Wireless Spec No Security Elixir
Source: E-Week
A new WLAN security specification is gaining momentum in the marketplace, with several vendors set to announce new products that use the technology. However, experts warn that the specification, 802.1x, has unresolved problems and should not be considered a panacea for the security ills plaguing wireless LANs.
802.1x is meant to serve as a framework on which enterprises can layer authentication methods such as smart cards or certificate-based systems. But security experts say it has limitations.
Researchers at the University of Maryland earlier this year found two security problems in the 802.1x standard that enabled them to hijack user sessions and execute man-in-the-middle attacks. The IEEE working group responsible for the standard is in the process of fixing the problems now.