Berkeley CSUA MOTD:Entry 22013
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/07/08 [General] UID:1000 Activity:popular
7/8     

2001/8/6-7 [Computer/Networking] UID:22013 Activity:high
8/5     Any recommendations for wireless networking setup (card/AP)?
        Requirements: robust, work w/FreeBSD & Linux, work with Berkeley
        network, reasonably secure, reasonably cheap.  Performance
        is not a major concern (basically I got sick of wires in the
        apartment, and want to replace them with 802.11b).
        \_ be careful, it looks like the current encryption scheme (WEP?)
           sold in most wireless LAN products today isn't strong enough
           keep your data from curious neighbors. saw an article in sj
           mercury news about it yesterday.  something to do order of
           "anyone with a laptop and wireless pcmcia card can break into
           most wireless crypto methods in about an hour"..
           \_ so use ssh.  duh.  -tom
           \_ Its Wireless Equivalent Privacy. WEP is not an encryption
              scheme. Its purpose is to make it just as hard to tap a
              wireless link as it is to tap a cat5 or fiber link. Its
              not designed to make the link more secure than standard
              ethernet.
              Just using wires doesn't make it any more secure. Even
              on wired switched ethernet its possible to read cleartext
              passwords using snoop or a catos/ios packet capture prog.
              BTW, if its poorly shielded cat5k cable, you perform a
              wiretap without splicing cables.
              If you are worried about security, use strong encryption.
              \_ But you can physically secure the cat5 wires as well as the
                 switches and routers, specially on a home network. Also, since
                 the switched ethernet is becoming more common it should be
                 very hard to sniff anything if at all and to get to the
                 switch/routers you likely need access to the secured area
                 where they are located within most organization. With 802.11b
                 you can sit safe and cozey in your office and sniff as far as
                 the other guy's laptop across the hall.
                    \_ So you are using double sheilded zero leakage cat5k
                       cable in your home? Wow! Are you using serial console
                       only to your networking equipment with the physical
                       console on a lcd so the FEDs can't read your screen?
                       \_ The KEYBOARD. You forgot about the KEYBOARD cable.
                 \_ It is simple to sniff switched wired networks if you
                    can plug into them.  -tom
                 \_ I thought many of these boxes (in particular Apple Airport,
                    but probably others) offer access lists based on MAC
                    address... wouldn't that help with sniffing?
                    \_ No. MAC based authentication is required for joining
                       the network and using active attacks. The WEP "attacks"
                       are all passive.
                       BTW, for all you cordless phone users, did you know
                       that with a few hundred dollars worth of ham radio
                       equipment I could listen to all your calls?
                       \_ Yea, but I use CDMA cell phones.
                          \_ Good for you. I guess I can put my parabolic
                             mic away now.
                             \_ Are those round transparent things on the
                                sidelines during a NFL football game parabolic
                                mics?
                 \_ Good point!  I keep my home network secured by keeping all
                    of my routers inside locked Faraday cages and covering the
                    outside of my house with aluminum foil.
        \_ WEP fallibliity aside, I find the Linksys BEFW11S4 to be a pretty
        good box, does wireless, network switch, DSL/Cable connection, the
        whole deal, and fully configurable through web browser. I've used
                                   \_ Does this mean that if I have e.g. an
                                      ATT Cable modem, this will be enough
                                      hardware to allow multiple machines w/
                                      wireless ethernet cards to access the
                                      Internet?
                                      \_ Yes. You can even get them with 4
                                         port switches. DHCP is supported
                                         out of the box.
        several wireless products, and as an Access point the linksys is
        the best I've seen so far. The lucent/(now Agere) wireless cards
        are really nice too, and they have linux/BSD as well as windows
        drivers.  -ERic
           \_ I also have one of the linksys PCMCIA cards. Not as nice as
           the agere/lucent one, and no option for a range extender antenna,
           which is kinda annoying. And yeah, the linksys card sucks
           for reception.  I find it odd that most of the complaints on
           the amazon reviews of the ACCESS POINT were actually complaints
           about an entirely different product, the wireless cards. -ERic
        \_ Thanks for the info.  I am aware of the security issues with WEP,
           but imho having an internet-connected computer exposes you to
           a comparable (if not greater) risk.  I am interested in hands-on
           experience people have with different hardware.  Linksys box
           has mixed reviews on Amazon, and I've seen postings to lists
           about protocol conformance issues (might be fixed in recent
           releases.)  Has anyone tried SMC? NetGear?  Lucent is nice,
           but it's also more expensive.
           \_ I've tried the addtron AP.  Works fine without WEP, could
               not get its encryption to work with anything else.  The
               lucent AP is damn nice, but really pricey.  I wouldn't
               recommend it for home use, unless you have money to burn. -ERic
        \_ I have a SMC Barricade wireless access point with the extra 3
           ports.  The documentation that comes with the product is spotty,
           and I had to download new firmware as soon as I got the box.  But
           it's been fairly trouble-free otherwise.  DHCP, PPPoE supported
           in-box with (very) limited control over the DHCP.
           I have a Mac with an Airport card and a PC with a Lucent WaveLAN
           gold on the network.  Unfortunately, the Airport only
           supports 40-bit WEP, the WaveLAN only supports 64-bit or 128-bit,
           and I believe the SMC only supports 64-bit, so I don't run WEP
           but rather ssh for all my non-web browsing activity.
           \_ I wanted WEP just to keep the idiots from piggy backing on my
              net.  Running without WEP and trusting ssh to keep your data
              secure doesn't help against parasitic denial-of-service when
              someone hooks up their computer to do WAREZ through your wireless
              link.
2025/07/08 [General] UID:1000 Activity:popular
7/8     

You may also be interested in these entries...
2012/7/26-9/24 [Computer/Networking] UID:54445 Activity:nil
7/26    Why big mega cable companies rule:
        http://arstechnica.com/tech-policy/2012/07/how-big-cable-killed-the-open-set-top-box-and-what-to-do-about-it
	...
2012/3/29-6/4 [Computer/HW/Memory, Computer/HW/CPU, Computer/HW/Drives] UID:54351 Activity:nil
3/29    A friend wants a PC (no mac). She doesn't want Dell. Is there a
        good place that can custom build for you (SSD, large RAM, cheap video
        card--no game)?
        \_ As a side note: back in my Cal days more than two decades ago when
           having a 387SX made me the only person with floating-point hardware,
           most machines were custom built.
	...
2012/4/26-6/4 [Computer/Networking] UID:54371 Activity:nil
4/26    I see that soda has an ipv6 address but ipv6 traffic from this box
        doesn't actually work (ping6 <DEAD>ipv6.google.com<DEAD>, ping6 http://www.v6.facebook.com
        Is this expected to work?
        \_ Soda doesn't have a real IPv6 address.  The IPv6 addresses you see
           in ifconfig are just link-local addresses; any IPv6-capable machine
           will autogenerate these, whether or not it's connected to an IPv6
	...
2012/1/19-3/3 [Computer/Networking, Politics/Foreign/Europe, Computer/SW] UID:54294 Activity:nil
1/19    Transcript between the Italian cruise ship captain and the Port
        Authority
        http://www.csua.org/u/v9i (abcnews.go.com)
        This captain is amazing.
	...
2011/11/8-30 [Computer/SW/Security, Computer/SW/OS/Windows] UID:54218 Activity:nil
11/8    ObM$Sucks
        http://technet.microsoft.com/en-us/security/bulletin/ms11-083
        \_ How is this different from the hundreds of other M$ security
           vulnerabilities that people have been finding?
           \_ "The vulnerability could allow remote code execution if an
               attacker sends a continuous flow of specially crafted UDP
	...
2010/11/1-2011/1/13 [Computer/Networking] UID:54002 Activity:nil
11/1    I'm moving from a home in Fremont to another home within the same ZIP
        code in Fremont, and AT&T customer service says I cannot transfer my
        DSL service because DSL is not available at my new home.  Is that BS?
        Are they just trying to push me to subscribe to their more expensive
        U-verse service?  I'm not asking for any lightening-speed connection.
            \_ could be
	...
2010/3/3-30 [Computer/Networking] UID:53739 Activity:nil
3/3     If you read this
        http://www.net.berkeley.edu/dhcp/faq.shtml
        and find why it's funny, you're an old Soda geek.  -John
        \_ Nice. Any idea who might have written this? erikk, maybe? There
           are probably a lot of Sodans in IST. -not-that-old-Soda-geek
           \_ Jon?
	...