Welcome, Guest. Please login or register.

Author Topic: Wifi on A1200  (Read 8596 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline Gilthanaz

  • Jr. Member
  • **
  • Join Date: Jul 2011
  • Posts: 62
    • Show all replies
Re: Wifi on A1200
« on: July 29, 2011, 09:06:38 AM »
@JJ: There is also the legal issues with unencrypted Wireless LANs:

Actually a WiFi should be firewalled anyway. The only reason why encrypted WiFis are really needed (besides the data security) is, that (at least over here) you are held responsible for whatever happens on your connections. If someone was to connect over my WiFi and do illegal things, even if I can prove it was not me, they'll get me arrested for "providing help in illegal activities" if I had not encrypted the connection. As soon as there is a minimal encryption that any evildoer must break before using the connection for his evil plots, I'am not to be held responsible anymore ;)

- Gil
 

Offline Gilthanaz

  • Jr. Member
  • **
  • Join Date: Jul 2011
  • Posts: 62
    • Show all replies
Re: Wifi on A1200
« Reply #1 on: July 29, 2011, 11:01:41 AM »
Mmmmkaaaay... no.
             

            .............Intarweb
..................|
LAN <=|> Firewall <|=> WLAN Router <=> WLAN Clients


And then some simple filters:
* by MAC
* by fixed IP per MAC  (MACs alone are way too simple to forge, takes like 2 seconds)
* Match chain => MAC ! fixed IP per Hostname => REJECT
* If you're hardcore you can also make a finger match for the OS that HAS to run on that machine with that IP and exactly that MAC, or even funnier:
* Have a random high port open on your machines where you have a rsync daemon drop a keyfile every hour that has to be synchronized on the firewall (using rsync with private keys for each machine), and have a match condition on the exact file bytes
* I guess I could come up with about 200 more creative solutions how to fortify a network so literally no one without physical access can fsck with it, not even if they break the WAP/WEP/WPA/[...] encryption.

- Gil

P.S:
Being paranoid and overly securing things does not mean they are not watching me!!