Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, June 16, 2014

How secure is your home WiFi?


Do you have WiFi at home? Do you have a mobile Hotspot? Maybe you have a small business or a Church with a WiFi wireless network. 
The next question might be a little more difficult to answer:  How secure is that WiFi? 

Most people don't give this a lot of thought.  As long as they can connect to their wireless network and access the internet in order to check email or watch Netflix, then they don't give their wireless network another thought.  But the real question is, "Should you"?

How would you like someone accessing your network, using the public IP address of your network, and doing nefarious things on the internet?  They could be viewing or downloading kiddie porn across your network, downloading illegal media, or even just sucking up your bandwidth by streaming or downloading large amounts of data thereby reducing the throughput potential of your network for your own use.  That means your favorite Netflix or YouTube video will not be able to stream properly and result in a large amount of buffering.  This kind of activity can also lead to your Internet Service Provider (ISP) reducing or blocking your service, or even to the authorities showing up at your doorstep with a warrant to arrest you and seize your computers.  While you might be able to prove that you are innocent, you will still need to pay the cost to prove the illegal activity was not you.

So, how can you protect yourself you might ask?  Well the answer comes back to the question first asked: How secure is your wireless network?  In other words, is your wireless network wide open so anyone may access it or is it secured and access limited with a passcode?  There are also some other basic settings that should be configured  to help optimize the speed and security of your network.

The first thing to do is to figure out how to log into your router.  This is usually done by visiting an internally hosted website which within the router itself.  This site is for administration purposes and is technically only accessible to the internal network but not easily from the the external network, better known as the public internet.  Consult your owners manual for the web address for this admin site for your specific router, but for most routers the web address is: http://192.168.1.1

Once you open this website, the router will ask you to log in.  Since this is the main admin site where you will set all the configuration options for the router, it is secured by a username and password.  The user name should be "admin", but once again please consult the documentation for your specific router as it might be different.  The default password is usually one of the following: "" (No password), "admin", "12345", or "password".  If you have visited here before, you may have changed the password already.  Enter in the login credentials, username and password, for your router.

Once you are logged into your router, you should see the configuration or setup page specific to your router.  Each one is slightly different and have the various setting organized in different ways, but most all routers present the basic settings which we will cover here in this discussion.  I will use the following Linksys screen shots for reference when describing the various settings, but keep in mind that your settings might be in a different section or labeled slightly different based on your router.

Below are the various things in your setting which you will want to set in order to secure your router and wireless network.

1) DHCP
This is used to dynamically assign IP (Internet Protocol) addresses on your local network.  Every device that wants to, and you allow to, connect to your local network will need an IP address.  The router handles this using the range of IP addresses specified in this setting.
First make sure DHCP is enabled, then verify the start IP address and either the ending IP address or the number of DHCP addresses to use.  If, as shown below in the Linksys example, the setting requires a starting address and a number of DHCP addresses, make sure that the resulting ending IP address will not be greater then 254.  In other words, if your starting IP address is 192.168.1.100 (where 100 is the number you entered), and the number of DHCP address you entered to allow is 155.  Then this would result in an ending IP address of 192.168.1.254.  However, if you entered 157, this would result in an ending address of 192.168.1.256 which is an invalid address and will result in an error.


2) SSID and WPS
This is your wireless network ID or the name of your network.  This ID is the name that you see when you search for a wireless network within windows or on your phone.  To be extra secure, you can "hide" this ID by turning off the option to Broadcast the SSID.  This means that when you scan for wireless networks, your network ID will not popup as being an available option, i.e. It will be hidden.  To connect,  you would have to type in the network ID and connect manually every time you want to connect.  But I do not recommend this as it becomes a pain because your devices will never automatically connect to your network either.  So level the Broadcast SSID option set to true.  
Set the SSID to a name that means something to you, but it is best not to leave it as the default of "Linksys G***" or whatever.  The reason is that leaving the SSID as the default will give would be criminals information about your network which would allow them to possibly compromise it if desired.  Also renaming your network to something you recognize will help you identify your network instead of a neighbor's network.
For Network Mode, choose the "Mixed" option.  The reason is that this will allow the greatest range of devices to connect to your wireless router.  If you are absolutely certain that you know that only one kind of device may be connecting to your network, like maybe only Wireless-N network cards, then you can choose that option.  But as a general rule, the safer choice is "Mixed"
For the Radio Band and Wide Channel options, you can change those, but again when you change them from the defaults, you are limiting the devices that might be able to connect.  So the recommended option is to leave them as their defaults.
If given the option to turn off WPS (Wi-Fi Protected Setup), make sure that this is either set to Manual, off, or changed away from WPS.  WPS can be used as an exploit to gain access into your network.


3) Wireless Security
Wireless security is another area that is commonly overlooked in setting up a private WiFi network.  To enable wireless security, navigate to that option in the menu structure for your device, then select the Security Mode of WPA2 Personal (or WPA2/WPA - or sometimes it is listed as WPA2-PSK).  Then if given the option, choose the WPA Algorithm of "TKIP+AES".  Next create a Pass-phrase with which you will use to connect to the network.  This should be a phrase which means something to you and is at least 10 characters long.
The other Security Mode settings are:

  • WEP (Wired Equivalent Privacy) - This is a Wireless security mode that was introduced with the original 802.11 wireless network standard. While it does offer some encryption and protection, it's algorithms can easily be broken.  This makes it almost as unfavorable as leaving your network without encryption.
  • WPA (Wi-Fi Protected Access) - This wireless security mode was created in order to address the security concerns, but still was lacking higher encryption standards and had a few vulnerability which could be exploited allowing people to access a secure network.
  • WPA2 (Wi-Fi Protected Access II) - This wireless security mode was release to supersede WPA and included AES encryption which helped eliminate the risk of attackers being able to breach the network directly.  Although both WPA and WPA2 both still have a vulnerability in terms of the WPS (Wireless Protected Setup) function.  If this function is disabled, then the vulnerability is removed.


If you'd like to learn more about the different Wireless Security Modes, visit this Blog about The Difference Between WEP WPA and WPA2

4) Change default password for the admin account.
This is a very important step.  It is highly recomended that you not only change the Default SSID, but you should also change the admin password as well so that others are not able to easily gain access to your router. The reason this would be bad is that if someone got access to your router, they could change your passwords, change your network ID, exclude your devices from connecting, or even set up more advanced networking options without you being aware.  I suggest using a password safe like www.LastPass.com to generate a random password and then store it do you don't have to worry about remembering it.


So, what happens if you forget your new Admin password or you mess up some settings and don't know how to get them back to a working state? 
Well luckily the answer is easy for most modern devices these days. Usually on the back, but sometimes on the front, there is a small round push button. If you use a pencil or a paper clip, push that button in for at least 10 seconds, maybe 30 seconds for some devices. This will perform a hard reset and change all router settings back to the factory defaults. Once back to the defaults, you can reapply your changes. 

I hope this helps you in setting up your own home wireless network and maybe even with  help troubleshooting issues with your router. Please feel free to add your own nuggets of information about your wireless networking experience in the comments below.


Friday, April 18, 2014

Heartbleed: Are you bleeding out?

So you have heard about the Heartbleed bug that is affecting the Internet, but what is it really and what does it mean to you? Should you really be concerned?

Some reports say that it is the worst bug discovered on the Internet so far and others seem to brush it off as just another tech mumbo jumbo.  But I'm betting that you'd like someone to explain it so you know what the heck this thing is and if you really should be concerned, right? Well, as your Nerd friend, let me say that you need to be a little concerned about all this and here is why.

What this whole thing is about is allowing someone, who is not you, to snoop, or "read", your secure Internet communications.  Let's see if I can explain; let's say you log into Amazon.com to do a bit of shopping. You find the items you want to buy and add them to your card. You then go to your shopping cart to check out. Now you notice the little green pad Lock up in the address bar (if you're using Chrome, otherwise it might be elsewhere depending on your browser). This means that you have a secure connection with the Amazon server, i.e. Only you and the Amazon server can read the communication between the two of you. This is because there is an SSL, or Secure Socket Layer, connection between your browser and the server. Think of it as a pipe, an encrypted pipe, between your browser and the server. Anyone trying to intercept and read messages sent along this secure pipe only can see garbley gook because everything inside it is encrypted.

Now, this connection is kept alive with what is known as a heartbeat message. The purpose of the heartbeat message is to tell each side that the other is still there and not to close the connection. This Heartbleed bug allows someone outside the pipe to intercept this heartbeat message and with a slight modification, request the original heartbeat message but also request additional bytes of data from server memory for that connection. This means that anything in memory for that connection could be exposed. That could be the encryption keys or even username & passwords. If the encryption keys are exposed, this is then bad because the attacker could use that information to read all communications in that secure pipe.  

Ok... So what, Right?  You might ask, "How does this effect me? And am I really at risk?"
Well the short answer is: Yes you are at risk. Why? Because over half of the internet, and maybe as much a three quarters (or 75%), might have been at risk of having their secure communications read.  Most small services like eRetailers or online service providers use OpenSSL to secure their sites. But even the big companies like Google, Yahoo, Facebook, and Twitter use OpenSSL and had to take steps to secure against this bug.  The real kicker about this bug is that it was introduced to the internet back in January of 2011, if the reports can be believed.  This means that for about 2 years, anyone that might have known about this bug could have been intercpting all of your secure online communications.  We do know that the NSA was exploiting this bug to spy on all of us.  But what we don't know is who else might have been exploiting it also.

So, what can you do about it? Well, the only real answer is to change your passwords on all affected sites and services.  Now, how do you know if a site was affected or not? Well, the best way is to check their website to see if they mention applying a patch for Heartbleed or reissuing the security certificates for their site. But really the easiest way is to use a tool like the one provided by LastPass.com to check each of the sites you use to see if you need to change your password or not (Click here to find out).

But doing this might seem like a monumental task, especially if you have a lot of sites.  Well, this is yet another reason for using a password manager, or password safe as sometimes termed, to store and manage your passwords.     

This article by  from CNET, entitled: "Beyond Heartbleed: Why you need a password manager", really provides great insight into how to go about cleaning up your accounts after a major internet event like this.  Even if you have been reluctant to try a password manager in the past, the shear effort of remembering all the passwords to each site you need to change can be daunting.  These tools help make that task a little easier.

So, what lessons should we take away from this event?  Well the first is to make sure that you change the passwords for all of you accounts once your service providers have patched their systems.  Then going forward, make sure you change your passwords on a regular basis.  For some of you, that might be every 90 days, as some security professionals suggest.  But for the rest of us, let's try to do better and try to change those passwords at least once a year!

Tuesday, February 4, 2014

Why worry online? You're safe right?

Like many IT professionals, I get questions all the time from friends and family about their computers or devices. I seem to be constantly giving advice and assistance on what they should buy, why their computer or device doesn't seem to be working properly, or how to fix a problem they are having.

All this is great and I truly love helping my friends and family when I can. But, like most of my techie friends, there is only so much time in the day and at some point being a free tech support becomes too much.  So, I thought I might write a couple things here to help answer some of these techie type questions and give a techie perspective on things.  Hopefully someone might find these useful and make both their digital and physical lives better in the process. 

Ok, to that point, the first topic I thought I'd share some thoughts on is being safe online.
First let me ask you a question, how safe do you consider yourself online? Is your version of safety like these two youngsters shown here?

Maybe you use multiple passwords for all your accounts, you try to stay away from shady websites, when viewing an email from an unknown sender you don't open attachments, and you run anti-virus software. Does that sum up your view on online security? Maybe you also have firewall software running too. All these things are good. Do you also have the thought that, "this is good enough, why would anyone want to hack into my accounts anyway?  I don't have anything important." 

That's one of the biggest farce's that we tell ourselves. The truth is that anyone and everyone who is online is a potential target. The question is, how temping of a target are you? The more important you become, the easier it is to "hack" into your accounts do to lax security on your part, or the more valuable the information is which is associated with your accounts then the higher the likelihood is that you will become the target of an attack attempt.

Attacks are not always just about gaining access to your financial information.  An attack could be to gain access to your account for purposes of gathering information about you or your contacts, they could target specific accounts in order to find out a very specific piece of information they could then use to access another of your accounts which contains more valuable information, say your email or your credit card.  This is called a Social Engineered Hacking.  In this case they are not cracking a password but circumventing the system by gaining access to your other less secured accounts to gain information like the last 4 digits of your credit card, your mailing zip code, or even answers to your security questions.  With this kind of information they could then reset your password on the account they want to access and then gain access to that account.  Once in, they can do whatever they want.  Delete information stored online, send malicious emails, deface websites in your name, post hate blogs, etc.

With weak passwords, hackers do not even need to go to these extreme methods to gain access to your email.  You might think that your email is safe because you don't have anything in it that is worth reading.  But the truth is that hackers don't care about your email.  They do want your email address in order to use it to send bulk spam out to all your contacts, as well as whomever else they want.  This is one way that spamming gets out of control and why it is so hard to catch spammers.

So what can you do?  Is all a lose?  Should you bury your proverbial head in the proverbial internet sand?  or maybe even go cold turkey and cut off the online addition all together?  While going cold turkey is probably the safest, it really isn't practical these days.  So the question really is what to do, and the answers really aren't all that hard.  Well, I say that, but the truth is that you can take some relatively simple steps to keep yourself relatively safe online.  But nothing will keep you 100 percent safe from digital threats as long technology is a part of your life.  Don't believe me, go do a little research on the Stuxnet virus (http://en.wikipedia.org/wiki/Stuxnet) and ask Iran how that worked out for them.

So what can you do to be safe?  Well here are a few simple things to do:
1) Have a unique 20+ character password for each of your sites or applications.  Anything below this is easily hacked.  I could bore you with the details, but trust me when I say this.  And those of you with the password of "Password123", just stop it, ok?

2) Store your password in a secure online password safe, like LastPass (http://www.LastPass.com).  No one can have a unique 20+ character password for every site or application and hope to possibly remember what each and every password is, so instead, remember a single password and let a password safe remember them for you.

3) Use a Sandbox tool like Sandboxie (http://www.Sandboxie.com) to browse the web in a more secure way.  Using something like this will wrap your browser in a sandbox and this will in turn keep any malicious code running from a website or attachment from accessing your computer and infecting it.  This offers much better protection then an antivirus which attempts to "clean up" the virus after the infection has already occurred.

4) Follow the Elmer Fudd approach to opening attachments, Be w'ery w'ery careful, we're huntin' w'iruses!  Remember that ANY attachment, even those from known contacts, could contain viruses or malicious code.  If at all possible, open all attachments in a secure browser or in a sandboxed environment.

5) Do not browse to any suspicious websites.  If something looks strange or you think you are being taken to a website that isn't where you expected to go, don't hang around and click on things.  The best thing is to close the page and open a new page in a known/familiar location, like (http://www.google.com).

6) Do not trust free or open public WiFi.  Feel free to use it to check the latest sports scores or traffic status, but never ever access your financial information over a free or open public WiFi.  These networks are very easily hacked and are a huge source for theives to steal your ID, passwords, or financial information.  Be careful and just assume that on these types of networks someone is always reading or watching every single thing you do.

7) Last but not least, please also remember that Email is NOT secure.  Do not send anything of a sensitive nature via email, EVER!  Email is always sent in pain text mode, meaning that anyone who intercepts that message can view the contents of that message.  Nothing that is sent via email should ever be considered private.  Emails are constantly being intercepted and read, and not just by the NSA.  So if you don't want unknown people reading your private stuff, then don't send it in an email.

So there are 7 simple things that you can do to be a little safer and more secure online, starting today.
Enjoy!