To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here
Search
Search internet.com
News Reviews Insights Tutorials WiMax VoIP HotSpots Forums Events Products Glossary About


Go Back   Wi-Fi Planet Forums > Wi-Fi Planet Forums > Security

Security Here's where to discuss security issues, as they pertain to 802.11 wireless networks.

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
  #1  
Old 08-29-2003, 10:49 AM
Wildcats Wildcats is offline
Registered User
 
Join Date: Jun 2003
Posts: 55
Question Open vs Shared-Key Authentication - Which is best?

I need to chose to implement either Open or Shared-Key authentication our our access points. Granted, I should use something else (EAP?), but I have no choice in this case.

Open auth is subject to DoS attacks, since the AP could be overloaded with "associations".

Shared-key auth suffers from sending both plain-text AND cipher text during the authetication process. Someone with enough time and CPU power could use these two pieces of info to obtain the WEP key. We may be talking NSA's capabilities in this case, not simply a person using WEPCrack! WEPCrack exploits a different weakness.......

I like the idea of shared-key auth, since it will allow me to see authentication failures in my logs (from people that have no WEP key or the incorrect WEP key). I can then track them down (?). However, there is an outside chance that the WEP key(s) could be compromised, as it appears that no encrpytion algorithm is perfect.

Your thoughts?
__________________
Get out and VOTE! If you don't vote......Don't complain! You CAN make a difference. Your vote DOES count.

This message is protected by the DMCA. Isn't everything?

http://www.isc2.org
Reply With Quote
  #2  
Old 08-29-2003, 11:18 AM
dot11guru dot11guru is offline
Registered User
 
Join Date: Aug 2003
Posts: 12
Every WLAN is open to Denial of Service (DoS) attacks. There's not much of anything you can do to prevent that except eliminate the source of the attack.

Given that, Shared Key Authentication is not a good idea IMO because of the clear text.
Reply With Quote
  #3  
Old 08-30-2003, 01:32 PM
Aiakos Aiakos is offline
Registered User
 
Join Date: May 2003
Posts: 143
dot11guru is right ANY wlan can be DoSed, just get a 2.4 GHz cordless phone hand set and hide it in a desk.

Shared Key is vulnerable because the AP sends out a challenge in plain text, then the client replies with an encrypted version. If someone were able to intercept these they could compare them and deduce the key.

I have not done any research into this but I do not know of any tools that perform this comparision. For this reason I would say Shared Key has some merrits in a home network.
Reply With Quote
  #4  
Old 08-30-2003, 03:30 PM
mvario mvario is offline
Registered User
 
Join Date: May 2003
Location: New York, NY
Posts: 34
as long as you are using mandatory WEP for encryption you don't really gain any security by using shared key authentication, since packets won't be passed if the client doesn't have the WEP key. And as others have said, with shared key, during the authentication process, the some data is excahnged in both encrypted and plaintext form making it easier to crack. "Best practices" is to use open authentication.
Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 08:12 PM.



>> Wi-Fi Planet Marketplace



Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.