Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Wireless security: The case for VPNs

April 2, 2003 12:00 PM ET

Computerworld - If you talk with any one of the growing multitudes of people using Wi-Fi technology today, you'd think you were listening to an infomercial. The response and adoption has been that good. The technology is being liberally embraced everywhere, from the traditional enterprise to universities, airports and malls. Despite the positive response, the Achilles' heel of the technology, either real or imagined, has always been the notion of security.
Historically, Wi-Fi technologies have been driven by the IEEE 802.11 working groups, which have undertaken much of the heavy lifting involved in making interoperable wireless local-area networking possible. Despite their remarkable achievements in this space, one of the trade-offs, from a technology standpoint, has been security.
As such, the initial solution was a rather meek approach called 40-bit WEP, or Wired Equivalent Privacy. WEP, the security mechanism initially built into all standard 802.11 products, encrypts data on the wireless network but is flawed because it reuses the same encryption key, which could allow a hacker to figure out that key from a small amount of traffic. This is causing security-conscious network managers to sprout premature gray hairs. Wi-Fi access to the LAN puts critical information out in the open and has the potential to provide further LAN exposure to unauthorized parties. Because of this and all that has gone on domestically and geopolitically over the past couple of years, there has been reluctance by some enterprises and government agencies to adopt the technology.
To allay many of these fears and to encourage adoption, the IEEE has been working on a task team for a security standard to be called 802.11i. However, a ratified standard is still some time away. The Wi-Fi Alliance (WFA) provided a sneak peek of 802.11i in an approach called Wi-Fi Protected Access (WPA), which has been a good start. Interoperability testing is under way, and WFA- and WPA-certified products are expected to hit the market in the next several months.
Despite the progress, this approach still isn't exactly what enterprises, government agencies and service providers need. Specifically, there are concerns over support for operating systems (other than Windows XP), and there are also concerns over installation and integration with other enterprise technologies such as Remote Authentication Dial-In User Service servers. The WPA standard is also under investigation by a number of security experts who have found some possible problems, such as "man in the middle" attacks, whereby a hacker can pose as a rogue access point and hijack a user session.
How VPNs fit
The approach to



Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...