Re: securing OpenBSD wireless network

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: David Newman
Date: Monday, November 19, 2007 - 4:08 pm

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/19/07 2:36 PM, Tonnerre LOMBARD wrote:

Before either of those processes begin, I can associate like crazy to
your access point. That would ensure you never get Internet access, even
without my flinging a single IP packet at you.

I have a test tool that can associate 500 times to the same AP,
appearing as 500 unique clients. In my experience, most APs crash and
burn a long time before then -- and that's before seeing any IP traffic.

Even if your AP is robust enough to handle a huge number of client
associations, the chatty nature of the 802.11 protocol ensures the
medium will be so full of management frames that you won't be able to
send an IP packet. (I like to think of 802.11 as a technology that
combines the worst aspects of Ethernet and token ring...)

If you come in without IPsec, i.e. you cannot establish the IKE

Does not cause *you* problems != no leakage at L2


Well, for starters every 802.11 AP broadcasts its availability 10 times
a second. And since 802.11 is a shared-access medium, you'll also see
the first packet of every client's 802.1X auth exchange, as well as
SSIDs of all available stations.


Probably true for your setup, definitely less true in other (and
arguably most other large-scale) setups.

Most APs consist of a dinky little CPU and a very little bit of memory,
both easily swamped by doing too much work *just at layer 2.*

Further, they have to contend for spectrum with other 802.11 stations,
microwave ovens, Bluetooth devices, cordless phones, ham radios (that's
for the far more popular 2.4-GHz spectrum used by 802.11b/g/n. The
5.8-GHz spectrum used by 802.11a/n is much better, though still hardly
pristine).

Anything you can do to keep your AP's RF section free and clear will
result in a better WLAN experience, where "better" means both "faster"
and "more secure."

dn
iD8DBQFHQhdsyPxGVjntI4IRAiehAJ48mn685Gk0VaQ/ui50Zg07LvpKTQCgsQaW
iEhNeWGoplX7tIAAMCYKKgc=
=/Guk
-----END PGP SIGNATURE-----
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
securing OpenBSD wireless network, Juan Miscaro, (Fri Nov 16, 12:39 pm)
Re: securing OpenBSD wireless network, David Higgs, (Fri Nov 16, 5:35 pm)
Re: securing OpenBSD wireless network, Lars Hansson, (Sun Nov 18, 7:19 pm)
Re: securing OpenBSD wireless network, Clint Pachl, (Sun Nov 18, 10:51 pm)
Re: securing OpenBSD wireless network, Tor Houghton, (Mon Nov 19, 4:18 am)
Re: securing OpenBSD wireless network, Lars Hansson, (Mon Nov 19, 5:40 am)
Re: securing OpenBSD wireless network, David Newman, (Mon Nov 19, 8:59 am)
Re: securing OpenBSD wireless network, Tonnerre LOMBARD, (Mon Nov 19, 9:16 am)
Re: securing OpenBSD wireless network, Marc Balmer, (Mon Nov 19, 10:32 am)
Re: securing OpenBSD wireless network, Tor Houghton, (Mon Nov 19, 2:23 pm)
Re: securing OpenBSD wireless network , Marco S Hyman, (Mon Nov 19, 2:44 pm)
Re: securing OpenBSD wireless network, Peter N. M. Hansteen, (Mon Nov 19, 2:57 pm)
Re: securing OpenBSD wireless network, David Newman, (Mon Nov 19, 3:20 pm)
Re: securing OpenBSD wireless network, Tonnerre LOMBARD, (Mon Nov 19, 3:36 pm)
Re: securing OpenBSD wireless network, David Newman, (Mon Nov 19, 4:08 pm)
Re: securing OpenBSD wireless network, Jairo Souto, (Thu Nov 22, 1:56 pm)