I just got a WRT54GS (v2) and have been playing around with TinyPEAP
(Radius). It is a little flakey, but does work. Pretty cool. Don't think
I can find a home for it on my WLAN (802.11a), but it is just something else
to play around with. The WRT54GS cost next to nothing anyway. Nice to have
another tool in the kit, should it be needed, anyway.
Happy with my WLAN as it is anyway. Seperate, using all the wifi security
measures to fullest, and even doing VPN.
However, I like to keep one (internet only) AP completetely unsecured, by
intention. I'm doing just this on a seperate network and using a captive
portal (ZoneCD). I keep it open for my neighbors to use while they are
outside on the back porches, along with anyone else that wants to. Not only
could I care less, but I'm even inviting anyone that wants to use it by
suffixing the SSID's with "_OPEN". My philosophy of wireless is that one
of the greatest potentials is to provide free and open access.
Unfortunetly, the world is full of stupid people, so you do have to take
some cautionary measures, and that is why I have ZoneCD in the loop.
I wish manufacturers would adopt this type of thinking for home users. Many
users would keep an internet-only pipe open, but are so worried about the
girlfrield-less, Friday-night, wardrivers that they stop short of sleeping
on their porch with a shotgun and dog. What is needed for them is
simplicity to allow both their WLANs to be secured, while keeping an
internet SSID open (but still filtered). I.e., everything ZoneCD provides,
plus filtering against all the immature BS like strobing, repetative
pinging, repative emailing, filtering against large blocks of known porn
sites, ect. (I block as much porn as I can. Thats one thing I'm not about
to keep open. Use my open AP all you want, but use your own damn internet
for porn.)
I don't buy into the wardrivers' speal about how they are only out doing
"research" and trying to save the world from itself. If that was the case,
then why is it that the few times I got visited, they didn't simply mark the
location and drive on? (Hell, I am even labeled "_OPEN"!) Do they simple
just connect and pull up a browser to see if it works? Nope. Every time,
the first thing they do is start strobing and seeing what they can screw
with. (They never get anywhere, but get logged nicely.) If they are so
damn beneign, then why is it if you do a deja search for "wardriving" one of
the main things you find are posts asking how to spoof MAC's. Give me a
break, no-lives! Get a damn girlfrield and I bet you care less about
people's little $100 plastic boxes.
Thought about baiting 'em, by say having a captive portal redirect to
http://www.goatse.cx/ (*DON'T LOOK! ITS VERY NASTY!*) and automatically
upload strings of virii, but that would be no better than them (and also
potentially cause harm to neighbors).
Cheers,
Eric