Alan Stevens
Alan Stevens

Gaps remain in Wi-Fi security

Sadly the new WPA2 security spec won't make your wireless LAN invulnerable

Written by Alan Stevens

Here's some good news - the Wi-Fi Protected Access 2 (WPA2) spec is finally with us, and the Wi-Fi Alliance has begun certifying compliant products. "Hurrah," I hear you shout, "finally we can have secure wireless networks."

Now the bad news; starting with the fact that WPA2 is not so much a standard as an interoperability stamp for wireless encryption and authentication technologies conforming to the IEEE's 802.11i spec.

This means we have one set of technologies with two names from two bodies. Moreover, WPA2 joins a confusing and growing list of similar measures, including the original WPA, with which WPA2 is supposed to be backwards compatible, and Wired Equivalent Privacy (WEP), with which it isn't.

Add to all that the fact that a lot of existing hardware won't support WPA2, and celebrations start to seem premature. Plus it's important to note that the technologies involved only address a subset of most people's wireless security worries.

Delve into recent history and the rationale becomes clearer, since the first stab at WPA was never meant to be a long-term solution. Rather it was introduced by the Wi-Fi Alliance to address perceived shortcomings of WEP, until 802.11i could be finalised. This would have been fine if it all hadn't taken so long, and if everyone had added WPA to their products. Unfortunately some vendors didn't bother, especially for older devices. On the plus side, where WPA support has been added, it's been relatively easy to install. In most cases a software download has been the only change required.

WPA2 isn't so straightforward, primarily because it tightens up security by using Advanced Encryption Standard (AES), and this algorithm needs to be implemented in hardware if performance is not to suffer. Some wireless chipsets have this capability built in, but many don't.

Finding out whether your hardware supports WPA2 may be hard. Of course you could always ask the vendor and certified products will be listed on the Wi-Fi Alliance web site. However, that list will take time to grow, since some vendors won't bother to get everything tested. To muddy the waters further there are two implementations of WPA2.

WPA2-Personal uses simple pre-shared keys to encrypt data and does not require users to be separately authenticated. WPA2-Enterprise is for larger firms and uses an 802.1x framework and Extensible Authentication Protocol (EAP) to identify users, typically via a Radius server.

Finally, don't assume that by implementing WPA2 you will have a wireless network as secure as your wired LAN. There are still plenty of other vulnerabilities to worry about, such as the possibility of "rogue" access points.

See what other readers are saying in our Letters blog and add your own comments instantly.

Tags:

reader comments

related articles

Improved wireless Lan performance

Chipsets boost Wi-Fi range by 50 per cent

Broadcom promises top-speed data rates at longer distances 22 Nov 2004

 

IEEE tunes into spectrum possibilities for wireless

Organisation seeks to establish standard for wireless regional area networks 14 Oct 2004

Your simple guide to wireless

Wireless technology is playing an important role in the increasingly mobile workforce. But the different technologies, acronyms and terms can be confusing 24 Sep 2004

Wireless LANs

Exploring wireless networking technology and its business applications 08 Aug 2003

related whitepapers

today's top stories

CIO priorities for the next six months: the Gartner view

Gartner research director Dave Aron outlines the three key priorities for IT leaders during the second half of 2009 13 Jul 2009

The wishful CIO – the further adventures of Bob

Like a phoenix, Bob has risen from the ashes of his once fast-tracked career . He is pursuing a green agenda as... 10 Jul 2009

Infallabile opposition to outsourcing

The Holy Father, Pope Benedict, has warned of the dangers of outsourcing. Yes, you’d better believe it. The Vatican is now stepping... 10 Jul 2009

Google Chrome OS - We didn't see that coming did we?

Reading through the various news and blog sites on the internet it seems the wheels of the rumour mill are turning apace... 10 Jul 2009

Strength through unity

The friction that has traditionally characterised relations between finance and IT has no place in today’s business landscape 08 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation