Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Mobile/Wireless Computing
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Hospitals back off Cisco LEAP security for WLANs

IT managers are opting for stronger, multilayered defenses

October 17, 2003 12:00 PM ET

Computerworld - For some health care IT managers, Cisco Systems Inc.'s wireless LAN authentication protocol's vulnerability to attacks aimed at discovering passwords is reinforcing the importance of developing multilayered approaches to securing their networks.
Several users this week said they have already adopted or plan to install a mix of WLAN authentication and encryption protocols to ensure that their companies comply with the data privacy requirements of the federal Health Insurance Portability and Accountability Act.
Chris Lenaghen, a network engineer at St. Alphonsus Regional Medical Center in Boise, Idaho, said he views Cisco's Lightweight Extensible Authentication Protocol (LEAP) as "a temporary solution" until the hospital can install an updated version of Novell Inc.'s Extend Director software.
The Novell software supports the Lightweight Directory Access Protocol (LDAP), which Lenaghen said should make it harder for malicious hackers to run so-called dictionary attacks against the hospital's WLAN. St. Alphonsus will speed up its move from LEAP to LDAP because of the Cisco technology's vulnerability, Lenaghen said.
Cisco disclosed in early August that LEAP could be compromised by dictionary attacks. At a conference earlier this month, Joshua Wright, a systems engineer at Johnson & Wales University in Providence, R.I., demonstrated such an attack using a tool he developed (see story). In an interview this week, Wright said he plans to make the attack tool publicly available in February (see story).
Gene Gretzer, a senior analyst and project leader for access technologies at St. Luke's Episcopal Health System in Houston, said the health care provider uses LEAP to help secure 100 wireless access-point devices made by Cisco. But St. Luke's also controls WLAN access through a database of Media Access Control (MAC) addresses and use of the Advanced Encryption Standard.
Miami Children's Hospital in Coral Gables, Fla., has taken a layered approach to WLAN security as well, said Alex Naveira, its chief information security officer. In addition to LEAP, the hospital is using MAC address authentication and 128-bit Secure Sockets Layer encryption.
Ron Seide, product line manager at Cisco's wireless business unit, agreed that many organizations need stronger authentication capabilities than LEAP provides.
He said Cisco recommends that such users install the Protected Extensible Authentication Protocol (PEAP), which relies on digital certificates to control network access. PEAP was co-developed by Cisco, Microsoft Corp. and RSA Security Inc.



Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

iPhone for the Enterprise
One of the biggest concerns of using the iPhone for the enterprise is the security and manageability issues. Read this white paper to...  

5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....

Yankee Group Mobile WAN Optimization Report
Mobile work continues to evolve. Learn how to keep up with the demands of your organization's mobile workforce....  

Managing Laptops Outside the Office
(Source: Absolute Software) In this webinar, learn how you can reduce costs by tracking mobile computers no matter where they are located. Featuring...

Mobile Device Management for Dummies
Did you know that up to 70% of enterprise data exists in various frontline settings, from laptops to handheld devices, to store and...  

What Are 'Free' Remote Support Tools Really Costing You?
(Source: LogMeIn) In this webinar from LogMeIn, discover how "next generation" remote support tools are optimized to provide advanced capabilities like scripting, system...

Ponemon Study: The Business Risk of Lost Laptops
Employees can access and store enormous amounts of confidential data on your organization's laptops, leaving your company vulnerable to substantial business risk when...  

IT Strategies for Remotely Supporting a Distributed Workforce
(Source: Citrix Online) Today's workforce is a distributed one - workers across industries are telecommuting, working out of satellite offices and connecting into...

Airport Insecurity: The Case of Lost Laptops
(Source: Dell) Business travelers lose more than 12,000 laptops each week in U.S. airports, yet most admit they don't take steps to protect...  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...