Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > Security with Manged Access Point

Reply
Thread Tools Display Modes

Security with Manged Access Point

 
 
Phil A. Buster
Guest
Posts: n/a

 
      01-26-2008, 08:00 PM
In an apartment building wireless is available with a login provided by the
landlord. The tenant selects the connection and is prompted for a username
and password and then has Internet access. However, it appears that the
connection is not encrypted in that the user is never asked for a WPA or
other key and Windows warns about it. I'm not very familiar with this
type of managed access and wondering how secure it is. Am I correct in
thinking that this probably is unencrypted and vulnerable to sniffing or is
it possible that there might be some kind of secure tunnel established after
the logon?
Thanks.
--



 
Reply With Quote
 
 
 
 
Jeff Liebermann
Guest
Posts: n/a

 
      01-27-2008, 04:00 PM
"Phil A. Buster" <(E-Mail Removed)> hath wroth:

>In an apartment building wireless is available with a login provided by the
>landlord. The tenant selects the connection and is prompted for a username
>and password and then has Internet access. However, it appears that the
>connection is not encrypted in that the user is never asked for a WPA or
>other key and Windows warns about it. I'm not very familiar with this
>type of managed access and wondering how secure it is. Am I correct in
>thinking that this probably is unencrypted and vulnerable to sniffing or is
>it possible that there might be some kind of secure tunnel established after
>the logon?


If your wireless client manager indicates that the connection is not
encrypted, then you are susceptible to sniffing, session hijacking,
and impersonation. Whatever you're using for a connection manager
should show the current connection status and protocols used.

However, WPA-RADIUS does not ask for an encryption key. The encyption
key is supplied by the RADIUS server. You also authenticate with the
RADIUS server using a login and password as you described. It is one
of the most secure forms of wireless connectivity. Your connection
manager should show that you're using WPA-RADIUS or WPA2-RADIUS (also
known as WPA-Enterprise) if this is the case.

Even if your sessions are not encrypted, you can setup a VPN tunnel,
to a secure server to prevent sniffing. See the FAQ at:
<http://wireless.wikia.com/wiki/Wi-Fi#VPN>
for candidates. These are designed for secure surfing at "public"
access points.

--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
 
Reply With Quote
 
Phil A. Buster
Guest
Posts: n/a

 
      01-27-2008, 04:37 PM
"Jeff Liebermann" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> "Phil A. Buster" <(E-Mail Removed)> hath wroth:
>
>>In an apartment building wireless is available with a login provided by
>>the
>>landlord. The tenant selects the connection and is prompted for a
>>username
>>and password and then has Internet access. However, it appears that the
>>connection is not encrypted in that the user is never asked for a WPA or
>>other key and Windows warns about it. I'm not very familiar with this
>>type of managed access and wondering how secure it is. Am I correct in
>>thinking that this probably is unencrypted and vulnerable to sniffing or
>>is
>>it possible that there might be some kind of secure tunnel established
>>after
>>the logon?

>
> If your wireless client manager indicates that the connection is not
> encrypted, then you are susceptible to sniffing, session hijacking,
> and impersonation. Whatever you're using for a connection manager
> should show the current connection status and protocols used.
>
> However, WPA-RADIUS does not ask for an encryption key. The encyption
> key is supplied by the RADIUS server. You also authenticate with the
> RADIUS server using a login and password as you described. It is one
> of the most secure forms of wireless connectivity. Your connection
> manager should show that you're using WPA-RADIUS or WPA2-RADIUS (also
> known as WPA-Enterprise) if this is the case.
>
> Even if your sessions are not encrypted, you can setup a VPN tunnel,
> to a secure server to prevent sniffing. See the FAQ at:
> <http://wireless.wikia.com/wiki/Wi-Fi#VPN>
> for candidates. These are designed for secure surfing at "public"
> access points.
>
> --
> Jeff Liebermann (E-Mail Removed)
> 150 Felker St #D http://www.LearnByDestroying.com
> Santa Cruz CA 95060 http://802.11junk.com
> Skype: JeffLiebermann AE6KS 831-336-2558


Thanks! That's very helpful.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless switch / access point WEP security windsurferLA Wireless Internet 4 06-16-2008 06:48 AM
When Security enabled, no access point available? Frank Wireless Networks 1 07-04-2005 07:17 PM
news: New WiFi Security Isse "The Eveil Twin: Access Point helpster Wireless Internet 0 02-06-2005 07:44 AM
Add an access point or buy a combined modem/router/access point? Martin Home Networking 2 12-16-2004 01:20 PM
Access Point with Security for MN-500 Brandon Broadband Hardware 1 01-22-2004 09:18 AM



1 2 3 4 5 6 7 8 9 10 11