<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1602343160402662832</id><updated>2011-11-13T12:54:07.361-08:00</updated><title type='text'>Sniffer-Proof</title><subtitle type='html'>securing your wireless perimeter</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://snifferproof.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1602343160402662832.post-7597579494081906771</id><published>2009-06-27T17:49:00.000-07:00</published><updated>2009-06-28T00:28:52.236-07:00</updated><title type='text'>PCI DSS -- The Retail POS Mandate for WirelessWall</title><content type='html'>&lt;h2&gt;&lt;span style="font-size:100%;"&gt;Introduction&lt;/span&gt;&lt;/h2&gt; &lt;p class="MsoNormal"&gt;TLC-Chamonix, LLC today unveiled its WirelesWall POS Architecture for XPe wireless Point of Sale Terminals. It achieves &lt;b style=""&gt;PCI DSS compliance&lt;/b&gt; by combining AES encryption, firewall and end-to-end security in a standards compliant &lt;i style=""&gt;software solution&lt;/i&gt;. It allows replacement of WEP without having to disturb existing networks or POS terminals (including Fujitsu TeamPoS terminals).&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;WirelessWall is a unique, encrypting firewall that leaves the network infrastructure fully intact while providing a transparent &lt;b style=""&gt;&lt;i style=""&gt;instant upgrade&lt;/i&gt;&lt;/b&gt; to WPA2-Enterprise level security, allowing business applications and operations to continue undisturbed. It gives peace of mind from better security, compliance, and loss prevention, while avoiding the cost of new equipment, new leases and downtime.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2&gt;&lt;span style="font-size:100%;"&gt;Industry Initiative&lt;/span&gt;&lt;/h2&gt;  &lt;p class="MsoNormal"&gt;Faced with the prospect of &lt;i style=""&gt;billions&lt;/i&gt; of dollars in losses and lawsuit settlements, the retail industry is finally taking serious measures at self-regulation to protect merchants and consumers from wireless security breaches. Consider:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;2009 TJX, the parent company of TJ Maxx, Marshalls and other retailers, paid a $9.8M settlement to 41 states after a $40.9M settlement to Visa for wireless POS breaches. &lt;i style=""&gt;It absorbed over $135 million loss from its 2007 incidents alone.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;2008 breaches identified by the Identity Theft Resource Center-breaches totaled &lt;span style=""&gt;449&lt;/span&gt; with over &lt;u&gt;22 million records &lt;/u&gt;exposed. (That’s more than all breaches in 2007 and the individual record count is climbing and will exceed 2207 as well)&lt;/li&gt;&lt;/ul&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;2007 breaches totaled &lt;span style=""&gt;448&lt;/span&gt; paper and electronic breaches with 127 million records exposed. &lt;/li&gt;&lt;/ul&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;2006 breaches totaled &lt;span style=""&gt;315&lt;/span&gt; affecting nearly &lt;u&gt;20 million individuals&lt;/u&gt;. &lt;/li&gt;&lt;/ul&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;2005 breaches totaled &lt;span style=""&gt;158&lt;b&gt; &lt;/b&gt;&lt;/span&gt;affecting more than 64.8 million people. &lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The Payment Card Industry (PCI) is a consortium of worldwide credit card companies (Visa, Mastercard, American Express, Discover and JCB International). To confront and mitigate these mounting losses, and faced with imminent regulation by state and federal agencies plus penalties for violating existing privacy laws, they formed a Security Standards Counsel which implemented a Data Security Standard (PCI DSS) to preemptively control the problem.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="font-weight: bold;" class="StyleHeading2Firstline0"&gt;&lt;span style="font-size:100%;"&gt;PCI DSS – A &lt;st1:place st="on"&gt;New World&lt;/st1:place&gt; Order&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The latest edition of the standard mandates improved wireless security practices and drops the broken Wired Equivalency Protocol (WEP) as an approved method, in favor of protocols using strong encryption such as AES. See: &lt;a href="https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-2.pdf"&gt;PCI DSS 1.2&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;PCI DSS is not merely a set of recommendations -- &lt;b style=""&gt;non-compliance is not an option&lt;/b&gt;. It is a &lt;i style=""&gt;contractual obligation&lt;/i&gt; which demands all retail merchants big and small to comply as a condition of being allowed to continue processing credit cards and consumer information via electronic Point of Sale (POS) terminals or other wireless method. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;According to mandate, retailers may not implement new wireless payment systems that use WEP after March 31, 2009. For those that already have wireless payment systems in place, they must &lt;u&gt;stop using WEP for security as of June 30, 2010&lt;/u&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;Impact Assessment&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;Naturally, this has enormous significance to operations and the bottom line of retailers. Perhaps just as great is the cost to POS terminal vendors, who have a large inventory of WEP-only wireless terminals that are often leased to merchants. They stand to lose considerable sums replacing or retrofitting equipment at costs which cannot easily be passed on to merchants, especially in a bad recession. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;In these difficult times, vendors and merchants alike need a lower cost, easy to deploy solution that scales from small business to large enterprises with least impact.&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-size:100%;"&gt;WEP Dominates&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;The mandate bans the use of WEP, but it still dominates and others like WPA2 are poorly adopted.&lt;span style=""&gt;  &lt;/span&gt;An &lt;a href="http://www.airtightnetworks.com/home/resources/knowledge-center/financial-districts-scanning-report.html" target="_parent"&gt;Airtight 2009 Financial Districts Survey &lt;/a&gt;of 3,632 access points in major cities found &lt;u&gt;half&lt;/u&gt; were Open or used WEP security. It concluded:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;Everybody who knows security knows WEP is broken, but it still dominates.&lt;/li&gt;&lt;li&gt;Some used WPA, which had a crack demonstrated in &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;Tokyo&lt;/st1:place&gt;&lt;/st1:city&gt; in 2008.&lt;/li&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Others hide SSIDs which doesn't protect traffic captured by wireless sniffers.&lt;/li&gt;&lt;li&gt;&lt;!--[endif]--&gt;39% were “&lt;u&gt;enterprise&lt;/u&gt;” APs (corporate HQs, offices, etc.)&lt;/li&gt;&lt;li&gt;&lt;!--[endif]--&gt;&lt;b&gt;Only 11% used WPA2&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Even worse than this news is that of the tiny few organizations using WPA2, almost all have implemented pre-shared keys (WPA2-PSK) which has well known dictionary cracks, like &lt;a href="http://www.willhackforsushi.com/Cowpatty.html" target="_parent"&gt;CoWPAtty&lt;/a&gt; that can crack it in seconds – in many ways, making it worse than WEP.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2 style="font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;Why Fix Something that Isn’t Broken?&lt;/span&gt;&lt;/h2&gt;  &lt;p class="MsoNormal"&gt;The abysmal failure of WPA2 to gain widespread adoption has not prompted the industry to question why (almost) no one is using it.&lt;span style=""&gt;  &lt;/span&gt;Serious debate and changes in the telecommunications industry to adopt better technology and new standards will be needed before WEP is entirely eliminated.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;WEP is still pervasive in large part because wireless equipment manufacturers and industry groups failed to take decisive action to totally replace it and continue to manufacture equipment that supports it. WPA2 is still a security configuration option (and alphabetically WEP is first in most lists). Many users are simply unaware of the difference.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;There is also the reluctance to switch from existing protocols until there is an incident that demands it. This translates to the maxim: &lt;i style=""&gt;Why fix something that isn’t broken?&lt;/i&gt; Unfortunately, this common sense rule can be very costly when applied to security. WEP &lt;b style=""&gt;is&lt;/b&gt; broken, but most users don’t know it. The feeling is that if WEP weren’t “good enough”, why would the protocol still be supported by network equipment?&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Consumer awareness is one aspect. Even among the technically knowledgeable, there is little appreciation of the distinction between WPA, WPA2-PSK and the only truly strong protocols: &lt;b style=""&gt;WPA2-Enterprise&lt;/b&gt;. All others suffer risk of Man-In-The-Middle attacks, brute-force guessing, or key exchange compromises. The dictionary vulnerability risk of WPA2-PSK can be more vulnerable than WEP.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;WPA2-Enterprise is the best solution, but &lt;i style=""&gt;many businesses just don’t have back-end RADIUS authentication and LDAP identity management servers or IT with the level of knowledge required to use them&lt;/i&gt;, so they accept the risk&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;h2 style="font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;The WirelessWall Architecture&lt;/span&gt;&lt;/h2&gt;  &lt;p class="MsoNormal"&gt;The award winning WirelessWall is a government certified (FIPS 140-2) wireless security suite used by the military and DOE. Renown for its investment protection value, WirelessWall adds WPA2-Enterprise grade protection to the current network as a &lt;i style=""&gt;software-only solution&lt;/i&gt; instead of replacing legacy wireless hardware and firmware. The DoD 8100-2 directive is mandate for federal and state governments to provide standards based end-to-end strong security. WirelessWall satisfies this directive and was assessed by the Joint Interoperability Testing Center (JITC) for use by Coalition Forces. &lt;span style=""&gt; &lt;/span&gt;This high level of protection is now being used to benefit the private sector and retail to eliminate hacking or sniffing end-to-end. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;br /&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" style="'width:243pt;" ole=""&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msohtml1\01\clip_image001.emz" title=""&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_KVUCcCAdL6E/SkcXAVe15nI/AAAAAAAAAA0/Lb7CQ6XOjvU/s1600-h/image002.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 272px;" src="http://4.bp.blogspot.com/_KVUCcCAdL6E/SkcXAVe15nI/AAAAAAAAAA0/Lb7CQ6XOjvU/s320/image002.gif" alt="" id="BLOGGER_PHOTO_ID_5352271976687068786" border="0" /&gt;&lt;/a&gt;&lt;!--[endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:oleobject type="Embed" progid="Visio.Drawing.11" shapeid="_x0000_i1025" drawaspect="Content" objectid="_1307652505"&gt;  &lt;/o:OLEObject&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Even if terminals and WiFi gear only support WEP or no security at all, it adds a layer of strong encryption without any reconfiguration. Because it bundles WiFi AES encryption with RADIUS, LDAP and Firewall Policies &lt;b style=""&gt;all in one package&lt;/b&gt;, it is simpler to deploy and administer, and more cost effective than having those in a separate back-end (although it will support external services if needed). WirelessWall supports all wireless gear: all 802.11 protocols, WiMax 802.16e, Mesh and 4G. Using WirelessWall gives you everything for a fraction of the cost and none of the inconvenience of alternatives.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;br /&gt;&lt;span style="color: rgb(65, 65, 65);font-family:Calibri;font-size:10;"  &gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1026" type="#_x0000_t75" style="'width:197.25pt;height:63pt'"&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msohtml1\01\clip_image003.jpg" title="tlc-logo-md"&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;b style=""&gt;&lt;span style="color: rgb(65, 65, 65);font-family:Calibri;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;b style=""&gt;&lt;span style="color: rgb(65, 65, 65);font-family:Calibri;" &gt;Contact: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=";font-family:Calibri;font-size:100%;"  &gt;TLC-Chamonix, LLC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;st1:address st="on"&gt;&lt;st1:street st="on"&gt;&lt;span style="font-family:Calibri;"&gt;120 Village   Square Suite&lt;br /&gt;11&lt;/span&gt;&lt;/st1:street&gt;&lt;span style="font-family:Calibri;"&gt; &lt;st1:city st="on"&gt;Orinda&lt;/st1:city&gt; , &lt;st1:state st="on"&gt;CA&lt;/st1:state&gt; &lt;st1:postalcode st="on"&gt;94563&lt;/st1:postalcode&gt;, &lt;st1:country-region st="on"&gt;USA&lt;/st1:country-region&gt;&lt;/span&gt;&lt;/st1:address&gt;&lt;/span&gt;&lt;span style=";font-family:Calibri;font-size:100%;"  &gt;&lt;br /&gt;Phone : +1-877-479-4500&lt;br /&gt;&lt;span class="search"&gt;E-Mail:&lt;/span&gt;&lt;a href="mailto:info@tlc-chamonix.com"&gt;info@tlc-chamonix.com &lt;/a&gt;&lt;br /&gt;&lt;a href="http://wirelesswall.com/"&gt;http://wirelesswall.com/&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1602343160402662832-7597579494081906771?l=snifferproof.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferproof.blogspot.com/feeds/7597579494081906771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1602343160402662832&amp;postID=7597579494081906771' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/7597579494081906771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/7597579494081906771'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/2009/06/pci-dss-retail-pos-mandate-for.html' title='PCI DSS -- The Retail POS Mandate for WirelessWall'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_KVUCcCAdL6E/SkcXAVe15nI/AAAAAAAAAA0/Lb7CQ6XOjvU/s72-c/image002.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1602343160402662832.post-553091677974649634</id><published>2009-05-27T08:06:00.001-07:00</published><updated>2009-05-28T13:05:49.524-07:00</updated><title type='text'>Why (not) 11i?</title><content type='html'>A few years ago, the 802.11i draft standard was touted as the solution to secure wireless and make up for the weaknesses of WEP or some of the proprietary protocols like &lt;a href="http://blogs.zdnet.com/Ou/?p=454&amp;amp;page=2"&gt;LEAP&lt;/a&gt;. Indeed, the 802.11i standard did present a solution called Robust Secure Network (RSN) in addition to weaker levels to accommodate industry transition and "good enough" security for personal/home use.&lt;br /&gt;&lt;br /&gt;Fast forward to today. Enterprise mobility and a remote workforce is common. It's an understatement to say the security perimeter is longer.  With the coming WiMax revolution, the perimeter can be measured in miles. The 802.11i draft became the 802.11-2007 standard.  The need for RSN as the &lt;span style="font-weight: bold;"&gt;only &lt;/span&gt;security level is greater than ever.&lt;br /&gt;&lt;br /&gt;Even though the RSN calls for WPA2-Enterprise, most deployments use WPA2-Personal that allows for pre-shared keys (PSK). The resulting encryption can be strong, but the key is vulnerable to dictionary attacks (like &lt;a href="http://www.willhackforsushi.com/Cowpatty.html"&gt;CoWPAtty&lt;/a&gt;) so it could be guessed. It also doesn't provide end-to-end protection to the datacenter. The "keys are in the ignition" with the 802.11-2007 standard because it does not allow the topography where the Access Point is not the holder of the key material. The CAPWAP standard proposed this "Split MAC" model that made it possible to handle encryption at the datacenter, but this is still a long way from ratification.&lt;br /&gt;&lt;br /&gt;In summary, if we ask why not 11i or why not WPA2, the answers are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;WPA2 is usually deployed as the weaker WPA2-PSK.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;WPA2 in all forms leaves the "keys in the ignition" for Access Point vulnerability.&lt;/li&gt;&lt;li&gt;WPA2 does not provide end-to-end encryption -- the back-door is open.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;WPA2 does not avoid the "weakest link" syndrome of non-uniform security across the enterprise.&lt;/li&gt;&lt;li&gt;Many client machines still don't support WPA2, which can result in allowing pockets of weakness, or costly replacement of user devices if they aren't commodity PCs.&lt;/li&gt;&lt;li&gt;WPA2-Enterprise is (very) difficult to implement across Mesh networks.&lt;/li&gt;&lt;li&gt;Cost of upgrading the wireless infrastructure to WPA2 can be high.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;The use of WirelessWall solves every one of the above problems to make a certified strong, uniform blanket of security and keeps costs down by protecting the investment in existing wireless assets.&lt;br /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;input id="gwProxy" type="hidden"&gt;&lt;!--Session data--&gt;&lt;input onclick="jsCall();" id="jsProxy" type="hidden"&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1602343160402662832-553091677974649634?l=snifferproof.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferproof.blogspot.com/feeds/553091677974649634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1602343160402662832&amp;postID=553091677974649634' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/553091677974649634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/553091677974649634'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/2009/05/why-not-11i.html' title='Why (not) 11i?'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1602343160402662832.post-2582505440917971637</id><published>2008-08-08T19:46:00.000-07:00</published><updated>2008-08-11T15:03:19.150-07:00</updated><title type='text'>Where's Your End-Point?</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_KVUCcCAdL6E/SJ0G88ysbUI/AAAAAAAAAAM/SxYheYjbVak/s1600-h/proximity.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_KVUCcCAdL6E/SJ0G88ysbUI/AAAAAAAAAAM/SxYheYjbVak/s320/proximity.JPG" alt="" id="BLOGGER_PHOTO_ID_5232345986255056194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Modern wireless networks are fielded with security without thought to where the security ends. Typical 802.11 access points secure the 300-foot or so space between the station and the Access Point (AP). This is fine for a Home network with an AP or router only a few feet away, but inadequate for an enterprise or corporate network where the larger wired or wireless gap to the data center can  span floors in a building, or between facilities. If WiMAX or long-haul bridges and repeaters are used (as in Mesh Networks), the distance can be many miles/km. This leaves a huge backdoor that can be sniffed or tapped. This weakness has now made headlines and the risks have been shown to directly translate to major financial cost in the billions due from theft and privacy loss.&lt;br /&gt;&lt;br /&gt;To be really secure, encryption should originate from the Datacenter, not each AP. This way, the AP is just a passthrough and can be set to open mode and still pass the encrypted traffic end-to-end, regardless of distance. The &lt;a href="http://wirelesswall.com"&gt;&lt;span style="font-weight: bold;"&gt;WirelessWall&lt;/span&gt;&lt;/a&gt; software from TLC-Chamonix, LLC is both the cheapest solution and the most secure, since it makes &lt;span style="font-weight: bold; font-style: italic;"&gt;any &lt;/span&gt;existing wireless infrastructure sniffer-proof with no new capital equipment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1602343160402662832-2582505440917971637?l=snifferproof.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferproof.blogspot.com/feeds/2582505440917971637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1602343160402662832&amp;postID=2582505440917971637' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/2582505440917971637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/2582505440917971637'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/2008/08/wheres-your-end-point.html' title='Where&apos;s Your End-Point?'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_KVUCcCAdL6E/SJ0G88ysbUI/AAAAAAAAAAM/SxYheYjbVak/s72-c/proximity.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1602343160402662832.post-5658150479035200652</id><published>2008-08-08T19:09:00.000-07:00</published><updated>2008-09-09T02:06:57.724-07:00</updated><title type='text'>Access Points: An Open Back Door</title><content type='html'>Every Access Point on the market is vulnerable because even though encrypted information may go out, unencrypted information goes in. The flawed assumption is that the wire going into the AP is trusted. This makes it easy to tap, sniff or spoof.&lt;br /&gt;&lt;br /&gt;Today's standards for WPA2 (Personal or Enterprise) perpetuate the exposure by requiring key material or RADIUS passwords to be stored on the AP itself.  This is a vulnerability for AP hacking -- either physical (opening up the AP) or by gaining wireless access to the AP administrative channel and getting Pre-Shared Keys or RADIUS shared secrets). The AP could then spoof the backend or be reprogrammed to broadcast traffic in the clear on another channel. This is particularly true of the Atheros Multiband chipsets that can support many "virtual" APs.&lt;br /&gt;&lt;br /&gt;Access and firewall policies are not centralized or standard between AP vendors. These must be replicated on each AP whenever the policy changes, adding to cost and complexity of administration, which means they are less likely to be changed often even though that would strengthen security. Various remote management schemes add another dimension to the exposure.&lt;br /&gt;&lt;br /&gt;Centralized Security Management offers the advantage of keeping key material and 802.1X authenticator passwords at the Datacenter rather than on APs at the edge of the security envelope. This model is reflected in the "Split-AP" model in the upcoming IETF CAPWAP  standards and used by WirelessWall. It keeps the APs blind to all security profiles.&lt;br /&gt;&lt;br /&gt;In summary, WirelessWall is recommended because it follows the CAPWAP Taxonomy guidelines for a Split-AP mode. CAPWAP is a future standard that is not yet ratified and years away from market. WirelessWall provides comparable security-model functionality &lt;span style="font-style: italic;"&gt;today  &lt;/span&gt;as a FIPS 140-2 software solution using AES-CCMP Layer 2 encryption, 802.1X and EAP-TTLS with mutual authentication. It is smart security to keep APs "dumb" -- administrators have less to worry about because they don't expose the data center to compromise at every AP location.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1602343160402662832-5658150479035200652?l=snifferproof.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://snifferproof.blogspot.com/feeds/5658150479035200652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1602343160402662832&amp;postID=5658150479035200652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/5658150479035200652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/5658150479035200652'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/2008/08/access-point-penetration-risks.html' title='Access Points: An Open Back Door'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1602343160402662832.post-5182871248916895922</id><published>2008-08-08T12:47:00.001-07:00</published><updated>2008-10-28T14:40:52.562-07:00</updated><title type='text'>Wireless Warning</title><content type='html'>&lt;h1&gt; T.J. Maxx Data Theft Likely Due To Wireless 'Wardriving'&lt;/h1&gt;&lt;h1 class="storyHeadlineFull" style="margin-left: -2px; padding-left: 1px; letter-spacing: 0px; text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;[&lt;a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=199500385"&gt;article&lt;/a&gt;]&lt;/span&gt;&lt;/h1&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;You've read the headlines. A small ring of hackers using wireless sniffers stole 45 million credit cards from a single chain resulting in LOSSES IN THE &lt;span style="font-weight: bold;"&gt;BILLIONS&lt;/span&gt;.  This should put retailers and any organization using WiFi on notice. That underscores how vulnerable WiFi really is and the stakes. DON'T LET THIS HAPPEN TO YOU.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;What many don't know is that EVERY ACCESS POINT ON THE MARKET TODAY IS VULNERABLE AND IMPOSSIBLE TO SECURE. 802.11i (WPA2) was supposed to solve the weaknesses in earlier encryption (WEP). IT DOES NOT. Stronger encryption alone is not enough.&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;Access Points truly are impossible to secure because of the flawed assumption in the industry that the wire going in is trusted and unencrypted. While acceptable for home wireless, too many organizations have a security perimeter that is a lot farther than a router a few feet from their computers. Access Points used in business and government are often on a different floor, or a different building on campus, and can be connected to the datacenter on a LAN, or worse, by wireless repeaters and bridges that may have poor or no security. Miles of vulneraility and exposure to physical tapping, interception or sniffing.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;a href="http://wirelesswall.com"&gt;WirelessWall&lt;/a&gt; treats the AP as a conduit, it encrypts all traffic at Layer 2 before it goes into the AP, and it is only decrypted by the trusted user at the end-point. Because it is Layer 2, EVERYTHING above it is secure, without relying on elective, weak or slow application security at Layer 3 or above.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;If you're serious about Loss Prevention, choose WirelessWall.&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in -1pt 0.0001pt 1pt; line-height: 11.4pt;"&gt;&lt;br /&gt;&lt;span style="color: rgb(54, 52, 53); letter-spacing: -0.35pt;font-family:Arial;font-size:10;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1602343160402662832-5182871248916895922?l=snifferproof.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/5182871248916895922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1602343160402662832/posts/default/5182871248916895922'/><link rel='alternate' type='text/html' href='http://snifferproof.blogspot.com/2008/08/first-line-of-defense.html' title='Wireless Warning'/><author><name>Phil Smith</name><uri>http://www.blogger.com/profile/02292232789498247290</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
