• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Can router antennas be aimed?

You would guess wrong, sir. :D

As for the exploit, that vulnerability is overstated. Almost nobody uses WPS.

How is the vulnerability overstated ? Does it not do what it says ?

Do you have any numbers to back up your assertion that almost nobody uses WPS ?

Why don't you go here and see how many vendors have it enabled by default, and then come back and tell me 'almost nobody uses it'.
 
His concern may be security, sure, but let's face it -- there's a huge problem with wireless signals flooding the spectrum, potentially causing all sorts of interference with one another. Building a half-Faraday shield to make the signal more directional is easy, cheap and helps keep your own signal pollution down to a minimum.

.

The problem here more seems to be that he/she is using Wi-Fi when wired options (Powerline, flat Ethernet cables) are available - and much more secure.
 
His concern may be security, sure, but let's face it -- there's a huge problem with wireless signals flooding the spectrum, potentially causing all sorts of interference with one another. Building a half-Faraday shield to make the signal more directional is easy, cheap and helps keep your own signal pollution down to a minimum.

Sorry, but no. Building an effective shield at those frequencies is, will virtually impossible to do inside a normal house. A faraday cage is not enough. You will need a shield where no hole or even discontinuity is larger than 1/10 the wavelenght, and no unfiltered conductors may pass through the shield. A part shield may reduce range in one direction, but it is impossible to control. It might well increase range in some unwanted and unexpected directions.

You can attach a directional antenna to the router, but it will only be useful for increasing the range in some direction, it will be no guarantee that the signal cannot be picked up in other directions.

The problem is that even if you might get good control of the radiation characteristics of the antenna itself, signals at these wavelengths bounce back from all sorts of stuff; walls, utilities, wires, persons, ...etc.

For security, sufficiently strong encryption is the ONLY solution, and, fortunately, readily available.

Hans
 
The problem here more seems to be that he/she is using Wi-Fi when wired options (Powerline, flat Ethernet cables) are available - and much more secure.

Powerline is not much more secure than Wi-Fi. It may travel quite far outside the house.

If you use strong encryption and a decent passcode, Wi-Fi is perfectly secure, unless you are a high-end spy. - In which case, I'm sure your handlers will have provided you with adequate solutions.

Hans
 
Wifi security isn't a big issue. Whatever sensitive stuff you're doing should already be encrypted, otherwise it doesn't help much because your vulnerabilities are elsewhere.

What I like to do is use two routers, one public and one private. The public one is throttled so it doesn't impede my personal traffic but can easily handle web surfing, email and such. It's actually cheaper that way than buying one expensive router that can do both jobs. I see it as a community thing.
 
Sorry, but no. Building an effective shield at those frequencies is, will virtually impossible to do inside a normal house. A faraday cage is not enough. You will need a shield where no hole or even discontinuity is larger than 1/10 the wavelenght, and no unfiltered conductors may pass through the shield. A part shield may reduce range in one direction, but it is impossible to control. It might well increase range in some unwanted and unexpected directions.

You can attach a directional antenna to the router, but it will only be useful for increasing the range in some direction, it will be no guarantee that the signal cannot be picked up in other directions.

The problem is that even if you might get good control of the radiation characteristics of the antenna itself, signals at these wavelengths bounce back from all sorts of stuff; walls, utilities, wires, persons, ...etc.

For security, sufficiently strong encryption is the ONLY solution, and, fortunately, readily available.

Hans
Thank you for the correction, I didn't realize it was that complicated; I mean, I knew there was some complexity but not to that extent.

I guess other signal methods need to be more thoroughly developed to help control for this annoying amount of signal pollution.
 
Powerline is not much more secure than Wi-Fi. It may travel quite far outside the house.

If you use strong encryption and a decent passcode, Wi-Fi is perfectly secure, unless you are a high-end spy. - In which case, I'm sure your handlers will have provided you with adequate solutions.

Hans

The physical advantages of powerline over a CAT5 type wire is:

a: You don't need to string wires around your home or have to deal with getting the wires inside the walls.

b: It is portable so that you can move the device easily as long as you have an outlet available.

Security wise I can think of these advantages:

a: It is encrypted (WiFi can be too of course so it's not so much an advantage over WiFi as it is an equal but it does need to be mentioned).

b: It is much less likely to be hacked into simply because you need to have a compatible device on the same circuit (in this case circuit means sharing the same transformer on the utility pole). No drive by or war driving.

c: The software that you use to set it up will tell you if any other device is present and connected and you can check it at any time. You can do this with wireless too of course but it's not a one click and check type deal.

d: Interference is a non-issue. No more "Dead spots" where your WiFi doesn't work well.

The disadvantages are:

a: It's a hub type system not a switch or router so adding powerline adapters will slow them all down. As long as you are using a higher speed adapter this shouldn't be an issue as long as you don't go crazy with it. 4 max would be my guess, that should keep it at or near 802.11.g speeds.

b: Expense. While they have come down in price a good one will run you about $125 a pair out the door.

c: There are some electrical situations where they won't work. Improper wiring (by that I mean wiring not installed up to code may not work, knob and tubing will still work though so age isn't an issue), most power strips will not work either (it has to do with the surge protection).

Overall I think that it falls somewhere in between a CAT5 hard wired setup and a wifi setup. Not for everyone but a good option to consider where mobility isn't an issue or is not a viable option and you are considering running cable.
 
Antenna design and radio wave propagation can be quite complex mathematically, but you might get some good results by experimenting with various high-gain, directional antenna designs, like the Yagi-Uda and waveguide models.

Here's a good jumping-off point for further research: http://www.turnpoint.net/wireless/has.html
 
I recently moved a wifi router to accommodate new bookshelves. Reception upstairs fell to almost zero. A little experimentation suggests that books make darn good shielding, as do bookends made of solid quartz.
 
I recently moved a wifi router to accommodate new bookshelves. Reception upstairs fell to almost zero. A little experimentation suggests that books make darn good shielding, as do bookends made of solid quartz.

My refrigerator was a great way to block off he rest of the house also. I have found that the higher up you can get the router, the further you can get a good signal, in general.
 
I recently moved a wifi router to accommodate new bookshelves. Reception upstairs fell to almost zero. A little experimentation suggests that books make darn good shielding, as do bookends made of solid quartz.

That's weird because my router is in our little library and there are two full shelves of books between my computer in a different room and the router. I have a shelf of books that sticks out into the room as well as the bookshelves that line the walls in the room and there is no reception problem. I wonder if it isn't some other variable involved in your upstairs downstairs issue.

I don't get it why the password protection isn't enough. Who the heck is it going around trying to use the wireless? I mean, I can't imagine my neighbors would have any capability to break password codes like that.
 
Last edited:
I don't get it why the password protection isn't enough. Who the heck is it going around trying to use the wireless? I mean, I can't imagine my neighbors would have any capability to break password codes like that.

It's called 'wardriving' -- when a person/people drive around looking for open wireless networks and/or looking for easy targets to crack. Sometimes it's for criminal enterprises, sometimes it's for the lulz.
 
It's called 'wardriving' -- when a person/people drive around looking for open wireless networks and/or looking for easy targets to crack. Sometimes it's for criminal enterprises, sometimes it's for the lulz.

Still, good encryption and a long passcode, and you will give them a hard time; probably harder than they want to have. It is like license plate theft where I am: Most plates are just clipped on, I have glued mine to the holder. This would not keep someone from stealing them, if they really wanted, but it is enough to make them move on to the next car.

Likewise, even the best protection can be cracked, but who will bother?

Hans
 
How is the vulnerability overstated ? Does it not do what it says ?

Do you have any numbers to back up your assertion that almost nobody uses WPS ?

Why don't you go here and see how many vendors have it enabled by default, and then come back and tell me 'almost nobody uses it'.

Simply turn off WPS. Problem solved. Now that everyone knows about it, anyone who still has WPS enabled deserves to get pwned.

ETA: I will note that if you have a Cisco (or linksys) router, you can't disable WPS. WTF Cisco?
Right about now I'm really glad I use Tomato.
 
Last edited:
Quick question. Is WEP better or worse security than WPS?

(I'm using WEP because the OS I used to have on my notebook wouldn't recognize the WPA encrypted connection my router had as default. But I'm not greatly concerned about security, since I don't live in a densely populated area.)

I recently moved a wifi router to accommodate new bookshelves. Reception upstairs fell to almost zero.

If you think in three dimensions, a regular wi-fi antenna is partially directional. It directs the signal out to the sides of the antenna rather than out through the ends. So if both antennas (the one on the router and the one on your wi-fi card) were vertical and directly above each-other, it would be normal to get next to no reception. This can be fixed by tilting the antennas.
 
Last edited:
Simply turn off WPS. Problem solved. Now that everyone knows about it,

Except when you cant turn it off. And everyone knows about it because I announced it in this thread ? Wow ?

anyone who still has WPS enabled deserves to get pwned.

That's right ! **** all the people who don't follow security and rely on vendors to do things correctly ! They deserve it !!
 
Quick question. Is WEP better or worse security than WPS?

(I'm using WEP because the OS I used to have on my notebook wouldn't recognize the WPA encrypted connection my router had as default. But I'm not greatly concerned about security, since I don't live in a densely populated area.)

You mean WPA (not WPS ?)

WEP is horribly broken, and is much worse.
 
(I'm using WEP because the OS I used to have on my notebook wouldn't recognize the WPA encrypted connection my router had as default. But I'm not greatly concerned about security, since I don't live in a densely populated area.)


Wha? WHA?

What OS are you running that doesn't support WPA? Windows 98?

Even with WEP, you could bolster your security a bit by setting your router to turn off broadcasting its own ESSID. That way, your network will be pretty much invisible unless somebody already knows it's there and knows the SSID, or unless they're deliberately "wardriving" (scanning for WiFi networks) with their network card in "monitor mode."

But yeah, I see your point about security being a lesser issue in a sparsely populated area. I live in a densely-populated city, and I keep my **** locked down tight. I use WPA with a crazy, unrecognizable passphrase, my network doesn't broadcast its own ESSID, I use MAC address filtering to only allow access to my own devices, and I've mapped the local IP address of my router's admin server to something other than 192.168.0.1. I've done this not because I'm paranoid, but just because I'm a nerd who gets off on this kind of stuff.
 
Last edited:
What OS are you running that doesn't support WPA? Windows 98?

The custom Linux OS that came pre-installed on my Eee PC (before Eee PCs started using Windows as default). It supported WPA, but for unknown reasons wouldn't connect.

I've since installed Puppy Linux on it instead, so maybe it's time I switch the router back to WPA.

ETA:

I've only got one neighbor beside me, and I don't think my router's signal is strong enough to reach the houses across the street. There's a parking lot for a "neighborhood house" behind me (where people can take basic courses in craft, cooking, computers, etc). In theory someone might park behind my house and break in to my internet, but it'd be easier to just pay $2 to use the internet at the neighborhood house for an hour.
 
Last edited:
Still, good encryption and a long passcode, and you will give them a hard time; probably harder than they want to have. It is like license plate theft where I am: Most plates are just clipped on, I have glued mine to the holder. This would not keep someone from stealing them, if they really wanted, but it is enough to make them move on to the next car.

Likewise, even the best protection can be cracked, but who will bother?

Hans
Sure, I have no argument with this; I was responding more specifically to SG's question of 'Who the heck is it going around trying to use the wireless?'
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom