Monday, August 11, 2008

Using WEP for secure communication

Using WEP for secure communication
Wired Equivalent Privacy, or WEP, is the first security standard for wireless networks. The
basic concept for WEP security is to encrypt the data that is sent back and forth between the
access point and the client adapter. This is done using various degrees of encryption strength. A
special key, known as the encryption key, is used by computers to connect to a WEP-protected
wireless network. This allows the client computer’s adapter to be able to decrypt and also send
encrypted messages in the same language as the base station.
This standard sounds like a great way to secure a wireless network. However, it presents some
flaws. The largest one is that the whole system relies on just one key. If someone’s laptop is
stolen that is part of a corporate network, the encryption key must be changed for the base
station and for all of the other computers using the wireless connection. This change is
necessary because the current encryption key could be easily extracted from the system settings.
Additionally, someone can potentially derive the encryption key by carefully analyzing the data
they intercepted.
If you have a wireless base station, I highly recommend that you enable WEP to protect your
home. Setting up WEP is different on every set of hardware, but the following are the basics:
1. Connect to your base station setting remotely using your Web browser. This address and
port number varies, but usually is http://192.168.1.1 or http://192.168.2.1. Often, the
port number is changed to 8080 so people don’t think you have a Web server running. In
that case, try http://192.168.1.1:8080 or http://192.168.2.1:8080.
2. Once you connect, you usually are asked for a password. For all Linksys hardware, the
Username field is left blank and the password is admin. Other hardware manufacturers
use some sort of a variation of the above. It also would be a good idea to change the
password to something other than admin when you are working in the administration
settings.
3. Locate the WEP settings and specify the encryption strength in bits. Then, come up
with an encryption key and type that in.Write down your encryption key and strength
for use in step 5.
4. Save your changes. You can now close the Web administration site.
5. The last part of setting up WEP is configuring the client computers that will connect to
the base station. Once again, this information varies, depending on your wireless card.
Consult the manual for your card to find out how to set up your card to use WEP.
Setting up WEP will greatly increase the security of your wireless network. Even though there
are some flaws, it is much better than using no protection at all. It has the same effect as a car
alarm. If a burglar has to choose between a car that clearly has an alarm or one that doesn’t,
which one will they choose to break into?

No comments: