Vulnerability Development mailing list archives

RE: Wireless Lans give EVERYONE ACCESS


From: "Jon Erickson CCG" <Jon.Erickson () caspiangroup com>
Date: Fri, 10 Aug 2001 10:20:50 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

-----Original Message-----
From: Jonas Thambert [mailto:JonasT () guld spray se]
Sent: Thursday, August 09, 2001 1:14 AM
To: 'Conal Darcy'; Russell Handorf
Cc: VULN-DEV () securityfocus com; bugtraq () securityfocus com
Subject: RE: Wireless Lans give EVERYONE ACCESS


WLAN is best used on a separate VLAN/NIC of the firewall in 
combination 
with VPN into the rest of the internal networks.

The VPN authentication is best handled my RSA, safeword or biometric
systems.

Even then its not safe since it only takes 15 min to decrypt the
40-bits key. Maybe WEP2 128-bits key will solve that :-)

40-bit WEP, 128-bit WEP.. it really doesn't matter that much, since they
both still only use 24-bit IVs to set up the RC4..  =(

It's really just the illusion of greater cryptographic security with
128-bit WEP...

- --
Jon Erickson         Cryptologist and Security Designer          Caspian
415.974.7081  D49B 4561 1078 0A72 DDF3 7250 8EF4 4681 587E 41DD  1728748

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.4

iQA/AwUBO3QX7I70RoFYfkHdEQJlwgCfYW92iJvPULTyB+y9PpFtK8dhdssAoPvT
c1SBasuL4kn42S7hLp3bp1S/
=WxQy
-----END PGP SIGNATURE-----

<<winmail.dat>>


Current thread: