joanie_wexler
Writer

Acceptable use policies needed for soft APs

Opinion
Feb 23, 20102 mins

* New class of unauthorized AP emerges in operating systems, handsets

Balancing usability with security is only getting trickier with so much functionality now quietly embedded directly into operating systems and handsets to satiate consumers’ mobile computing appetites. Because of these features, a user might easily — and unwittingly — become a portal into the corporate network.

The mobile phone evolution

For example, the last newsletter described a virtual Wi-Fi adapter function in Windows 7 that allows users’ laptops to operate simultaneously in both Wi-Fi client and AP modes. The function has strong appeal to users wanting to share MP3s, photos, games and such among their laptops. A similar capability exists in Apple’s Mac OS and is going to be embedded in handsets via Wi-Fi chipsets built by companies such as Atheros and Marvell.

Lisa Pfifer, president of Core Competence, sees these proprietary solutions as precursors to Wi-Fi Direct, a recently published spec from the Wi-Fi Alliance to create a faster, farther-reaching personal area network (PAN) than Bluetooth.

The good news from a security perspective with Wi-Fi Direct, Pfifer says, is that “WPA2-PSK [Pre-Shared Key] is part of the package. But the bad news is that these direct connections make it easy for users to bypass whatever security policies are enforced by enterprise controllers and APs.”

The Alliance’s Wi-Fi Direct test and certification program won’t be launched until mid-year, so it’s not clear yet which bits of the spec will be mandatory in certified products, she says. The Alliance has said publicly that the spec was designed to be “enterprise-friendly and incorporates some important management features.”

But Pfifer wonders whether entry-level consumer products “will really offer those enterprise-class knobs. If they don’t, then businesses will have to find another way to spot and stop unauthorized Wi-Fi Direct soft APs. Either way, businesses definitely need to start thinking about acceptable use policies for [Wi-Fi Direct] before this brand new class of rogue AP starts popping up everywhere.”

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author