Subject: Re: Maximising IKE/IPSec security?
To: Dmitri Nikulin <dnikulin@optusnet.com.au>
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
List: tech-security
Date: 04/17/2005 01:58:38
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Dmitri" == Dmitri Nikulin <dnikulin@optusnet.com.au> writes:
    Dmitri> Good thing I decided to just do away with WEP: extra
    Dmitri> administration and processing overhead (IPW 2200BG has
    Dmitri> software WEP) for chewing-gum security. It should be illegal
    Dmitri> to continue calling it 'wired equivalent' and especially
    Dmitri> advertising it as security. From what I hear everyone and
    Dmitri> their dog can bring a sufficiently powerful laptop and
    Dmitri> subvert arbitrary WEP networks just off battery power - but
    Dmitri> I hope it's not that severe.

  Breaking the WEP might get you into the network, but far easier is
to just put up a fake network with the same ESSID.  That's the real
sadness of wireless "security" --- it fails to deal with attacks on
the infrastructure itself.

- -- 
] Michael Richardson          Xelerance Corporation, Ottawa, ON |  firewalls  [
] mcr @ xelerance.com           Now doing IPsec training, see   |net architect[
] http://www.sandelman.ca/mcr/    www.xelerance.com/training/   |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQmH7DIqHRg3pndX9AQGEFwQAgmaYXS0EKrIgWtHzMonTCisQZ0G5SPPZ
3HfYjDfMWnCFXiIRCc10TKzY0goFT79w2mfP31Vgorhk2Z/j0RXMFO4xe5Y7per5
MGHr2/gzxtT0eKpWLGB1eC50CYwKAdSMEzxIjbKu0BKPwOAi9qM6VxUvtNcbT7Dp
6SJ3LVYID6k=
=SUd9
-----END PGP SIGNATURE-----