BYTE.com > Chaos Manor > 2003
Travelin' Blues
By Jerry Pournelle
June 2, 2003
(Travelin' Blues
: Page 1 of 1 )
Column 274 (Continued from the Previous Week)
Wi-Fi Blues
Wi-Fi works, and everyone loves it, but it can be a security nightmare, and some of that nightmare is built in. When you turn on a Wi-Fi card in a system, it goes out looking for wireless access points. When you find one and log on, all is well. Let's say you have found an access point on a network called WinHEC2003 for example. You're using it to connect to the Internet. Now you go into another room, out of range of the access point. You are disconnected because your Wi-Fi card can't see the other network.
What happens next is odd: If your Wi-Fi card can't find the network it was connected to, it may create a new one with that name! This one is peer-to-peer without an access point. Moreover, your card broadcasts to the world that this network exists, although you are probably unaware of that. The easy way to prevent this is to turn off your Wi-Fi when you aren't using it, but suppose you forgot.
Now another user turns on his Wi-Fi system, and it looks for networks. Let's suppose this guy is midway between you and the original access point to the "real" WinHEC2003 network. Chances are good that his system will see both. At one point in the Internet Cafý at WinHEC I saw seven nets named WinHEC2003. Six of them were peer-to-peer, but if you don't read the fine print when you connect to the network you may not notice that.
It gets worse. It's possible for me to connect to your machine through one of those pseudo-WinHEC2003 nets, and if you have any public shared files I can see them, and if you don't have write protection enabled I can leave you a folder called MY VIRUS on your machine, and indeed we did that to some unsuspecting chap late this evening. Of course the folder was empty, but it didn't have to be.
The moral of this story should be obvious. First, go into your wireless network properties, and find the advanced properties. Tell it to connect to access points only.
Page 1 of 1
BYTE.com > Chaos Manor > 2003
|