Wireless Routers and Encryption

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Wireless Routers and Encryption

Post by Wally Balljacker » Mon Feb 26, 2007 9:05 pm

lately I've been toying with the idea of turning encryption off on my router for a few reasons. The first being, using WPA encryption is a pain in the ass, and it impacts performance and reliablity. I can't even count how many times my laptop has refused to connect to my AP, or completely dropped the connection and quit working. The second is, I use open WiFi networks all the time, and I feel like i should be giving back. So, my question is, do you guys use encryption? Is it safe to leave an access point open and keep your systems secure?

User avatar
Linc
Site Admin
Posts: 345
Joined: Mon Apr 26, 2004 11:54 pm
Contact:

Re: Wireless Routers and Encryption

Post by Linc » Mon Feb 26, 2007 9:22 pm

Wally Balljacker wrote:lately I've been toying with the idea of turning encryption off on my router for a few reasons. The first being, using WPA encryption is a pain in the ass, and it impacts performance and reliablity. I can't even count how many times my laptop has refused to connect to my AP, or completely dropped the connection and quit working. The second is, I use open WiFi networks all the time, and I feel like i should be giving back. So, my question is, do you guys use encryption? Is it safe to leave an access point open and keep your systems secure?
While I don't keep my access point completely open, I only use mac address filtering for the reasons you already stated. The only thing you should pay particular attention to is your EULA agreement with your ISP. Many of them have issues with you sharing your bandwidth publicly. If your ISP is cool with it, and you can afford the bandwidth, it's a noble venture afaic.
-Linc Fessenden

In the Beginning there was nothing, which exploded - Yeah right...

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Mon Feb 26, 2007 9:32 pm

I used to DMZ my WAP and leave it open. In San Diego I'd get between 20 to 50 unique MACs pulling IPs per day. In Santa Fe I'd get 1 or 2 a week. Sometimes I'd sniff traffic for grins - it's amazing the # of people who are stupid enough to steal bandwidth but use unencrypted protocols.

I wonder why you're having so many issues with WPA though.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

chuck
Posts: 141
Joined: Wed Nov 02, 2005 6:51 pm

Post by chuck » Mon Feb 26, 2007 9:38 pm

I've never noticed a significant speed loss using encryption. I do not run any of my wireless networks unencrypted for privacy reasons. At some small companies that I've set up public wireless access for using IPCop we've allowed the wireless to go out to the net through the proxy and throttled the bandwidth, while keeping them off the internal network.

If you don't segment the public, you will tend to be abused at some point. Your network will be vulnerable.

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Post by Wally Balljacker » Mon Feb 26, 2007 10:01 pm

Thanks for the input. Would tunneling a web browser/IM Client over SSH be secure? Is there any way for someone to sniff packets before or after they go through SSH?

Looks like it's against Comcast's Terms of Service to share wifi. They also forbid running servers at home. :cry: :cry:

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Tue Feb 27, 2007 9:49 pm

Wally Balljacker wrote:lately I've been toying with the idea of turning encryption off on my router for a few reasons. The first being, using WPA encryption is a pain in the ass, and it impacts performance and reliablity. I can't even count how many times my laptop has refused to connect to my AP, or completely dropped the connection and quit working.
Are you sure you don't have something in your walls that may block the signal, or cause a slight interference? It's not a good idea to place stuff like microwave ovens close to wireless access point (or router). Also, there could be other sorts of radio interference. If this behavior is only noticeable with WPA enabled, try stealing a friend's router while he's on vacation and see if it has the same problem. If it does, try a different WiFi card.
If working correctly (In the sense of no interferences), WPA should cause no loss of reliability and only a very thin bit of additional wordload that WEP.

Wally Balljacker wrote:The second is, I use open WiFi networks all the time, and I feel like i should be giving back. So, my question is, do you guys use encryption? Is it safe to leave an access point open and keep your systems secure?
Well, I don't actually have a wireless network, but I have "bugfixed" and set up a bunch of them for friends. I think encryption is sort of a must have. I don't want some stupid-ass 14 year old (Many 14 year olds aren't stupid, but many are) using my internet connection to download music off of some spyware riddled file-sharing network, and get me in trouble for it. I know some people have been able to say "My WiFi network was open, and I know it wasn't me, so it must have been some n00b!!", well, the RIAA won't buy those forever, because they can just tell a judge something like "Well, if he didn't want people to use his network for illegal stuff, he should turn on encryption", and if you argue that that is either too difficult or something, the RIAA could just throw you an RTFM and told you to look at the router manual to figure out how to enable encryption. Also, the dumb 14 year olds that I know of, all have their "oh so hip gaming rigs" riddled with spyware and worms, and for completeness of this topic, to people with Windows boxes, the thing that generally has killed worms like Blaster is that routers just block it, and then people feel OK about disabling Windows built-in firewall, but if some moron gets on your network, you're toast!

Also, regarding to you being secure on an unencrypted wireless network. Unless you use something to encrypt your traffic, while it's in the air, then I can just grab it, no matter how much time you have spent on hiding your SSIDs, or tweaking your MAC address filtering ( :lol: ).


Linc wrote:
Wally Balljacker wrote:lately I've been toying with the idea of turning encryption off on my router for a few reasons. The first being, using WPA encryption is a pain in the ass, and it impacts performance and reliablity. I can't even count how many times my laptop has refused to connect to my AP, or completely dropped the connection and quit working. The second is, I use open WiFi networks all the time, and I feel like i should be giving back. So, my question is, do you guys use encryption? Is it safe to leave an access point open and keep your systems secure?
While I don't keep my access point completely open, I only use mac address filtering for the reasons you already stated.
Since we're talking about wireless networking, and security issues around it, I just thought I'd refer to an earlier post of mine, because MAC address filtering is absolutely NOT security. It's like having a dog outside the door of your house that will bite everyone except the people you've explicitly told it not to bite, but if I have a gun and shoot the dog before trying to enter your house, no problem at all getting into your house.

I went into details about this here:
Wireless suggestions? #2


Linc wrote:The only thing you should pay particular attention to is your EULA agreement with your ISP. Many of them have issues with you sharing your bandwidth publicly. If your ISP is cool with it, and you can afford the bandwidth, it's a noble venture afaic.
It's not just "many" ISPs, pretty much no ISP allows sharing your internet connection with your neighbor.


Snarkout wrote:I used to DMZ my WAP and leave it open. In San Diego I'd get between 20 to 50 unique MACs pulling IPs per day. In Santa Fe I'd get 1 or 2 a week. Sometimes I'd sniff traffic for grins - it's amazing the # of people who are stupid enough to steal bandwidth but use unencrypted protocols.

I wonder why you're having so many issues with WPA though.
DMZing your wireless connection, now that's a really great idea, especially if you have access to true-DMZ possibilities, because a regular router won't isolate a DMZ computer from the rest of your LAN, it will just forward any incoming traffic to that machine, and if it gets compromised, well, once again you're toast in terms of security. A true DMZ separates the computers in the DMZ from the rest of the LAN, often the LAN machines can access the machines in the DMZ, but not the other way around, this way you're not screwed if some machine in the DMZ gets rooted.


chuck wrote:I've never noticed a significant speed loss using encryption. I do not run any of my wireless networks unencrypted for privacy reasons. At some small companies that I've set up public wireless access for using IPCop we've allowed the wireless to go out to the net through the proxy and throttled the bandwidth, while keeping them off the internal network.

If you don't segment the public, you will tend to be abused at some point. Your network will be vulnerable.
Firewall distros such as IPCop, m0n0wall, pfSense etc. offer a lot of extra stuff compared to your average D-Link or Netgear router, which can be used to aid in securing wireless, such as a true DMZ.


Wally Balljacker wrote:Thanks for the input. Would tunneling a web browser/IM Client over SSH be secure?
Oh yeah! Dude, who's gonna try to crack a 2048-bit RSA encryption? :lol:
By the time you would be done, mankind have already migrated to Mars, because we have foobared the Earth and then the sun toasted it.

Wally Balljacker wrote:Is there any way for someone to sniff packets before or after they go through SSH?
Nope, because the tunnel is set up before you start transmitting any of your actual data, and the data is not, in any way, exposed on the network before going into the tunnel, so you there's no way to sniff it, without first breaking into your machine and doing something that might do some weird things.

Wally Balljacker wrote:Looks like it's against Comcast's Terms of Service to share wifi. They also forbid running servers at home. :cry: :cry:
You're not allowed to run a server? Well, you can always use some nice encryption stuff so that they can't see what you're doing. To them, SFTP (OpenSSH's FTP-like feature) traffic looks just as garbled as running an X app over OpenSSH.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Tue Feb 27, 2007 10:47 pm

It's easier to do if you have cisco equipment, that's for sure. However, if you collect networking crap like I do/did it's pretty easy to DMZ with a wap a router and a switch.

modem
. . |
switch
| . . . |
| . . . WAP
| . . . . \
| . . . WLAN
|
router
. \
. . LAN
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Tue Feb 27, 2007 11:07 pm

Snarkout wrote:It's easier to do if you have cisco equipment, that's for sure.
I like to build stuff myself, so I'd just take one of my old computers, put three cheap NICs in it, and install pfSense on there, set up a DMZ and done deal!
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Post by Wally Balljacker » Wed Feb 28, 2007 12:23 am

Tsuroerusu wrote:
Snarkout wrote:It's easier to do if you have cisco equipment, that's for sure.
I like to build stuff myself, so I'd just take one of my old computers, put three cheap NICs in it, and install pfSense on there, set up a DMZ and done deal!
Not everyone wants some noisy, power-hungry PC running 24/7 tolling their electric bill.

I guess there is a "geek" factor involved with building a router/firewall out of an old computer, but in reality it seems like a waste of time and energy. There are so many cheap off-the-shelf routers that do a fine job, silently and reliably that are plug and play and consume very little power.

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Post by Wally Balljacker » Wed Feb 28, 2007 1:17 am

Tsuroerusu wrote:Are you sure you don't have something in your walls that may block the signal, or cause a slight interference? It's not a good idea to place stuff like microwave ovens close to wireless access point (or router). Also, there could be other sorts of radio interference. If this behavior is only noticeable with WPA enabled, try stealing a friend's router while he's on vacation and see if it has the same problem. If it does, try a different WiFi card. If working correctly (In the sense of no interferences), WPA should cause no loss of reliability and only a very thin bit of additional wordload that WEP.
I usually have my laptop sitting on my desk 12 inches away from my router. The problem isn't interference or my wireless card. I've experienced connection dropouts on several wireless routers using WPA on Windows, FreeBSD, and Linux. I'm not too worried about it, usually everything works fine, it's just frustrating when everything flakes out and I have to reboot my laptop and reconnect.

I think I recall Leo Laporte expressing similar issues with his wireless network. I doubt I'm the only one who has the occasional loss of connection.

chuck
Posts: 141
Joined: Wed Nov 02, 2005 6:51 pm

Post by chuck » Wed Feb 28, 2007 7:52 am

Wally Balljacker wrote:I usually have my laptop sitting on my desk 12 inches away from my router.
Oddly enough, this may be part of your problem. As an experiment you may want to move your wireless point across the room and see if the dropouts continue or not. I had to move my desk at work because I was sitting under the wireless AP and it was causing me issues that you describe. Since I moved another 8 feet away I haven't had an issue.

User avatar
Vogateer
Posts: 700
Joined: Thu Nov 17, 2005 11:18 pm
Location: Norman, Oklahoma
Contact:

Post by Vogateer » Wed Feb 28, 2007 8:01 am

There's someone at work with an HP laptop running XP and the blasted Broadcom wireless networking drops out constantly at every wireless place she's ever been to. Makes even email undependable. It seems like I can't even properly install the new wireless driver they put out.
Vim is beautiful

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Wed Feb 28, 2007 9:39 am

Wally Balljacker wrote:Not everyone wants some noisy, power-hungry PC running 24/7 tolling their electric bill.
Well, you could build a little quiet machine using a VIA mini-ITX motherboard, those don't use a lot of power, and I'm quite sure you could run it without a fan if you lowered the clock speed of the CPU a bit.

Wally Balljacker wrote:I guess there is a "geek" factor involved with building a router/firewall out of an old computer, but in reality it seems like a waste of time and energy. There are so many cheap off-the-shelf routers that do a fine job, silently and reliably that are plug and play and consume very little power.
Well, I'm really really tired of those routers, because they're not extendable, they often have limited functionality (Which of course is to get you to shell out more cash for a more expensive router), and often the manufacurer do a LOUSY job in releasing fixes for potential security problems, and at some point there's no more patches. Of course the Linksys WRT54G routers are somewhat of an exception. But still, I'd really like to use pfSense as my firewall, but I can't because there's no documentation available for the hardware in the WRT54G router, so FreeBSD can't support it.

If you're gonna buy an off-the-shelf router that does true a DMZ, good VPN server etc. etc. they're all of a sudden not so cheap, sure not everybody needs or wants this, but it's something I would want.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Wed Feb 28, 2007 10:41 am

You could split the difference and buy a soekris kit (or similar). I actually have a net4801 right here I initially had running as a router/firewall, but I eventually opted to set it up as a small server, and went back to a COTS router. IME linksys and their ilk do an admirable job for a home network. They suck as a replacement for a real router/firewall at an office of 50-100 people though.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Wed Feb 28, 2007 10:48 am

Snarkout wrote:You could split the difference and buy a soekris kit (or similar).
Ah yeah, I heard about those, a bunch of m0n0wall guys and some OpenBSD guys seem to really like these, but you know, eehhhmm, I don't like buying expensive equipment from outside of Denmark, because I like our consumer protection laws here :P :wink:
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

Post Reply