Sorry to bring up an old thread, but this has to be answered.
Quote:
Originally Posted by Da Nag
That's so overly broad as to be incorrect.
Your neighbor may or may not care. Your neighbor's ISP may or may not have restrictions on such things (mine doesn't), but even if they do, the TOS applies to your neighbor - not you.
|
http://www.cbsnews.com/stories/2005/07/07/tech/main707361.shtml
Quote:
Originally Posted by Da Nag
Not really useful. First, it's effective for basic/default scans by a user's OS only. It's trivial to find an SSID that is not being broadcast, with any number of free tools - no "hacking" necessary.
|
While that may be the case, the same principle can be said about leaving the front door to your home was open and someone let themselves in. It's still not right.
Quote:
Originally Posted by Da Nag
The main reason it's of no use - as you rightly advised, WPA2 should be enabled on the access point, for those that want/need such security. If so, who cares if your SSID is being broadcast? Anyone with sufficient skills to crack WPA2, would easily find your SSID even if broadcasting were turned off.
|
Belt and suspenders. Hiding the SSID will only slow down a hacker because he will have to do more work. Obviously however if someone was truly hell bent on getting something you have it would be only a matter of time.
Quote:
Originally Posted by Da Nag
Anything remotely related to financial/banking is unaffected, as the connections are encrypted over SSL. You can not decipher captured traffic being transmitted over SSL, nor can you perform man in the middle attacks over such connections. And, it's trivial to protect email as well - virtually every ISP/email package allows encrypted connections, as do the major web based providers. GMail for example, can be configured to always use SSL.
|
Not necessarily. Most people do not check to ensure that there is an active SSL connection. In fact in most browsers all you have is a little lock box and the "https". If somebody was malicious enough, all it would take is to force the "www.gmail.com" to point directly to
http://www.gmail.com and hijack it from there. Set up a web server and force all current users to a hacked DNS server to point to your special web page.
Quote:
Originally Posted by Da Nag
For other sites, such as this one - sure, all bets are off. Unless one is dopey enough to use the same credentials for financial/email services as they do at sites such as this, there's limited exposure.
That's simply paranoid. As mentioned above, most anything important is completely safe from prying eyes.
|
You missed my point about setting up a web server and pointing unknowing users to a fake web page that looks like the identical one. It's not difficult and entirely easy to set up as I have done before in demos for information security classes.
Your suggestions are dangerous and could potentially leave users with identity theft problems.