Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Security /

Adventures in Network Security /

Wireless Protocol Adventures

Related linksToday's breaking news
Send to a friendFeedback


Network World Fusion, 02/25/04

The RSA Conference provides wireless access to full conference attendees. Someone (no doubt either a brave soul or someone with a fine whiskey collection) decided they should use 802.1x authentication on this network. So, I tried to use it. This describes my adventure so far.

Short answer: it doesn't work.

I've got an IBM Thinkpad, with a Cisco/Linksys wireless card, with Windows XP Pro, Service Pack 1, rollups and patches all applied. It doesn't work. I get about 5 seconds of connectivity and then it dies.

Now rather than drag you all through the sordid details of my unpleasant experience, let me tell you what I see as the issues here, because that's relevant to all of us.

* - It's not supported.

You have to update your O/S, your drivers, your authentication mechanism, your certificate set, and it only works on a few operating systems, if it works at all. This is not what I would describe as a "supported feature". This is a new technology that is experimental, on a good day.

*- It has security implications

It uses certificates, which is fine. I know how to do certs, having been in that space for a while. Having my device driver proudly ask me to pick a random root from the 200 or more roots loaded into my PC by the browser vendor isn't the way to deploy a hierarchy, in my opinon. So we are back to certificate/PKI headaches. Why on earth would I ever want to have the ABA (who deploys a root via Internet Explorer) to certify a wireless access point?

*- It's got performance issues

During the 15 second intervals when I did see connectivity, my T23 (that's a gigahertz Pentium) slowed to a crawl. It's very impressive to see the mouse pointer respond sluggishy, but it's not user friendly. I suppose this could be crypto issues, but no other crypto software has such issues in this class of machine, so I'm not sure what they're doing under the rug.

*- It's got network management issues

There's no logging, dialog boxes, magic secret text message files, or any other trail left by a failure. Because I'm not shy and because I finally started explaining I was going to blog this, I was able to artifically raise the visibilty of my problem and prevail upon the kindness of the show staff and one or two personal firewall vendors at the show, in order to get someone to help me troubleshoot this. When you can make the network elf start muttering in Old High Latin whilst typing arcane diagonstic commands into the serial port on their high-end Enterprise-class Wireless AP, only to see the same silly link failures, it's pretty bad. This is not a deployed technolgy - it's a science fair project.

So what did I do? I cheated. I used the Ethernet drops in the press room, or, I walked across the street (in the rain) to the coffee shop, where the wireless works fine.

Back to Adventures in Network Security

Comments

this was the most disappointing feature of the RSA conference, and NOT a selling point for wifi or wifi security.

The two galling issues:

- having to do it THEIR way with all the upgrades and config requirements. Last I checked, it's still my data, my computer, my responsibility.

- the inability with 10,000 security experts around to actually have a system that works

Posted by: Chris on February 28, 2004 09:26 AM

Simple solution: provide access to the APs but only allow encrypted protocols (SSH, SSL, IPsec, PPTP etc.) and block all others.

Posted by: Jay on March 1, 2004 06:23 AM

Post a comment

Name:


E-mail address:


URL:


Comments:


Remember info?




NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.