Will the real Wireless security procedure please stand up?

James Colbert

New member
Guru
Local time
7:29 PM
Messages
1,127
Location
Ellesmere Island
When I set up my (only on when needed) wireless network, I researched many tutorials, security schemes and 'expert' opinions. So how can it be that what some say are essential steps to truly securing your wireless network, others say are myths and, in fact, detrimental to security?

Having read the information at the links provided, I've come to believe the latter.

First, a tutorial on these forums:

http://www.sevenforums.com/tutorials/105015-wireless-security-how-protect-your-network.html

Note the recommendations to disable SSID broadcasting, use MAC filtering and turning off DHCP.

Even Linksys endorses some of these practices:

Linksys | Learning Center

Now read the information at these links (below). They not only contradict these methods, but condemn them as 'security suicide':

The six dumbest ways to secure a wireless LAN | ZDNet

Wireless LAN security guide - By George Ou

How to break MAC filtering (wifi security)

MAC filtering seems to be the largest security vulnerability here...It seems that any MAC address entered in the permit filter is automatically allowed in...no password authentication required!(?) With the right freeware, anyone can determine your MAC address and spoof it. One article analogizes this to using an ID card which anyone can steal and walk right in the front door with no one to stop them.

One wonders, if the 'accepted' practices of filtering, SSID disabling, etc are so detrimental to security, why do thes "myths" continue unabated?

I myself have disabled MAC filtering. SSID broadcast disabling doesn't seem to be a large issue, so I'll wait to re-enable that when more data is in.

Not mentioned yet is a strong password. This may be the best defense, coupled with a strong security protocol (such as WPA, WPA2) and encryption. Is there more?

I'd be interested in hearing form the security experts amongst us. Any other links or information (on wireless or CAT5 networks) are very welcome!

James
 
Last edited:

My Computer My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
Use both MAC Filtering and a strong Password. The SSID doesn't matter, it won't have an impact on security one way or the other. Turning off or on DHCP will not affect security. DHCP just manages handing out IP addresses (and other network information) so you don't have to do it manually.

But yes, use both MAC filtering and a strong Password/Encryption the strongest your Wireless Hub/Card can support.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
use both MAC filtering and a strong Password/Encryption the strongest your Wireless Hub/Card can support.

But doesn't MAC filtering leave one susceptible to MAC spoofing? From what I've read (and admittedly, this doesn't seem clear), MAC filtering authenticates a MAC address and thus does not require the password. Is this correct?
 

My Computer My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
The way I understand this to work is that if using mac filtering you must be on the allowed list and enter the password - this is the way it has always worked on the many different routers that I have used in the last 30+ years.

as for the non display of the SSID this is a simple but effective security system - If a potential hacker cannot see the network as existing then they are less likely to try to hack it
 

My Computers My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
The way I understand this to work is that if using mac filtering you must be on the allowed list and enter the password - this is the way it has always worked on the many different routers that I have used in the last 30+ years.

Hi Barman,

That's the way it should work, but in my readings, there seem to be vague implications, but nothing that outrightly states that permitted MACs must also use pw authentication. Seems a no-brainer, but I'd really like to see a definitive statement on the matter rather than set up wireless networks only to find out later that I left a gaping security hole. I just can't seem to find an authorative article plainly stating that (likely) reality.

as for the non display of the SSID this is a simple but effective security system - If a potential hacker cannot see the network as existing then they are less likely to try to hack it

That's what I thought, until I found this MS article last night (incidentally, I have SSID set to hidden, also MAC filters and strong, strong password and encryption passphrase):

Non-broadcast Wireless Networks with Microsoft Windows
 

My Computer My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
That's the way it should work
It comes down to how you configure it and if your hardware allows you to do. Having both MAC Filtering and a strong password is security in depth. However, as far as I know all of them support MAC Filtering and Passwords because that Password is part of the encryption key. Without it the encryption will fail. And no the Wireless HUB never sends the full-encryption key to any computer.

Now as for SSID, you only are hiding one part of it. There are several ways to actually see a wireless network. Just because it doesn't broadcast an SSID does not make it invisible. Any serious attacker will get around that in a jiffy.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
All that anyone can do with regards to data security is to assess the level of protection applied, potential loss involved and likelihood of attack. No system is 100% secure all we need to do is make the system more difficult to break than the next persons system, so that the hacker movs on to the easier target.

Home users are unlikely to be targeted directly by the professional hacker, the potential return is just not there. It is more likely that the security discussed here will deter the casual opportunist looking for free wireless access, (these are unlikely to be using network sniffers,in any case).

The use of limited accounts protected with secure passwords at the file level, firewalls, and the best available wireless security should suffice to prevent all but the most determined attack.

in a business environment the stakes are higher as is the likelihood of attack, and then the more advanced systems are viable. I have worked with systems where all data drives were physically removed from site outside of working times, so the security levels can vary tremendously.
 

My Computers My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Thanks Barman and logicearth. I appreciate the input. I'm going to play around with some neighbors wireless networks (with permission, of course :) ) just to see what I come up with. I'll post back if anything of interest is discovered.

James
 

My Computer My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
Just updating for those who may turn up this thread in google...as mentioned, mac filtering is an additional layer of security rather than a free pass in for spoofers (i.e., passphrase still necessary).

Here is a pretty good primer on wireless security:

Wireless Wi-Fi network security tutorial 101 (part 1)

Note that it is 4 parts. The link to part two is near the end of the article, with subsequent links in subsequent parts.

Here also is a link to the Technologies branch of this site, which contains a lot of good info:

Technologies (IT & IS)

James
 

My Computer My Computer

OS
Win7U 64 RTM
CPU
Q9550
Motherboard
GA-EP45-UD3R
Memory
8GB Gskill
Graphics Card(s)
ASUS|EAH4850/HTDI/1GD3/A
Sound Card
xfi Plat
Monitor(s) Displays
Dell 2405fpw
Screen Resolution
1920x1200
Hard Drives
Seagate & WD sata Drives
PSU
Antec
Case
Antec
Keyboard
MS Natural Ergonomic 4000
Mouse
Logitech MX610 USB Cordless
Back
Top