topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Experts ponder securing the wireless world

April 12, 2001, 10:32 AM —  PC World — 

As security experts watch the airwaves get crowded with wireless transmissions
of voice and data, they see their field becoming more vital--and complicated,
in this world of mixed network protocols.

Unlike the Internet, which uses only a handful of standard protocols, the wireless
world is built on many disparate protocols that don't necessarily work together
at all. This lack of standards complicates the security of wireless networks,
which discourages their wider adoption.

Effective security requires widely accepted standards, agree security gurus
and vendors at the RSA Conference here this week. Discussion at the gathering
has tackled proposed new protocols, algorithms, and networks for both the wired
and wireless worlds.



While still in their infancy, wireless broadband and other forms of wireless
networking, including home LANs, show great promise as an alternative to wired
services used by businesses and home users. But unless the security of those
networks can be assured, the young industry could be stillborn, the security
experts warn.

To protect you, these networks will have to incorporate new security protocols
and algorithms as well as some existing methods found on the wired Internet.
But agreeing on which standards to adopt may be as big a challenge as getting
the high-speed services out the door.

New toys raise risks

"Modern expectations of the Internet include [service that's] always on,
handy, and immediate as well as secure," says Shawn Abbot, president of
IVEA Technologies, a developer of security infrastructure products for e-commerce.
"But the challenge of these connected personal devices is that they put
more personal data into cyberspace, raising the threat to privacy."

The most dire risks include forms of identity theft. Someone might learn and
misuse your personal information through eavesdropping or information tapping,
Abbot says.

Also, marketers are eager for the opportunities offered by global positioning
functions, which could let them target ads or services based on your location.
But "location-based services only magnify these threats, increasing the
need for trust from consumers," Abbot adds.

Current networks won't do

Today's mobile phone and paging networks--used for wireless devices--weren't
really designed to meet the security needs of transactions, corporate communications,
and network-based personal profiles, the experts agree.

The traditional mobile phone network has limited security, says Yiquin Lisa
Yin, research leader at NTT DoCoMo's Multimedia Communications Labs. "The
proprietary protocols and algorithms only provide security for the air interface
and not the whole network," Yin says.

The air interface in traditional cell phone networks includes the traffic between
the handset and the cellular base station, Yin says. Then, the base station
connects to a core network for the carrier, often with little security between
them, she adds.

On the reverse end, Internet

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources