news and comments targeted for Small Business Owners and the WiFi Community at Large.

Tuesday, January 1, 2008

So You Think Your Wi-Fi Network is Secure?

Wi-Fi networks deliver tremendous benefits. They provide the ability to connect to the Internet almost anywhere at anytime. You can connect in your home, office, or the coffee shop without being tethered to a wall jack, and Wi-Fi is built into most laptop PC's.

Wi-Fi is also easy to set up if you don't think about security. Out of the box, you can quickly turn on your wireless network, and connect your without much effort. Without security however, everyone else can connect to your network with the same ease. If you don't take the steps to secure your wireless network everything you do over the wireless network can also be seen by hackers up to a mile away.

Who Needs Wireless Security?

One of the common reasons why users don't secure their Wi-Fi networks is that no one wants access to their network or that there is no important information on the network to worry about. Hacking is less about joy-riding on someone else's network and more about the financial payoff that can be gained by stealing confidential or personal information over the network. In fact, over half of cyber crimes are now committed over Wi-Fi networks, because they provide anonymity that wired networks don't provide.

With a poorly secured Wi-Fi network, a wireless hacker can read your email, see the websites you visit, and even access files on your system that aren't properly secured. Your e-mail username and password are easily picked off an unsecured Wi-Fi network when every time your email is updated. Once your e-mail account is compromised, it becomes very easy to gain personal identity.

Another common misconception is that Wi-Fi can only be accessed from 300 feet away. With a $50 antenna, a hacker can access your Wi-Fi network from a mile away, out of sight and undetectable.

War drivers looking for unsecured networks, locate and record Wi-Fi networks. They then share those locations on websites such as www.wigle.net for other war drivers and hackers to find and user those networks.

Why Are So Many Networks Unsecured?

While setting up a Wi-Fi network is easy, turning on security takes some technical expertise and the ability to understand terms like WEP, WPA, 802.1x, and EAP. While wireless equipment manufacturers provide access to these security parameters, very few of them make it easy to understand, or easy to set-up.

Wi-Fi Security for Dummies

There are 4 basic levels of Wi-Fi security: "Open" (unsecured), WEP, WPA-PSK, and 802.1X. Let’s walk through these techno-acronyms and explain these basic levels of security in less technical terms.

  • "Open" is just that, open to all comers without any basic level of security. Like leaving your front door unlocked for anyone to enter, open networks are just a bad idea.
  • WEP is the lowest level of security available on most Wi-Fi networks. Unfortunately, WEP have fundamental flaws that make it easy to hack and software on the Internet can crack WEP security in 10 minutes. WEP is equivalent to locking your screen door; it may keep your neighbor out, but it takes little effort to break in.
  • WPA is the successor to WEP that is more difficult to crack. WPA is comparable to having a single lock on your front door, and giving a key to everyone you want to give access to. Keys can be shared or walked away with when someone leaves the network. The challenge with WPA is removing someone requires the entire network to be re-keyed and new keys re-distributed to valid users.
  • "802.1X" is called enterprise-level security because it provides the highest level of Wi-Fi security available. 802.1X is widely deployed by Fortune 500 companies and eliminates the common key problem by providing a unique key for each valid user every time they enter the network. This is analogous to the room key used in hotels. Each authorized user gets a new unique key every time they enter the network valid only for the time they are on the network.

802.1x typically requires a RADIUS server, which takes training and some technical work to deploy and maintain. This put the highest level of Wi-Fi security out of reach for most small and mid-sized businesses because of implementation costs.

Products like WiTopia's SecureMyWiFi Business Edition addresses the need for small and mid-sized businesses to quickly and easily deploy strong Wi-Fi security. It can deliver 802.1x enterprise level security for small and midsize business that can be set up in less than 15 minutes without any wireless or security expertise.

It's important that wireless network users understand the dangers of unsecured networks, and properly secure their networks. Open (unsecured) and WEP are poor approaches to Wi-Fi security. WPA, while complex, offers a base level of security, and 802.1x offers the best security available. Businesses are best advised to use 802.1x through either RADIUS server or the more simplified approach that WiTopia offers.

Labels: , , , , ,

Saturday, June 30, 2007

Wi-Fi Security for Dummies

There are 4 basic levels of Wi-Fi security: "Open" (unsecured), WEP, WPA- PSK, and 802.1X. Let's walk through these techno-acronyms and explain these basic levels of security in less technical terms.

  • "Open" is just that, open to all comers without any basic level of security. Like leaving your front door unlocked for anyone to enter, open networks are just a bad idea.

  • WEP is the lowest level of security available on most Wi-Fi networks. Unfortunately, WEP have fundamental flaws that make it easy to hack and software on the Internet can crack WEP security in 10 minutes. WEP is equivalent to locking your screen door; it may keep your neighbor out, but it takes little effort to break in.

  • WPA is the successor to WEP that is more difficult to crack. WPA is comparable to having a single lock on your front door, and giving a key to everyone you want to give access to. Keys can be shared or walked away with when someone leaves the network. The challenge with WPA is removing someone requires the entire network to be re-keyed and new keys re-distributed to valid users.

  • "802.1X" is called enterprise-level security because it provides the highest level of Wi-Fi security available. 802.1X is widely deployed by Fortune 500 companies with a RADIUS Server and eliminates the common key problem by providing a unique key for each valid user every time they enter the network. This is analogous to the room key used in hotels. Each authorized user gets a new unique key every time they enter the network valid only for the time they are on the network.

Labels: , , , ,

Wednesday, May 30, 2007

How TJX Data was Stolen Over a Wireless Network

The Wall Street Journal's article today - How Credit-Card Data Went Out Wireless Door - is a must read article for small and medium businesses using wireless networks. The article explains how hackers easily broke into the wireless network, sniffed out user credentials, and then used those credentials to get into the corporate network (presumable over a VPN) to access millions of customer credit card and social security numbers. The article talks about the devastating effect this breach had on TJX and it's customers and didn't even mention the impact it had on TJX's confidential internal data, which is probably something they don't want to talk about. This should be a call to action for any business using Wi-Fi. Make sure your Wi-Fi network is secure. A RADIUS server and 802.1X control that gives you control over individual access is best. At the very least, use WPA or WPA2 and make sure you change the encryption keys when employees leave the company. Witopia and DAZ Software provide great tools that makes RADIUS easy for small businesses. Companies like Interlink Networks provides a higher end RADIUS server that is better suited for larger enterprises and ISPs.

Labels: , , , ,

Friday, April 27, 2007

New WiFi Security Product

An interesting new WiFi security product is now in beta testing called WiFi Login Pro. I had the opportunity to review the product a few weeks back. It is quite a clever WiFi Security solution - it supports WPA & WPA2, but rather than requiring the user to set up certificates for EAP-PEAP or EAP-TTLS, it uses the POP3 mail server to authenticate the user and let them on the network. This WiFi security product supports up to 100 users, is cost effective ($199), and is targeted at small businesses that need the same level of WiFi security that large corporations use without the hassle of a full blown RADIUS server. WiFi Login Pro is actually a RADIUS server that runs on a Windows Vista, 2003, XP, or 2000 PC. Unlike the complex set up of a RADIUS server, WiFi Login Pro simplifies the set up with a straight forward wizard and allows you to use your pre-existing POP3 e-mail server to authenticate users access to the WiFi network. WiFi Login Pro is available as a beta version right now. If you're interested in seeing a beta copy go to their web site at www.dazsoftware.com and click onthe download link.

Labels: , , ,

Tuesday, April 3, 2007

The Five Deadly Dangers of Unsecured WiFi Networks

Once hackers have access to your WiFi network, they can readily capture personal and business information. There are two types of WiFi attacks. Passive attacks, where the hacker captures your network traffic, are almost impossible to detect because the hacker never joins your network. They can sit silently with their antenna tuned into your network and capture gigabytes of network traffic for off-line analysis at a later time. Active attacks, where the hacker joins the network, can be the most devastating because they can launch active attacks into the network and onto your devices on the network.

There are 5 attacks that WiFi hackers can very easily & readily perform on your wireless network with very little effort or expense. The first two are passive attacks, and the last 3 are active attacks. But make no mistake - all of these attacks can be deadly.

Deadly Attack #1: Account and Password Capture. There are several applications that send your account and passwords in clear text over the network. For example, every time a POP3 mail account checks for new e-mail, the account name & password are in the clear as part of the data transfer. Anyone sniffing the network traffic can easily get your e-mail account information. Once they have that information, they can access your e-mail account at their leisure, monitoring for personal information without leaving a trace. From there, any confidential information they can get from your account just escalates their attack.

Deadly Attack #2: E-mail, IM and Web Site Traffic Capture - It is very easy to monitor and capture all of the e-mail traffic sent over an unsecured wireless network. Since most e-mail is sent in clear-text, and instant messaging is sent in HTML, it's very simple to capture the traffic and mine the traffic off line for any “interesting” information at a later time. By monitoring your wireless traffic, all of the HTML data can be captured & reconstituted as web pages on the hackers PC to see exactly what web sites & content you are surfing over the wireless network.

Deadly Attack #3: Accessing Data on Your PC. Let's face it, it's pretty easy to turn file sharing on, and then forget to turn it off when you attach to an open WiFi network. Once file sharing has been left on or the personal firewall is mis-configured, a hacker can readily access you PC and hard drive across the wireless network. Firewalls are also easy to mis-configure or turn off, and forget to turn back on. With older versions of Windows (NT, W2K), if improperly configured, it's easy prey for a hacker to get in over the network, log-in as a null session and take over your platform.

Deadly Attack #4: Access to the Corporate Network. If you’re wireless network is connected to a corporate network through a site-to-site VPN, an open wireless network punches a hole through the network, and opens up both sides of the VPN to anyone attaching to the network. Another threat is with improperly configured client VPNs which can be more easily compromised to provide the hacker access through the VPN.

Deadly Attack #5: SPAM and Virus Launching over the Wireless Network. Unsecured Networks provide are an ideal launch point from which hackers can launch SPAM & Virus attacks because it is very difficult to track the source back to them. From a distance, the SPAMmer can launch the SPAM (from your e-mail account if he or she sniffed your e-mail account info) without repudiation. When the ISP or FBI tracks down the violator, the trail points to your network, and possibly your e-mail account. The liabilities to the owner of the unsecured network are still newly contended battlegrounds for the lawyers.

Hacking open networks isn't as hard as one may think. See this flash demonstration on the tools hackers use to crack WiFi networks.

Labels: , , , ,

Monday, March 19, 2007

The Benefits of Wireless Networks

It seems these days that wireless networks are everywhere.With Wi-Fi capabilities built into most new laptop computers, and with relatively inexpensive network adapter cards, Wi-Fi is within reach of most PC users.

The freedom and benefits of an un-tethered connection to your network are very compelling:

  • Create your network when wiring isn’t practical. Many office and warehouse spaces find it very difficult or impossible to lay wire for networking. Wi-Fi is a cost-effective and convenient alternative to a wired network.
  • Expand your network with no additional wiring costs. This is especially beneficial in home offices that aren’t pre-wired for Ethernet, or for small businesses that are rapidly expanding, or frequently reconfiguring their office layouts.
  • Information at your fingertips anywhere you work. The ability to access your e-mail, the Internet, and network-based applications in a conference room or another office gives you additional degrees of productivity and convenience.
    • Doctors can carry patient records on a laptop or tablet PC to each exam room and stay connected all the time.
    • Lawyers can bring their lap tops into depositions and conferences and fact check or access networked data instantly.
    • Project members can collaborate in team meetings each with instant information available across the wireless network to accelerate decisions with immediately available information.
    • Wireless at home means delivers the ability to work anywhere in the house, or deck. The ability to be around your family when you’re catching up on e-mails is truly convenient.

Beware the Dark Side

Despite the benefits, there is a dark side to wireless. Without the proper security measures in place, your business and personal information can easily be retrieved over the wireless network. With a $100 directional antenna and free software available on the internet, hackers can access your network traffic and PC data from as far as a mile away.

In June 2004, a world-wide “war drive” event among the hacker community uncovered over 230,000 wireless networks and posted their positions on the Internet. A startling 61.6% of all the networks they surveyed had no security whatsoever, and the majority of the other networks had the weakest form of security that can be cracked in under 15 minutes.

Wireless Security has tremendous benefits, especially when secured and properly managed. Pay attention to the security and gain the benefits without the risks.

Labels: , , , ,

Thursday, January 25, 2007

WiFi Security is Essential for Small Business Networks

Over 60% of the wireless networks used by small and mid-sized businesses are unsecure, leaving the door wide open to hackers to steal personal identity and confidential corporate information, access computer networks, and launch attacks from the business networks. Many businesses do not understand how vulnerable they are to attack over their WiFi networks.

WiFi Security is essential - using WPA or WPA2 technology. Set it up and use it. There are a number of small business WiFi Security Servers out there (based on RADIUS technology) that can hide many or most of the technical details. Don't let hackers pull your passwords, business and personal information off your wireless networks.

Labels: , ,