* Addressing the Wi-Fi security angle in the small and home business markets
A few months ago we wrote a column about the software launched by Pure Networks – their home network management software really impressed as the kind of thing that could help both end users and broadband providers. The idea struck a chord with many readers too; we got feedback from a number of you and also heard from a number of other vendors with products in a similar space.
Since we wrote that column, we’ve seen a lot of solutions for the home and small business markets which provide either the customer, the carrier or both some greatly enhanced degree of control, management and monitoring of the endpoints within their networks. One area within those networks that hasn’t really been addressed completely, in our opinions, is the Wi-Fi security angle.
Now it’s not news that Wi-Fi security is a big deal for everyone (or at least it should be). We did some research with enterprises several years ago that came up with that answer, and every bit of research we’ve seen since says concurs. The folks at the Wi-Fi alliance themselves recently concluded the same thing, finding that security (along with standards compliance) is one of the top two Wi-Fi concerns of enterprise IT managers.
At the same time, the news continues to be full of stories about enterprises both large and small that are NOT taking the proper precautions and fully locking down their wireless networks. And don’t even get us started when it comes to consumer networks. All we need to do is look at the “available network” lists on our screens at home to see how many of our neighbors haven’t enabled a bit of network security.
And you know what? We can’t blame them – it’s still often too difficult to create a secure Wi-Fi network, especially for consumers and small businesses without an IT staff to force the issue. It gets even harder if a business (or a telecommuter) wants to really lock down their network by moving from WPA-Personal to a fully authenticated 802.1X-enabled WPA-Enterprise solution. How many non-technical SMBs or SOHO customers even know what a RADIUS server is for, much less how to set their own up?
We’ve seen a few new services recently that make us think help is at hand, however. An example is the hosted WPA/802.1X security and authentication services offered by Wireless Security Corp (WSC). Called WSC Guard, the service (about $4 or $5 a month per station) provides a software client, Web site administration, hosted RADIUS services, and the support that wraps the whole thing together in a user-friendly package.
802.1X authentication gives the customer real control over who gets onto the network, and who doesn’t. The benefits of this are obvious on the client side, but the two way authentication included (client and AP both) can provide security benefits on the AP side as well. Specifically, this two way authentication can significantly reduce the risk of “evil twin” rogue APs that have been in the news so much lately. It’s a definite good thing to have your customers be sure they are connecting to their own AP and not some bad guy’s.
The service has a simple Active X client for guest access (guests can also use the free client software), so partners, clients and customers can get on the Wi-Fi network without jeopardizing overall network security. In fact, this is one big advantage of WPA-Enterprise over WPA-Personal: there’s no single, universal pre-shared key (or passphrase) that every user must have to get online. Every user gets their own individual key when authenticating with RADIUS. Which means that when there’s a move, add or change, the administrator (who could be the business owner or another non-IT person) won’t have to change the password for everybody just to maintain security.
So what’s the angle for a service provider? Well at a bare minimum, this seems like the kind of service that would be a breeze to resell to security conscious customers. Broadband providers are handing out APs like candy to their customers, but few have gotten very deep into the process of securing those customer’s networks.
There are also cost issue to keep in mind. Unsecured Wi-Fi on every SMB or residential customer’s broadband connection is a potential nightmare from a “someone sneaking on the network and BitTorrenting every episode of the Sopranos” perspective. Or from the perspective of any of a1000 Wi-Fi nightmares that local news anchors breathlessly report on.
Service providers who do try to push Wi-Fi security, however, face a challenge. The folks at WSC told us about a carrier they’re working with who had installation techs “turn on” WEP or WPA for all new customers. Great news, but a few months down the line, as customers started requiring configuration changes, the support calls starting piling up. And we all know how support calls can change the business case on a low-priced value-add like Wi-Fi on top of broadband.
So it seems to us that the folks at WSC are on to something. From the vendor side, there’s definitely traction, as Linksys is bundling the service with their most popular SMB 802.11g access point, and has even gone so far as to integrate the configuration into the access point’s Setup Wizard on the CD. Service provider partners like iPass are using the service too, mainly for roaming telecommuters. We expect to see more service providers exploring services like WSC Guard – it just makes good sense to bring this kind of enterprise-level security down to their smaller customers.




