Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

 
NetNews
N E W S / A N A L Y S I S  


Fear-Mongering In Las Vegas

  May 29, 2003
  By Dave Molta


TOC Issue TOC
Printer Print full article
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author

Fear is a powerful emotion, and it's been used for years to sell products. Afraid someone might break into your home? We sell a deadbolt lock. Scared you might get hurt in a traffic accident? Our latest SUV has airbags and crumple zones.

Wireless hackers are the latest concern in the tech industry, and the problem is, indeed, serious. Security protocols have been poorly designed, and the broadcast nature of radio networks makes them vulnerable. But we can do without the scare tactics used by some vendors to push products.

The latest case in point is a press release issued by AirDefense, a developer of WLAN security products, which highlighted what it considered lax security at the recent NetWorld+Interop show in Las Vegas. Using one of its probes installed for two hours on the show floor, AirDefense identified 230 access points and 824 wireless stations. And guess what--these systems weren't secure.

Of course the show floor's wireless network wasn't secure! In fact, it was a total RF nightmare. One of the vendors I visited on the floor ran a NetStumbler scan and discovered access points on every possible 802.11 channel. If there was a message here, it was the amazing discovery that you could transmit an 802.11 frame over the airwaves without errors in what could possibly be the most WLAN-hostile environment ever created.

But that wasn't AirDefense's take on the situation. The fact that the company was able to use "just one of its remote sensors to monitor all wireless LAN traffic in the 100,000-square-foot showroom" must provide tremendous comfort to potential customers whose buildings look like convention halls. But I'd bet most of your buildings have walls. Even more preposterous was AirDefense's summary of problems that "exposed network traffic and opened devices to attacks and other security threats." For example, 92 of the 230 APs didn't authenticate or encrypt traffic. Imagine that. Equally shocking, 95 APs experienced excessive network interference, which forced them to retransmit more than half of the time.

Let's not minimize the security challenges associated with WLAN implementations. And though probe products, such as those offered by AirDefense, may be appropriate for some organizations with rigid security requirements and big budgets, the real news is this: First, don't trust public wireless networks at trade shows. And second, select a WLAN infrastructure provider that can provide adequate security capabilities.

Post a comment or question on this story.


Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Next Generation Data Center, Delivered, November 17th
NWC


Salary

Video