Welcome, Guest. Please login or register.

Author Topic: Wifi on A1200  (Read 8595 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline kolla

Re: Wifi on A1200
« on: July 29, 2011, 10:04:52 AM »
Quote from: Gilthanaz;652081
Actually a WiFi should be firewalled anyway.


Using what - aluminum foil?
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS
 

Offline kolla

Re: Wifi on A1200
« Reply #1 on: July 30, 2011, 02:09:21 PM »
Quote from: Gilthanaz;652093
Mmmmkaaaay... no.
             

            .............Intarweb
..................|
LAN <=|> Firewall <|=> WLAN Router <=> WLAN Clients

OK, we have totally different ideas about what security is, you just want to protect your LAN stuff, I also want to protect my wireless equipment.

Quote
* by MAC
MAC addresses are quite visible once WEP is cracked
Quote
* by fixed IP per MAC
IP addresses are equally visible
Quote
* Match chain => MAC ! fixed IP per Hostname => REJECT
Just hoping the intruder won't figure that out?
Quote
* If you're hardcore you can also make a finger match for the OS that HAS to run on that machine with that IP and exactly that MAC, or even funnier:
* Have a random high port open on your machines where you have a rsync daemon drop a keyfile every hour that has to be synchronized on the firewall (using rsync with private keys for each machine), and have a match condition on the exact file bytes
* I guess I could come up with about 200 more creative solutions how to fortify a network so literally no one without physical access can fsck with it, not even if they break the WAP/WEP/WPA/[...] encryption.

Really? With broken WEP, I can steal both your mac address and IP address and start hijacking your TCP sessions. And your machine will be doing all the creative stuff to make sure both of us are online.
B5D6A1D019D5D45BCC56F4782AC220D8B3E2A6CC
---
A3000/060CSPPC+CVPPC/128MB + 256MB BigRAM/Deneb USB
A4000/CS060/Mediator4000Di/Voodoo5/128MB
A1200/Blz1260/IndyAGA/192MB
A1200/Blz1260/64MB
A1200/Blz1230III/32MB
A1200/ACA1221
A600/V600v2/Subway USB
A600/Apollo630/32MB
A600/A6095
CD32/SX32/32MB/Plipbox
CD32/TF328
A500/V500v2
A500/MTec520
CDTV
MiSTer, MiST, FleaFPGAs and original Minimig
Peg1, SAM440 and Mac minis with MorphOS