Five Myths About Secure WLAN Networks
Over the years, many recommendations have been made on the internet on how to design wireless networks (WLANs) securely. Some must be strictly followed, others have become obsolete due to new standards, and some have persisted as stubborn myths:
- Hiding the SSID makes the WLAN invisible.
- MAC address filters make networks secure.
- Restricting IP addresses prevents unauthorized connections.
- Small wireless networks cannot be attacked.
- WPA2 with an easy-to-remember password is sufficient.
Read the details regarding these claims and what is true or not below. Subsequently, we will show you how to configure your WLAN securely .
Hiding the SSID makes the WLAN invisible.
Every wireless network has an assigned name, the so-called SSID. This is transmitted by default, so that users can receive the wireless LAN with their smartphone or computer and quickly associate it by name. If the SSID is hidden in the WLAN router settings, it seems as if the wireless network has been disguised because it no longer appears among the received wireless networks.
A WLAN that can no longer be received, but is still usable for registered users? In reality, the wireless network is still present; only the SSID is no longer transmitted. If at all, this would only be useful from a security perspective to hide one's own WLAN from unsophisticated script kiddies. Experienced hackers can determine the SSID via a simple deauthentication attack using the right tools.
The security of a wireless network is therefore not effectively improved by hiding the SSID. Rather, WLAN clients are subsequently forced to send so-called probe requests, which are used to determine whether the hidden wireless network is within range. These are used by hackers in attacks such as KARMA or Evil Twin to connect the WLAN client to a malicious access point.
Let us advise you
on how to establish effective protection in private and corporate environments.
MAC address filters make networks secure.
Almost every WLAN router allows MAC filtering. This makes it possible to restrict network access to specific devices. For this purpose, the corresponding MAC address is entered into a whitelist, which grants access to all devices with a MAC address from this list.
At first glance, this may look like effective access control. In fact, devices not included in the whitelist cannot use the network. However, a MAC address can be forged in a simple way. So-called MAC spoofing is possible with almost any network card. In this process, the MAC address of a device connected to the target network is eavesdropped upon and subsequently used by the attacker's device.
Equipping one's own wireless network with a MAC filter does not per se make it secure. The network is only sufficiently protected through the choice of an encryption method like WPA2 and secure passwords . MAC address filtering can then further strengthen the bulwark around the network, albeit at the cost of higher administrative effort.
Restricting IP addresses prevents unauthorized connections.
To communicate over a network, devices are assigned IP addresses. This happens either manually or automatically via a DHCP server.
One might assume that access by unauthorized devices could be prevented if
- the IP address range is restricted and all addresses from it are assigned, or
- the DHCP server is turned off and no IP addresses are distributed automatically.
Since IP addresses can also be assigned manually and arbitrarily, both approaches are ineffective from a security perspective. In the first case, an IP address conflict would occur; however, this does not prevent the unauthorized connection. In the second case, an attacker manually assigns themselves an unused IP address and can thus communicate problemlos within the network.
Small wireless networks cannot be attacked.
Many are familiar with the problem of poor WLAN reception in buildings where a lot of reinforced concrete has been used, or at large distances between WLAN access points and clients. If the wireless network cannot be received, it also cannot be used. Should it not then be possible to reduce the transmission power as much as possible, so that an attacker, for example from the street, cannot receive it and therefore cannot attack it?
The assumption of making one's own wireless network secure in this way resembles the assumption of making the wireless network invisible by hiding the SSID . In reality, an attacker who wants to receive signals even with low strength uses a directional antenna. This is neither expensive nor reserved for certain groups of people; such a Yagi antenna can even be built from a Pringles can. Even if the transmission power of one's wireless network is minimized, it can still be attacked. Reducing the transmission power most likely leads to a reduction in range, which will cause authorized users to experience connection problems more frequently.
WPA2 with an easy-to-remember password is sufficient.
We recommend using a secure encryption method to protect a wireless network. The method used must not have known vulnerabilities and must be suitable for the respective purpose. One might be of the opinion that a "secure" encryption method like WPA2 with an easy-to-remember password would provide sufficient protection. But it primarily depends on the strength of the password used by a secure encryption method.
If you are among the people who can easily remember ?nR.,vg-5+7W-pwP_,cH, the claim that an easy-to-remember password is sufficient for WPA2 is correct. For everyone else, we recommend storing secure passwords
in a corresponding password management program. WLAN traffic can be intercepted and stored for an offline attack. Since the encryption method is usually known, poor passwords can be cracked within a few hours or even minutes.
Conclusion
Not all myths about secure WLAN networks are far-fetched: those willing to build further hurdles into the network configuration at the cost of higher administrative effort can make life a bit harder for attackers (and probably themselves). However, wireless networks do not become secure because of this, and we strongly advise against using simple passwords for WLAN encryption . Follow the seven recommendations for a secure WLAN and contact us with any questions for a non-binding conversation.
On 20.04.2016 in the category Network Security published.

