Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Mobile

    Wi-Fi Alliance to Promote WLAN Security

    Written by

    Carmen Nobel
    Published January 31, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The Wi-Fi Alliance will use its pull in the industry to improve security measures in wireless LAN hardware over the next year.

      The Austin, Texas, trade organization, which confers the right to use the Wi-Fi label on hardware, plans to increase encryption requirements for certification. But members of the security task groups within the alliance stress that the onus of WLAN security still lies with the customer.

      Last fall, the group quietly made support for 64-character passwords a requirement for access points to be certified for WPA2—the next version of the Wi-Fi Protected Access protocol, which incorporates AES (Advanced Encryption Standard). The move came in reaction to a report last summer detailing potential attacks using rogue access points and a RADIUS servers shared secret. Adding characters to the shared secret makes the hack more difficult and less likely to succeed, experts said.

      /zimages/6/28571.gifRatification of 802.11i strengthens Wi-Fi security. Click here to read more.

      By spring of next year, the alliance will require that all access points be WPA2-certified to get the Wi-Fi label, said Frank Hanzlik, managing director of the group. WPA2 is based on the IEEEs 802.11i standard. The first version of WPA is already required for certification.

      Some analysts say WPA2 is too stringent a requirement.

      “I dont think its a good idea to require WPA2,” said Craig Mathias, an analyst at Farpoint Group, in Ashland, Mass. “I dont think everyone will need AES. I also think higher-level security of the 802.1x or VPN variety can effectively substitute for AES in many cases.”

      Alliance officials disagree. “It is really nonsense in claiming VPNs are an economic alternative to WPA2,” said Eugene Chang, vice president of strategic development at Funk Software Inc., in Cambridge, Mass., and an active member of the Wi-Fi Alliance security working group.

      “WPA2 is free, secure encryption at wire speed. VPN devices are extremely expensive. Even low-cost 1M-bps VPN servers are more expensive than an access point,” said Chang. “The strongest reason to use IPSec [IP Security] over WLAN is an application that requires use of FIPS [Federal Information Processing Standard] 140-2-certified encryption, [because] FIPS 140-2-certified 802.11i products are not available yet.”

      Meanwhile, throughout this year, the alliance will be adding various strains of EAP (Extensible Authentication Protocol) to its testing bed, Hanzlik said.

      Alliance officials said the responsibility for a secure WLAN still lies with the administrator, noting that there are plenty of users who dont take advantage of security protocols. For example, the aforementioned RADIUS hack assumed a weak shared secret on the users part. Requiring a vendor to support a 64-character shared secret does not preclude a user from choosing an eight-character one.

      “It is important that we always keep sight of the difference between the capabilities of the equipment and the practice of the users,” Chang said. “We should not be blurring the distinction between equipment flaws [and] the difficulties of user education.”

      While the Wi-Fi Alliance is not a government standards body, WLAN administrators and analysts say the group has cachet and that the Wi-Fi sticker matters.

      “I look at the Wi-Fi sticker to make sure the devices are capable of WPA either with preshared keys or server-based,” said John Greiner, chief technology officer at Legal Services for New York City. “Basically, it helps me screen out certain products more quickly.”

      Wi-Fi Security Initiatives

      2003

      WPA testing incorporated into the certification process

      2004

      Tests for WPA2 require that WPA2- certified products support a 64-character shared secret

      2005

      Tests for various iterations of EAP developed

      2006

      WPA2 support required for Wi-Fi certification

      /zimages/6/28571.gifCheck out eWEEK.coms for the latest news, reviews and analysis on mobile and wireless computing.

      Carmen Nobel
      Carmen Nobel

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×