<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Who didn&#8217;t know this?</title>
	<atom:link href="http://randomgemini.com/2008/04/who-didnt-know-this/feed/" rel="self" type="application/rss+xml" />
	<link>http://randomgemini.com/2008/04/who-didnt-know-this/</link>
	<description>One geeky girl set loose upon the world.</description>
	<lastBuildDate>Thu, 09 Feb 2012 19:54:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Random Gemini</title>
		<link>http://randomgemini.com/2008/04/who-didnt-know-this/comment-page-1/#comment-3368</link>
		<dc:creator>Random Gemini</dc:creator>
		<pubDate>Fri, 18 Apr 2008 22:09:04 +0000</pubDate>
		<guid isPermaLink="false">http://jolieve.polestar.org/blog/?p=819#comment-3368</guid>
		<description>I&#039;ve thought about slapping Ubuntu on my laptop after my HP warranty is up... but then there is that temptation of OSX. The guys down at the local mac store offered to throw OSX on here for me but it was a bit pricey, so I&#039;m not sure that&#039;s the route I want to go. Hearing that there&#039;s a live cd option for ubuntu warms my heart though. If I do decide to go that way, then I could play around with it before my warranty is up and not have HP gripe at me about voiding the warranty with its use. That would be sweet.

Thanks for the article link, I&#039;m not sure if I want to attempt setting this up on my own, but you&#039;ve given me great fodder for dinner table conversation with hubby tonight!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve thought about slapping Ubuntu on my laptop after my HP warranty is up&#8230; but then there is that temptation of OSX. The guys down at the local mac store offered to throw OSX on here for me but it was a bit pricey, so I&#8217;m not sure that&#8217;s the route I want to go. Hearing that there&#8217;s a live cd option for ubuntu warms my heart though. If I do decide to go that way, then I could play around with it before my warranty is up and not have HP gripe at me about voiding the warranty with its use. That would be sweet.</p>
<p>Thanks for the article link, I&#8217;m not sure if I want to attempt setting this up on my own, but you&#8217;ve given me great fodder for dinner table conversation with hubby tonight!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tsykoduk</title>
		<link>http://randomgemini.com/2008/04/who-didnt-know-this/comment-page-1/#comment-3367</link>
		<dc:creator>tsykoduk</dc:creator>
		<pubDate>Fri, 18 Apr 2008 20:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://jolieve.polestar.org/blog/?p=819#comment-3367</guid>
		<description>uh.. yeah. Here is the &lt;a href=&quot;http://swik.net/Firefox+ssh&quot; rel=&quot;nofollow&quot;&gt;article&lt;/a&gt;. :)</description>
		<content:encoded><![CDATA[<p>uh.. yeah. Here is the <a href="http://swik.net/Firefox+ssh" rel="nofollow">article</a>. <img src='http://randomgemini.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tsykoduk</title>
		<link>http://randomgemini.com/2008/04/who-didnt-know-this/comment-page-1/#comment-3366</link>
		<dc:creator>tsykoduk</dc:creator>
		<pubDate>Fri, 18 Apr 2008 20:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://jolieve.polestar.org/blog/?p=819#comment-3366</guid>
		<description>lol... 

Windows will do that to you if you are not careful :)

Here is a quick article on using SSH to build a &#039;poor mans&#039; vpn back to a home server... windows? I dunno if it will work. Windows SSH is... problematic at best. Works like a charm with *nix and macs.


Have you checked out the latest Ubuntu Linux? It pretty much rocked my socks off. I think that if it&#039;s not at grandma level, it&#039;s darn close. It even has a live-cd so you can try it with out totally destroying Winders.</description>
		<content:encoded><![CDATA[<p>lol&#8230; </p>
<p>Windows will do that to you if you are not careful <img src='http://randomgemini.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Here is a quick article on using SSH to build a &#8216;poor mans&#8217; vpn back to a home server&#8230; windows? I dunno if it will work. Windows SSH is&#8230; problematic at best. Works like a charm with *nix and macs.</p>
<p>Have you checked out the latest Ubuntu Linux? It pretty much rocked my socks off. I think that if it&#8217;s not at grandma level, it&#8217;s darn close. It even has a live-cd so you can try it with out totally destroying Winders.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Random Gemini</title>
		<link>http://randomgemini.com/2008/04/who-didnt-know-this/comment-page-1/#comment-3365</link>
		<dc:creator>Random Gemini</dc:creator>
		<pubDate>Fri, 18 Apr 2008 18:24:44 +0000</pubDate>
		<guid isPermaLink="false">http://jolieve.polestar.org/blog/?p=819#comment-3365</guid>
		<description>I really appreciate your comment, because the point of this post was to get people thinking about security on their home systems and the more information there is available for them to look at, the better off everyone is.

You&#039;re really a wealth of knowledge though! VPN is still a very new term to me, and as far as I knew (until about 10 minutes ago) VPN was just how people logged into their computers at work from home. *chuckle* I had to have my husband explain to me how it worked.

For me, it&#039;s like this, just over a decade ago, I helped my husband run all the home networking stuff and I was current on security and securing our servers from the outside world. Today, I&#039;ve become so attached to windows that it has crippled my memory of network security and caused all of my once really cool ability to geek with my husband to completely atrophy.

What I do remember though, is that there are always some very simple things that you can do that will make it that much harder for people to take advantage of you. This is true in life, and the internet. It doesn&#039;t make sense not to do them, even if some schmoe can easily work his way around mac filtering, there will be some other schmoe that can&#039;t figure out why your network doesn&#039;t work for him anymore. And while you may be right, that those people who are trying to get on your network without knowing how to get around mac filtering likely have good intentions, the road to hell is still paved with them.

It just makes sense to do what you can, even if it&#039;s simple and not necessarily the most effective means. Besides, Joe Neighbor could always come over and ask if you had a wireless network, and if you&#039;d mind sharing some bandwidth. I know I&#039;d be glad to let Joe Neighbor share some bandwidth if he hit a bad patch. 

Still, I love your suggestions and am now going to spend the remainder of the day reading about how VPN works, so I can get a more refined understanding beyond &quot;Well, it encrypts everything over your wireless, plus everything goes through one point so that it can be firewalled/proxied/filtered.&quot;</description>
		<content:encoded><![CDATA[<p>I really appreciate your comment, because the point of this post was to get people thinking about security on their home systems and the more information there is available for them to look at, the better off everyone is.</p>
<p>You&#8217;re really a wealth of knowledge though! VPN is still a very new term to me, and as far as I knew (until about 10 minutes ago) VPN was just how people logged into their computers at work from home. *chuckle* I had to have my husband explain to me how it worked.</p>
<p>For me, it&#8217;s like this, just over a decade ago, I helped my husband run all the home networking stuff and I was current on security and securing our servers from the outside world. Today, I&#8217;ve become so attached to windows that it has crippled my memory of network security and caused all of my once really cool ability to geek with my husband to completely atrophy.</p>
<p>What I do remember though, is that there are always some very simple things that you can do that will make it that much harder for people to take advantage of you. This is true in life, and the internet. It doesn&#8217;t make sense not to do them, even if some schmoe can easily work his way around mac filtering, there will be some other schmoe that can&#8217;t figure out why your network doesn&#8217;t work for him anymore. And while you may be right, that those people who are trying to get on your network without knowing how to get around mac filtering likely have good intentions, the road to hell is still paved with them.</p>
<p>It just makes sense to do what you can, even if it&#8217;s simple and not necessarily the most effective means. Besides, Joe Neighbor could always come over and ask if you had a wireless network, and if you&#8217;d mind sharing some bandwidth. I know I&#8217;d be glad to let Joe Neighbor share some bandwidth if he hit a bad patch. </p>
<p>Still, I love your suggestions and am now going to spend the remainder of the day reading about how VPN works, so I can get a more refined understanding beyond &#8220;Well, it encrypts everything over your wireless, plus everything goes through one point so that it can be firewalled/proxied/filtered.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tsykoduk</title>
		<link>http://randomgemini.com/2008/04/who-didnt-know-this/comment-page-1/#comment-3363</link>
		<dc:creator>tsykoduk</dc:creator>
		<pubDate>Fri, 18 Apr 2008 00:30:35 +0000</pubDate>
		<guid isPermaLink="false">http://jolieve.polestar.org/blog/?p=819#comment-3363</guid>
		<description>On the gripping hand, leaving your wireless network can been seen as neighborly. What if joe down the street looses his internet for a day? If you are open, you just made his week.

&lt;a href=&quot;http://www.schneier.com/blog/archives/2008/01/my_open_wireles_1.html&quot; rel=&quot;nofollow&quot;&gt;Bruce&lt;/a&gt; has this to say:

&lt;blockquote&gt;Whenever I talk or write about my own security setup, the one thing that surprises people -- and attracts the most criticism -- is the fact that I run an open wireless network at home. There&#039;s no password. There&#039;s no encryption. Anyone with wireless capability who can see my network can use it to access the internet.
To me, it&#039;s basic politeness. Providing internet access to guests is kind of like providing heat and electricity, or a hot cup of tea. But to some observers, it&#039;s both wrong and dangerous.
I&#039;m told that uninvited strangers may sit in their cars in front of my house, and use my network to send spam, eavesdrop on my passwords, and upload and download everything from pirated movies to child pornography. As a result, I risk all sorts of bad things happening to me, from seeing my IP address blacklisted to having the police crash through my door.
While this is technically true, I don&#039;t think it&#039;s much of a risk. I can count five open wireless networks in coffee shops within a mile of my house, and any potential spammer is far more likely to sit in a warm room with a cup of coffee and a scone than in a cold car outside my house. And yes, if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence&lt;/blockquote&gt;

Of course, he also goes on to talk about the risks of not using point to point encryption of some sort (esp. over wireless, and esp. over other people&#039;s wireless). If you have that part of it down, then it&#039;s no more unsafe then connecting from anywhere else.

Here is my take on it.

1) Have your wired network behind a firewall.

2) Have your wireless network open

3) With the correct sniffer, it is trivial to find and masquerade as a valid MAC address. So, MAC filtering is a good idea, but it&#039;s not a panacea for proper WPA pass-phrases and good tight VPN&#039;s.

4) Make sure that your wireless devices always use a secure VPN to connect to resources. In fact, it&#039;s a good idea to redirect _all_ of your traffic thru a VPN into your secure network and then back out. After all, how much of your email uses POP? Yeah... POP passes passwords in plain text.

So, (in an related topic) at the airport a few weeks ago, I saw a open wireless called &#039;Free Wireless&#039;. I tightened down the firewall, opened the log file, and connected. Wham. If I had been a windows box, I would have been rooted right then.

That was in SF. I also saw it at SeaTac. Not the same one, but the same idea. I also noticed that when I was connected to the AT&amp;T network at SeaTac, I was under constant assault.

So - VPN back home, and then traffic out to the internet from there with HUGE firewalls on the roaming device seem like a great idea to me.


;)</description>
		<content:encoded><![CDATA[<p>On the gripping hand, leaving your wireless network can been seen as neighborly. What if joe down the street looses his internet for a day? If you are open, you just made his week.</p>
<p><a href="http://www.schneier.com/blog/archives/2008/01/my_open_wireles_1.html" rel="nofollow">Bruce</a> has this to say:</p>
<blockquote><p>Whenever I talk or write about my own security setup, the one thing that surprises people &#8212; and attracts the most criticism &#8212; is the fact that I run an open wireless network at home. There&#8217;s no password. There&#8217;s no encryption. Anyone with wireless capability who can see my network can use it to access the internet.<br />
To me, it&#8217;s basic politeness. Providing internet access to guests is kind of like providing heat and electricity, or a hot cup of tea. But to some observers, it&#8217;s both wrong and dangerous.<br />
I&#8217;m told that uninvited strangers may sit in their cars in front of my house, and use my network to send spam, eavesdrop on my passwords, and upload and download everything from pirated movies to child pornography. As a result, I risk all sorts of bad things happening to me, from seeing my IP address blacklisted to having the police crash through my door.<br />
While this is technically true, I don&#8217;t think it&#8217;s much of a risk. I can count five open wireless networks in coffee shops within a mile of my house, and any potential spammer is far more likely to sit in a warm room with a cup of coffee and a scone than in a cold car outside my house. And yes, if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence</p></blockquote>
<p>Of course, he also goes on to talk about the risks of not using point to point encryption of some sort (esp. over wireless, and esp. over other people&#8217;s wireless). If you have that part of it down, then it&#8217;s no more unsafe then connecting from anywhere else.</p>
<p>Here is my take on it.</p>
<p>1) Have your wired network behind a firewall.</p>
<p>2) Have your wireless network open</p>
<p>3) With the correct sniffer, it is trivial to find and masquerade as a valid MAC address. So, MAC filtering is a good idea, but it&#8217;s not a panacea for proper WPA pass-phrases and good tight VPN&#8217;s.</p>
<p>4) Make sure that your wireless devices always use a secure VPN to connect to resources. In fact, it&#8217;s a good idea to redirect _all_ of your traffic thru a VPN into your secure network and then back out. After all, how much of your email uses POP? Yeah&#8230; POP passes passwords in plain text.</p>
<p>So, (in an related topic) at the airport a few weeks ago, I saw a open wireless called &#8216;Free Wireless&#8217;. I tightened down the firewall, opened the log file, and connected. Wham. If I had been a windows box, I would have been rooted right then.</p>
<p>That was in SF. I also saw it at SeaTac. Not the same one, but the same idea. I also noticed that when I was connected to the AT&amp;T network at SeaTac, I was under constant assault.</p>
<p>So &#8211; VPN back home, and then traffic out to the internet from there with HUGE firewalls on the roaming device seem like a great idea to me.</p>
<p> <img src='http://randomgemini.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

