Securing wifi suggestions

Been doing some reading about wifi security and wanted to calibrate here with some knowledgeable users.  What are best practices for securing a home wifi network?
From what I have read, best practices:
*WPA2/personal with AES encryption.
*Use a strong (mixed alpha/num/sym) 63 character password. 
*Use a strong (mixed alpha/num/sym) 63 character SSID.  Why?  My understanding is that the SSID is used as a component to generate key hashes used for handshakes.  Therefore, using a common SSID could mean that there is a set of rainbow tables build off that specific SIDD.
False sense of securities include:
*MAC filtering.
*SSID hiding which is actually a security risk since every device connected to the network will basically scream out 'here I am... where is SSID xxx' when not connected.
*WEP-based encryption.
Last edited by graysky (2012-03-02 14:52:54)

cfr wrote:63 character random keys and ssids are all very well but I would find them excruciating, error prone and probably end up abandoning any sort of security.
Call me paranoid, but when I need to create a password for something valuable (like a router), I use a utility created many moons ago by a Gentoo developer:
http://swift.siphos.be/tools-hex2passwd.html
This allows me to only need to remember a super simple word/phrase, but create (and most importantly, recreate) a fairly strong password... while still causing someone on a semi-compromised system some difficulty to recreate even if they found the hex2passwd utility on the box.
I also added the following to my BASH profile:
export HISTCONTROL=ignoreboth
so that when I need to create/recreate a password using the utility, I simply add a space at the beginning of the command line so it won't end up in my BASH history.
It's not a perfect method... but what is?
OBTW: The hex2passwd utility is in the AUR.
tl;dr story...
I set up my neighbor's box so that he could log into my wireless router (he's unemployed) that uses one of these insanely long passwords. Sometime later he tells me a story about how he let a friend try to (manually) copy the password so that she could log her laptop into my router to surf the web during her visit.
While I was somewhat upset that he let her do that, he said he was sure that she never would be able to copy it correctly because it was so damn long and bizarre... and with a big grin, he said he was right.

Similar Messages

  • IPhone connects to secured WiFi network, but can't access Internet

    Problem: iPhone connects to my secured home WiFi network, shows WiFi strength bars at top of screen, displays checkmark, lock, power, and blue arrow on WiFi Networks screen; however, cannot access Internet, iTunes store, stocks, Weather or anything else.
    Tests I've run:
    1. iPhone itself:
    ---DCHP:
    IP Address = 192.168.2.102 (within range automatically allocated by LinkSys router--see below)
    Subnet Mask = 255.255.255.0 (as per LinkSys router)
    Router = 192.168.2.1 (as per LinkSys router)
    DNS = 192.168.2.1 (confirmed by Apple as a valid DNS address given the above information)
    Tests:
    *Forget Network and rejoin--Failed to connect to Internet
    *Forget Network, reboot iPhone, and rejoin--Failed to connect to Internet
    *Reset Netowrk Settings and rejoin--Failed to connect to Internet
    *Reset All Settings and rejoin--Failed to connect to Internet
    *Deleted DNS entry--Failed to connect to Internet
    *Connect to Apple Store unsecured network--Success
    *Complete reset of iPhone at Apple Store:
    **Brought home, made no calls, did not sync with iTunes, did not reenter any info deleted by complete reset, joined network--Failed to connect to Internet
    **Synced data previously saved to iTunes, rejoined network--Failed to connect to Internet
    2. LinkSys router WRT310N:
    Tests:
    *Updated Router firmware--iPhone failed to connect to Internet
    *Entered a Static IP address on both router and iPhone--iPhone failed to connect to Internet
    *Reserved an IP within range automatically allocated by LinkSys router--iPhone failed to connect to Internet
    *Reserved an IP outside range automatically allocated by LinkSys router--iPhone failed to connect to Internet
    *Forced MAC filtering to use iPhone WiFi Address--iPhone failed to connect to Internet
    *Disabled all MAC filtering--iPhone failed to connect to Internet
    *Changed security settings:
    **No Security--Success
    **WAP Personal (AES)--iPhone failed to connect to Internet
    **WAP Personal 2 (auto selection AES or TKIP)--iPhone failed to connect to Internet
    **WAP Personal 2 (forced AES)--iPhone failed to connect to Internet
    **WAP Personal 2 (forced TKIP)--iPhone failed to connect to Internet
    *Changed security WAP Password/Passphrase:
    **10 characters (alpha numeric)--iPhone failed to connect to Internet
    **12 characters (alpha numeric)--iPhone failed to connect to Internet
    **10 characters (alpha numeric/ Uppercase alpha)--iPhone failed to connect to Internet
    **10 characters (alpha numeric/ Lowercase alpha)--iPhone failed to connect to Internet
    **10 characters (all numeric)--iPhone failed to connect to Internet
    *Set router to Mixed Wireless N/G/B Network Mode--iPhone failed to connect to Internet
    *Changed network radio band from Auto to Wide to Standard--iPhone failed to connect to Internet each time
    *Set router to Wireless G Only Network Mode--iPhone failed to connect to Internet
    *Changed Router IP address from 198.168.2.1 to 198.168.1.1 (LinkSys default)--iPhone failed to connect to Internet
    3. Microsoft router MN-500:
    Tried this old router (the one I used before purchasing the LinkSys). It is an old (circa 2002) Wireless B base station with WEP Security. The iPhone was never able to connect to the Internet using various settings, many of which were duplicates of the LinkSys tests above.
    On both routers my wife's Dell laptop and my HP printer connect without incident, using the same network/security settings.
    I have always been able to connect to various unsecured WiFi networks; I have never been able to connect to a secure WiFi network (although the only one I've really tried has been my own).
    I am at a loss as to what to do next. Any suggestions?

    SUCCESS!!!!!
    I visited my brother-in-law yesterday and attempted to connect with his secure network. By sheer luck, he is using the exact same model LinkSys router. My iPhone connected first time--so the iPhone was eliminated as a source of the problem.
    I didn't do a lot of troubleshooting at his house, but I did notice that his network was set for both dynamic DHCP and dynamic DNS. I know that either or both of Windstream (my ISP) and my broadband modem requires a pair of static DNS addresses.
    Sure enough, delving real deep into Windstream's support site, I discovered a LinkSys router DNS help page, specifying how to set static DNS addresses in LinkSys routers. I then accessed my router, enterd the known static addresses, saved the router settings, then rebooted the iPhone and connected to the network.
    SUCCESS!!!
    Thanks to Jane, who suggested it was an ISP issue, Jason, and all at Apple support. dumonj, I'll email you directly. Try this suggestion and see if it helps.

  • Help in connecting new iphone4s to home secure wifi

    i have a new iphone4s and find i am unable to connect to secure wifi at home. any suggestions?

    See http://support.apple.com/kb/ts1398

  • IPhone Won't Connect to Secured Wifi

    I recently got a new iPhone 4 and I am unable to connect to my secured WiFi network with it. I can connect to it just fine with my laptop, old droid phone, iPod touch. I can also connect to it if I remove the security but not if the security is on. I've looked all over online, tried everything I've read, even took it into the Apple store where they completely reset the phone, all to no avail. I also brought the phone into a Verizon store, and they were able to connect to a secured wifi hotspot in the store, so I'm going to assume its a problem with my router.
    ISP: Comcast Perfromance Cable
    Modem: Comcast Motorola SB5120 Cable Modem
    Router: Belkin N600 D8 Wireless N+ Router (Model: F9K1102v1); firmware up to date as of today.
    I went to this website, plugged in all those settings and still nothing. I simply get "Unable to connect to <Network>". The one setting that I wasn't able to match to those had to do with DHCP. By going to my cable modem's config, I can tell that the DHCP client on it is turned on. The problem is, I cannot change the modem's settings readily through that page (192.168.100.1) and when I turn off the DHCP on my router my laptop has problems maintaining a connection.
    Here's some screenshots of the settings, perhaps you guys have better insight/advice/etc. I've been trying to use the 2.4ghz connection for the iPod, I don't use it for anything else so I couldn't care less what the settings are... I just want it to be secured. I use the 5.0ghz connection for my laptop and such.
    Here's the Channel and SSID settings... renamed the networks for the purpose of this.
    Security Settings
    WPS Settings (Honestly, no idea what this does).
    Lastly, LAN settings:
    If it's a problem with the phone itself, I still am with the 14 day return policy.

    I guess I'm stumped other than to say that it can definitely create problems if you are trying to run DHCP on your wireless router if it already enabled on your Comcast cable modem.  You only want one device managing DHCP on your network, normally the one that is the furthest "upstream"; in this case that would be your Comcast router.  I would try disabling DHCP on your router just as an experiment, then power-cycle your Comcast router, followed by your Belkin router, followed by your phone, then see if it connects successfully.  If it does, and when you restart your other devices they connect successfully, I would try to figure out how to solve the problem of the laptop not maintaining a connection.  Perhaps it needs an driver update?

  • Secured wifi problem

    Hi all,
    I have just purchased a playbook. I am having a problem with wifi. I am able to access my home wifi just fine. I can also access "open" wifi from the surrounding areas (eg colleges) with full signal. But I am not able to access my college's secured wifi. The school's IT team spent an hour with it, but could not get it to connecto to the school's connection. They tried adding my playbook's MAC address, manually connect etc... nothing works. The signal that my playbook picks up at the college is rather sporadic, too. Sometimes it's 0 bar, sometimes it's full bar, sometimes it's in between. All can happen in a few seconds while I'm standing at one spot. The playbook can't even pick up the signal when I'm standing under the wifi-hot spot router.
    Anyone knows what's going on? My playbook does have the latest version of the official OS. I would like to keep my playbook, but I will return it for a refund if this issue can't be resolved.
    Thank you very much for your help.

    First make sure you've downloaded the 6067 update, then if you turn on the wifi and have it scan for networks, you'll then select the secured network you want to connect to, then you'll have a choice of access, my network uses a password so I enter the password and that profile is saved, so everytime it finds that secured network it connects. You can also connect using the other choices. As for the signal, is there a way you can test the signal strength using another computer to determine if there's just  weak signal? You need signal to connect. One other thing, since you've been trying a bunch of differenct things I would hit the battery symbol, then click on restart and after the PB reboots start over.

  • Iphone connects to secured wifi network but cant surf the internet

    I am trying to connect to the wifi at the office, it's a 64 bit WEP secured network (I enter a 10 character hex key). The Iphone connects to the network and is assigned a valid IP address. But when I try www.google.com or 64.233.167.99 for example, it fails with 'Safari could not open the page because the server stopped responding'.
    It all works fine at home on my non secured wifi network.
    Please, can someone help? Thanks.

    Are you 100% sure the WiFi at your work has access to get out...and also, I assume they know you are getting on it. Not sure what type of office you are at (eg: large business with network support/admin or at a small office where you or somebody right there set it up).
    But if large office with network admin...could be they locked it down with MacAddresses as well.

  • After my mac is left standing over 20 to 30 minutes it drops my secured wifi and locks on to some neighbor's unsecured wifi

    after my mac is left standing over 20 to 30 minutes it drops my secured wifi and locks on to some neighbor's unsecured wifi 

    Go to system preferences, then network, select wifi tab on the right, click the lock icon on the bottom left and type an administrator's password, then click on advanced. When in the advanced menu, select the tab: WiFi. Locate your neighbor's wifi and select it, and press the minus button and click ok. This should stop your computer remebering your neighbor's wifi.

  • Keep losing my secure wifi with iPhone and ipad with newest iOS update.  PC still connected

    Keep losing my secure wifi on my ipad and iphone with newest iOS update. My PC is still connected to same secure wifi. Any ideas.

    Contact xFinity (Comcast) to turn off dynamic channel switching if on and have it set to a fixed channel.
    Usually WiFi routers will only change channels to the least busy when they are initially powered up.

  • Use smart card for 802.1x secured WiFi authentication

    Hi,
    is it possible to use a certificate stored on a USB Security Token for WiFi 802.1x authentication?
    I have setup a test environment with all required components (AD, Enterprise CA, NPS, WPA2-Enterprise capable WiFi Access Point, all required certificates, all Server 2012 R2 / Windows 8.1 Pro) and created a user certificate for WPA2-Enterprise secured
    WiFi access (802.1x). Everthing works fine as long as the user certificate is stored in the local certificate store of the user's client computer: The user can connect to the WiFi network and the NPS logs show that the user has been authenticated correctly
    and granted access.
    To test this scenario with a Smart Card (Safenet USB Token), I stored that same user certificate on the token (incl. private key). The Safenet software on the client computer automatically makes the certificate stored on the token available in the local
    certificate store as soon as the token has been plugged in (checked via MMC Certificates snap-in). But the certificate can't obviously be used for the desired WiFi authentication: If I try to connect the secured WiFi (the same as in scenario 1) the connection
    fails.
    As I'm using exactly the same certificate in both scenarios, I don't think there's anything wrong with the settings in the certificate, the NPS or any other infrastructure component. The reason for failure in scenario 2 must be lying somewhere in either
    the local client computer configuration or in the Safenet software on the client computer.
    I'm very familiar with all the PKI and authentication stuff, but I'm new to smart cards. Are there differences between different types of smart cards and for what purpose one can use them? (USB tokens, chip cards, virtual tokens, etc.?)
    Has anybody experience in creating a 802.1x secured WiFi access with smart card based user certificates who could advise?
    Thanks + Best Regards
    Matt

    Hi,
    I found some links form technet site which can be helpful in this case
    Network access authentication and certificates
    http://technet.microsoft.com/en-us/library/cc759575(v=ws.10).aspx
    Enable smart card or other certificate authentication
    http://technet.microsoft.com/en-us/library/cc737336(v=ws.10).aspx
    Quote:
    Client certificate requirements
    With EAP-TLS or PEAP-EAP-TLS, the server accepts the client authentication attempt when the certificate meets the following requirements:
    The client certificate is issued by an enterprise CA or mapped to a user or computer account in Active Directory.
    The user or computer certificate on the client chains to a trusted root CA, includes the Client Authentication purpose in EKU extensions (the object identifier for Client Authentication is 1.3.6.1.5.5.7.3.2), and fails neither the checks that are performed
    by CryptoAPI and specified in the remote access policy nor the Certificate object identifier checks that are specified in IAS remote access policy.
    The 802.1X client does not use registry-based certificates that are either smart card-logon or password-protected certificates.
    For user certificates, the Subject Alternative Name (SubjectAltName) extension in the certificate contains the user principal name (UPN).
    For computer certificates, the Subject Alternative Name (SubjectAltName) extension in the certificate must contain the client's fully qualified domain name (FQDN), which is also called the DNS name
    Yolanda Zhu
    TechNet Community Support

  • I see another unsecured wifi network on my list. As I have recently changed routers etc. I just want to make sure it's not attached to me. It has a different IP address than the secured wifi network I have now set up.

    I see another unsecured wifi network (D Link)  on my list. As I have recently replaced an old modem router (D link) with a new fancy one (wireless gateway), I am wondering if this is somehow still attached to my computer. The D link wifi unsecured network has a different IP address than my newly formed secure wifi network's IP address.
    Also - if I turn my wifi off (regardless of if I am on the dlink or my new secured wifi) I can still watch netflix etc. on my tv from living room which tells me the the wifi is still on. Why is this so?
    Does my Mac have two IP addresses or is that D link someone elses?
    THank you to anyone who can straighten me out on this as I am confused.

    Thanks Tony,
    Believe it or not, I had already done that - that is why I was confused as I kept seeing it in the wireless networks that I was seeing even though I had deleted it in my advanced Network of Systems Preferences. I thought if it were mine it would go away, but alas it didn't.  Anyway, all is well and I can now relax that everything is secure thanks all to you.
    Cheers

  • Issues connecting to secure wifi

    I haven't seen this specific problem mentioned. Here is my issue. I can no longer connect to secure wifi connections that request user name/passwords. For example, my husband and I have the same phone (Galaxy S4). Our gym is now offering free wifi but requires you to log in, when my husband connects his phone to the wifi it redirects him to an internet browser to log in; mine does not. My phone just scans for the wifi, says that it is "saved" but will never connect. I had the exact issue at a hotel over the weekend that required a password. This problem seemed to have started a few months ago. I can access open wifi and password accounts that I had set up previous to this problem starting. Any thoughts?

    I haven't been able to enter the information in the first place. It scans, finds the wifi and then marks it as "saved". I never get a browser window to enter user/password. I tried manually going to a browser but that doesn't work either.

  • I want to enter the password for a secure WIFI network on several iphones.  If I do this, can the end users somehow extract the ip address and password for the wifi network from the iphone and use it from a pc (at home, for example)?

    I want to enter the password for a secured wifi network on several iphones.  If I do this, is it possible for the end users to somehow extract the ip address and password information and use it from a pc/laptop/other mobile device.  For security reasons, I don't want them to be able to to this.
    Please advise,
    Thanks.

    If you look at the top left of your screen you will either see a 3G (or 4G if you have AT&T) or you will see the wi-fi symbol.  If you don't see the wi-fi symbol you are connecting to Gmail through your cellular data plan, not via wi-fi.
    To answer your question, it doesn't happen often but when it does the steps I mentioned above will normally resolve it.  Hopefully you won't have any further problem with this.

  • TS1398 In "Set Up" I try to select our secured WIFi router from the list of available networks.  However, it will not allow me to select it. This then prevents me from going to the next step. What do I do?

    In "Set Up" I have tried to select our secured WiFi router from the available list shown.  It is listed.  However, when I try to select it, it will not check off or remain blue when I lift my touch.  This then will not allow me to go on to the next step.  What do I do to connect to a secure WiFi router? I do know the WEP Key number but there is no place to type then in.
    Alice from Hart

    The trial can only be loaded 1 time as far as I know. You could try http://labs.adobe.com/downloads/acrobatcleaner.html, remove any left over parts of the Acrobat folder, and reboot. Then try an install again, but my guess is you will have to purchase Acrobat at this point.

  • My Ipad connects with my hotel wifi, but does not indicate that it is a secure wifi, even though it requires a password to access - no lock symbol, hence no password request, hence no internet access - help.

    My IPad connects with my hotel wifi, but does not indicate that it is a secure wifi, even though it requires a password to access - no lock symbol appears against the wifi network, hence no password request, hence no internet access - help. My collegue who also has an Ipad can access the same wifi with ease, so it must be something to do with the settings on my machine, although checking the two machines, there appears to be no difference in the settings.

    My experience with hotel wifi is that it's an open, and unsecured, connection, but unless you agree to their terms on a launch page, you can't go any further or connect. Sometimes I need to force safari to come up and even make it go to a page, to trigger the auto load of the 'agree to our terms' page.
    Unless your machine is work provided so maybe could be blocked from unsecured net access?

  • Unable to connect to secure Wifi, password input was correct

    I was unable to connect to secure Wifi, i ensured that i entered the correct password, i tried to reset my network setting and reconnect to secure Wifi but still unable to connect. However i can successfully connect to public wifi.

    Hi Charlesjoseph - I struggled for days and tried all the solutions mentioned in various forums before I realised that the password (the WEP key number) is case sensitive. Once I tried it all in capitals it connected no problem. Doh!!

Maybe you are looking for

  • Itunes has stopped working APPCRASH

    hello guys !!A few days ago When I click on iTunes on my laptop(HP Pavilion dv6625us Entertainment Notebook PC) Appears a window saying itunes has stopped working APPCRASH . I uninistall y install iTunes again the last version and do not solve the pr

  • Problem in displaying Eastern asain language characters in GUI components.

    hi all, i m getting probelm in displaying chinies & japanies charatcter on GUI, i have my strings in xml file UTF-16 and UTF-8 formates. problem is that i can display the character on JFrame Title, tabbedPane Titles and in Text Area too, but i can't

  • Why can't I download podcasts into my iTunes on my phone?

    The Podcasts app is not installed on "iPhone", so you will not be able to play podcasts on your iPhone. The app only works with celluar data, which I pay for, and i need a connection so I can't listen to them on a plane. BS.

  • Internal table update

    Hi, I am created a structure in se11 and using that structure i have created one table type variable. This table type variable,i am using in my function module as export parameter .In my import parameter i am taken one a field type of my structure .

  • How to handle idoc status record.

    Hi expert, We have configure custom idoc, the status of inbound custom idoc when posting by process code is 64 (Ready to posting), How we can post with status 54, have any idea ? When I am using report RBDAPP01, it is in status 51 (Error), How I can