1
00:00:06,511 --> 00:00:08,640
- Now in this lesson, 14.2

2
00:00:08,640 --> 00:00:12,000
we're going to really focus
in on wireless configuration.

3
00:00:12,000 --> 00:00:14,610
And then in the next lesson, 14.3,

4
00:00:14,610 --> 00:00:17,160
we're gonna continue the
discussion about wireless.

5
00:00:18,720 --> 00:00:20,640
Now, we talk about wireless configuration

6
00:00:20,640 --> 00:00:22,170
or wireless networking,

7
00:00:22,170 --> 00:00:24,150
what we're talking about
is the connectivity

8
00:00:24,150 --> 00:00:26,940
through radio frequency transmissions.

9
00:00:26,940 --> 00:00:30,480
Now, wireless configuration
modes include an ad hoc mode

10
00:00:30,480 --> 00:00:32,700
which is a wireless
peer-to-peer relationship

11
00:00:32,700 --> 00:00:35,640
and infrastructure mode
topology, what we often refer to

12
00:00:35,640 --> 00:00:37,890
as our wireless network, which includes

13
00:00:37,890 --> 00:00:41,853
wireless devices access
points, and wired routers.

14
00:00:43,020 --> 00:00:43,853
So let's go through

15
00:00:43,853 --> 00:00:47,010
some different wireless
network configurations.

16
00:00:47,010 --> 00:00:50,640
We've got a WPAN that's a
wireless personal area network.

17
00:00:50,640 --> 00:00:52,560
You and I know it as Bluetooth, right?

18
00:00:52,560 --> 00:00:56,520
We use it to connect devices
in close range like our mice

19
00:00:56,520 --> 00:00:59,940
and our keyboard, or maybe
our earbuds or speakers.

20
00:00:59,940 --> 00:01:03,814
It uses the 802.15 IEEE standard.

21
00:01:03,814 --> 00:01:07,290
Then we have a WLAN that's a
wireless local area network

22
00:01:07,290 --> 00:01:09,930
which uses an 802 IEEE standard.

23
00:01:09,930 --> 00:01:10,770
And we're gonna be talking more

24
00:01:10,770 --> 00:01:12,620
about that standard in just a moment.

25
00:01:14,121 --> 00:01:15,630
Then we have a WMAN,

26
00:01:15,630 --> 00:01:17,689
which is a wireless
metropolitan area network

27
00:01:17,689 --> 00:01:21,150
which uses the 802.16 IEEE standard.

28
00:01:21,150 --> 00:01:24,000
And lastly, we have MBWA,

29
00:01:24,000 --> 00:01:26,970
which is a mobile
broadband wireless access

30
00:01:26,970 --> 00:01:31,320
which uses the 802.20 IEEE standard.

31
00:01:31,320 --> 00:01:34,173
But we're gonna really
be focusing in on a WLAN.

32
00:01:35,190 --> 00:01:39,060
So let's look at this
802.11 IEEE standards.

33
00:01:39,060 --> 00:01:39,960
First, let me tell you,

34
00:01:39,960 --> 00:01:42,600
you don't have to memorize this table.

35
00:01:42,600 --> 00:01:45,300
But what I want you to
know is the difference

36
00:01:45,300 --> 00:01:47,760
between the first one, two, three, four,

37
00:01:47,760 --> 00:01:49,920
five specifications there

38
00:01:49,920 --> 00:01:53,130
is data rate, frequency, and distance.

39
00:01:53,130 --> 00:01:54,870
So looking at 802.11,

40
00:01:54,870 --> 00:01:57,150
which was the original 802.11 standards

41
00:01:57,150 --> 00:01:58,780
or specification, our data rate

42
00:01:58,780 --> 00:02:01,410
for transfer was two megabits per second,

43
00:02:01,410 --> 00:02:04,440
our frequency was on the
2.4 gigahertz channel

44
00:02:04,440 --> 00:02:07,500
and our distance only
went a hundred meters.

45
00:02:07,500 --> 00:02:09,300
But go all the way down to n, right?

46
00:02:09,300 --> 00:02:12,900
And now we're at a data rate
of 150 megabits per second.

47
00:02:12,900 --> 00:02:15,180
We can go on two different
channels, so dual band,

48
00:02:15,180 --> 00:02:19,500
2.4 or five gigahertz, and
we can go up to 250 meters.

49
00:02:19,500 --> 00:02:21,120
Now that doesn't mean you necessarily have

50
00:02:21,120 --> 00:02:22,710
to put in you know, n.

51
00:02:22,710 --> 00:02:24,840
Maybe g is appropriate for you.

52
00:02:24,840 --> 00:02:25,950
So you're gonna make decisions

53
00:02:25,950 --> 00:02:29,550
based on configuration
and probably on cost.

54
00:02:29,550 --> 00:02:33,077
So just know that in those
basic specifications, right?

55
00:02:33,077 --> 00:02:36,180
The difference is data rate,
frequency and distance.

56
00:02:36,180 --> 00:02:41,180
Now, 802.11i is all about
security for 802.11 technologies.

57
00:02:41,610 --> 00:02:42,990
And for our purposes,

58
00:02:42,990 --> 00:02:44,490
we're gonna divide them into two buckets.

59
00:02:44,490 --> 00:02:47,460
A legacy bucket where web and WPA live,

60
00:02:47,460 --> 00:02:51,450
and a current bucket
where WPA2 and WPA3 live.

61
00:02:51,450 --> 00:02:55,530
And then 802.11 E
specification is all about QoS.

62
00:02:55,530 --> 00:02:56,820
It's quality of service

63
00:02:56,820 --> 00:02:59,403
for priority and for time sensitive data.

64
00:03:01,200 --> 00:03:04,770
So let's talk about
802.11i legacy security.

65
00:03:04,770 --> 00:03:07,770
That's where we find WEP,
wireless equivalent privacy

66
00:03:07,770 --> 00:03:10,770
and WPA, Wi-Fi protected access.

67
00:03:10,770 --> 00:03:13,890
So starting with WEP, WEP
used a pre-shared key.

68
00:03:13,890 --> 00:03:15,510
So everybody used the same key

69
00:03:15,510 --> 00:03:17,070
and all services used the same key

70
00:03:17,070 --> 00:03:19,860
or more than likely it was just wide open.

71
00:03:19,860 --> 00:03:23,460
The key was a shared 64 or 128-bit key.

72
00:03:23,460 --> 00:03:27,270
It used an RC4 stream cipher,
and it has been broken

73
00:03:27,270 --> 00:03:30,210
so it is without a doubt insecure.

74
00:03:30,210 --> 00:03:31,590
So there was a temporary fix

75
00:03:31,590 --> 00:03:33,693
by the Wi-Fi Alliance
that came out with WPA,

76
00:03:33,693 --> 00:03:36,660
which is Wi-Fi protected access.

77
00:03:36,660 --> 00:03:39,360
Really changed how we do
authentication, right?

78
00:03:39,360 --> 00:03:42,390
Authentication now could
instead of just a wide open

79
00:03:42,390 --> 00:03:44,610
or a pre-shared key that
everybody was using.

80
00:03:44,610 --> 00:03:47,280
We could use an enterprise
RADIUS for authentication.

81
00:03:47,280 --> 00:03:50,310
We could use a certificate
for authentication

82
00:03:50,310 --> 00:03:54,180
or we could use a personal
pre-shared key, a PPSK.

83
00:03:54,180 --> 00:03:56,910
We had separate 256-bit keys

84
00:03:56,910 --> 00:03:59,490
still using an RC4 stream cipher

85
00:03:59,490 --> 00:04:01,740
but it really was just a temporary fix.

86
00:04:01,740 --> 00:04:06,240
And fairly quickly it
was superseded by WPA2.

87
00:04:06,240 --> 00:04:08,337
But oddly, when you go to
configure a wireless network

88
00:04:08,337 --> 00:04:09,780
and you do a dropdown,

89
00:04:09,780 --> 00:04:14,103
you're still sometimes gonna
see WEP and WPA in the list.

90
00:04:16,110 --> 00:04:18,390
So I just mentioned that with WPA,

91
00:04:18,390 --> 00:04:20,040
we had the introduction
of a RADIUS server.

92
00:04:20,040 --> 00:04:21,240
So let's pause for a moment

93
00:04:21,240 --> 00:04:23,400
and talk about what a RADIUS server is.

94
00:04:23,400 --> 00:04:24,690
A RADIUS server which stands

95
00:04:24,690 --> 00:04:27,810
for remote authentication
dial-in user service

96
00:04:27,810 --> 00:04:30,584
provides centralized authentication,

97
00:04:30,584 --> 00:04:33,600
authorization, and accounting services.

98
00:04:33,600 --> 00:04:36,090
So it's often referred to as AAA

99
00:04:36,090 --> 00:04:39,660
for remote access and for network clients.

100
00:04:39,660 --> 00:04:43,260
Now, RADIUS servers act as
an authentication device.

101
00:04:43,260 --> 00:04:45,150
Once the user is authenticated,

102
00:04:45,150 --> 00:04:47,790
the RADIUS server can
determine access privileges

103
00:04:47,790 --> 00:04:49,710
that would be the authorization.

104
00:04:49,710 --> 00:04:53,010
And the RADIUS server can
keep track of network usage

105
00:04:53,010 --> 00:04:56,520
and can generate records
related to the user session.

106
00:04:56,520 --> 00:04:58,653
And that's referred to as accounting.

107
00:05:00,720 --> 00:05:03,390
Now, the other option that
was introduced was a PPSK.

108
00:05:03,390 --> 00:05:05,490
That's a personal pre-shared key.

109
00:05:05,490 --> 00:05:08,040
A personal pre-shared key
is a security mechanism

110
00:05:08,040 --> 00:05:10,890
that we use in our wireless
networks to authenticate

111
00:05:10,890 --> 00:05:13,380
and authorize client devices.

112
00:05:13,380 --> 00:05:16,980
Now, the PPSK is a unique
passade or key shared

113
00:05:16,980 --> 00:05:20,160
between the wireless access
point or the Wi-Fi router

114
00:05:20,160 --> 00:05:23,040
and the client device
that wants to connect.

115
00:05:23,040 --> 00:05:26,910
Now, although PPSK is shared
among multiple devices,

116
00:05:26,910 --> 00:05:29,820
each device is actually
uniquely identified

117
00:05:29,820 --> 00:05:31,293
by its MAC address.

118
00:05:33,150 --> 00:05:36,870
Now let's fast forward to
current 802.11i security.

119
00:05:36,870 --> 00:05:39,480
We've got WPA2 and WPA3,

120
00:05:39,480 --> 00:05:41,730
which are both considered
current versions.

121
00:05:41,730 --> 00:05:44,180
For authentication, WPA2 will use

122
00:05:44,180 --> 00:05:46,890
in enterprise RADIUS, we
just talked about that.

123
00:05:46,890 --> 00:05:49,830
Could use a certificate or
a personal pre-shared key.

124
00:05:49,830 --> 00:05:51,360
We just talked about that.

125
00:05:51,360 --> 00:05:54,090
It does use separate 128-bit keys.

126
00:05:54,090 --> 00:05:55,800
And now the encryption has moved

127
00:05:55,800 --> 00:05:58,320
from a stream cipher to a block cipher.

128
00:05:58,320 --> 00:06:01,110
And from RC4 to AES,

129
00:06:01,110 --> 00:06:02,910
which is a current US government standard

130
00:06:02,910 --> 00:06:04,323
for symmetric encryption.

131
00:06:05,220 --> 00:06:08,190
It is our current standard,
it is considered secure.

132
00:06:08,190 --> 00:06:10,230
There is a known vulnerability however.

133
00:06:10,230 --> 00:06:11,730
If you're using in conjunction

134
00:06:11,730 --> 00:06:14,130
with Wi-Fi protected setup or WPS,

135
00:06:14,130 --> 00:06:16,020
that's where you can connect.

136
00:06:16,020 --> 00:06:18,600
If you're just in close
proximity to the router,

137
00:06:18,600 --> 00:06:20,880
you can just click a
button and you'll connect.

138
00:06:20,880 --> 00:06:21,720
There is a flaw there

139
00:06:21,720 --> 00:06:26,520
that potentially would allow
the WPA key to be captured.

140
00:06:26,520 --> 00:06:29,490
Now, WPA3, which came
out a couple years ago

141
00:06:29,490 --> 00:06:31,770
but has optional certification now

142
00:06:31,770 --> 00:06:33,150
and is backward compatible

143
00:06:33,150 --> 00:06:37,260
with WPA2 really changed up the game.

144
00:06:37,260 --> 00:06:40,050
We moved from this
enterprise RADIUS certificate

145
00:06:40,050 --> 00:06:43,860
or personal pre-shared key
to what's known as enterprise

146
00:06:43,860 --> 00:06:47,990
or personal simultaneous
authentication of equals or SAE.

147
00:06:47,990 --> 00:06:49,890
So a totally different way of doing this.

148
00:06:49,890 --> 00:06:51,030
Sometimes, that's referred to

149
00:06:51,030 --> 00:06:53,223
as the dragonfly authentication.

150
00:06:54,150 --> 00:06:57,690
We have separate 256-bit or 384-bit keys.

151
00:06:57,690 --> 00:07:00,001
So 384 in enterprise, 256 in personal,

152
00:07:00,001 --> 00:07:03,750
still using an AES block cipher.

153
00:07:03,750 --> 00:07:07,830
The type of block we're
using is a GCMP-256 mode.

154
00:07:07,830 --> 00:07:09,930
So really enhancing the security there.

155
00:07:09,930 --> 00:07:12,030
And we're using an HMAC,

156
00:07:12,030 --> 00:07:14,403
remember we put a symmetric key in

157
00:07:14,403 --> 00:07:15,750
with the information that's going through

158
00:07:15,750 --> 00:07:19,023
the hashing process using SHA384.

159
00:07:20,190 --> 00:07:22,470
So really, really locked
down, really secure.

160
00:07:22,470 --> 00:07:24,600
Again, optional certification right now,

161
00:07:24,600 --> 00:07:27,573
it is backward compatible with WPA2.

162
00:07:29,460 --> 00:07:30,990
So let's dive in a little deeper

163
00:07:30,990 --> 00:07:31,823
about what do we mean

164
00:07:31,823 --> 00:07:34,710
about the simultaneous
authentication of equals.

165
00:07:34,710 --> 00:07:37,620
Simultaneous authentication
of equals or SAE,

166
00:07:37,620 --> 00:07:41,430
again, also known as dragonfly
authentication and encryption

167
00:07:41,430 --> 00:07:44,550
is a secure password-based authentication

168
00:07:44,550 --> 00:07:47,913
and password authenticated
key agreement method.

169
00:07:49,500 --> 00:07:51,090
Sounds pretty complicated.

170
00:07:51,090 --> 00:07:55,710
So WPA3 uses SAE to replace WPA2's

171
00:07:55,710 --> 00:07:58,740
personal pre-shared key exchange protocol.

172
00:07:58,740 --> 00:08:03,150
So SAE incorporates secure
mutual authentication

173
00:08:03,150 --> 00:08:06,540
and SAE employs perfect forward secrecy

174
00:08:06,540 --> 00:08:09,600
and is resistant to
offline decryption attacks.

175
00:08:09,600 --> 00:08:13,920
There's a lot of benefits
from moving to WPA3.

176
00:08:13,920 --> 00:08:16,650
In particular, perfect forward secrecy.

177
00:08:16,650 --> 00:08:19,170
So what's perfect forward secrecy?

178
00:08:19,170 --> 00:08:22,260
Perfect forward secrecy
is a protocol property

179
00:08:22,260 --> 00:08:25,050
that effectively protects past sessions

180
00:08:25,050 --> 00:08:27,510
against future compromises.

181
00:08:27,510 --> 00:08:30,060
A new session key is
generated for each session.

182
00:08:30,060 --> 00:08:33,813
And even if an attacker gains
access to the private key,

183
00:08:34,710 --> 00:08:37,770
the past communication
sessions can't be decrypted

184
00:08:37,770 --> 00:08:39,600
since those sessions were encrypted

185
00:08:39,600 --> 00:08:41,880
using different session keys.

186
00:08:41,880 --> 00:08:43,320
That transport layer security

187
00:08:43,320 --> 00:08:47,160
and internet key exchange, or
IKE, which is part of IPSec

188
00:08:47,160 --> 00:08:50,070
can be configured to
provide forward secrecy

189
00:08:50,070 --> 00:08:51,780
by generating ephemeral

190
00:08:51,780 --> 00:08:55,473
or unique session keys for each session.

191
00:08:56,460 --> 00:08:58,680
So that's our overview
of wireless security.

192
00:08:58,680 --> 00:09:01,380
And in the next lesson, we're
gonna dive a little bit deeper

193
00:09:01,380 --> 00:09:03,720
into wireless configurations.

194
00:09:03,720 --> 00:09:06,570
But before we do that, let's
do a three-second challenge.

195
00:09:07,770 --> 00:09:08,790
Challenge one.

196
00:09:08,790 --> 00:09:11,880
Common name for the 802.15 standard.

197
00:09:11,880 --> 00:09:13,380
You know this one.

198
00:09:13,380 --> 00:09:14,520
Starts the letter B.

199
00:09:14,520 --> 00:09:16,290
One, two, three.

200
00:09:16,290 --> 00:09:18,035
That's gonna be Bluetooth.

201
00:09:18,035 --> 00:09:19,560
Number two.

202
00:09:19,560 --> 00:09:22,473
Primary and time sensitive
data configuration.

203
00:09:23,490 --> 00:09:27,690
There's an 802.11 specification
specifically for this.

204
00:09:27,690 --> 00:09:29,760
One, two, three.

205
00:09:29,760 --> 00:09:32,493
And that's gonna be QoS
or quality of service.

206
00:09:33,870 --> 00:09:34,950
Number three.

207
00:09:34,950 --> 00:09:38,493
The authentication method used in WPA3.

208
00:09:39,390 --> 00:09:41,253
One, two, three.

209
00:09:42,630 --> 00:09:44,790
That's gonna be
simultaneous authentication

210
00:09:44,790 --> 00:09:48,363
of equals or SAE, also known as dragonfly.

211
00:09:49,380 --> 00:09:52,950
Number four, device that
can provide authentication

212
00:09:52,950 --> 00:09:55,923
authorization, and accounting services.

213
00:09:56,850 --> 00:09:58,830
AAA, notice I'll start with A.

214
00:09:58,830 --> 00:10:02,580
Authentication, authorization
and accounting services.

215
00:10:02,580 --> 00:10:04,800
Give me a device that can do all of those.

216
00:10:04,800 --> 00:10:07,316
One, two, three.

217
00:10:07,316 --> 00:10:08,666
And that's gonna be RADIUS.

218
00:10:09,600 --> 00:10:11,190
And lastly, number five.

219
00:10:11,190 --> 00:10:13,380
This protocol property can be configured

220
00:10:13,380 --> 00:10:16,743
to protect past sessions
against future compromises.

221
00:10:17,700 --> 00:10:20,190
One, two, three.

222
00:10:20,190 --> 00:10:23,790
That's gonna be PFS or
perfect forward secrecy.

223
00:10:23,790 --> 00:10:24,623
All right, let's go

224
00:10:24,623 --> 00:10:27,843
and do a security and action
about wireless connectivity.

225
00:10:28,920 --> 00:10:31,140
Your neighborhood coffee
shop offers free Wi-Fi

226
00:10:31,140 --> 00:10:32,550
to their customers.

227
00:10:32,550 --> 00:10:34,860
You did a bit investigating and determined

228
00:10:34,860 --> 00:10:38,323
that their current
configuration is WPS 802.11n

229
00:10:39,558 --> 00:10:42,390
with web authentication.

230
00:10:42,390 --> 00:10:45,360
Hmm. Should you connect?

231
00:10:45,360 --> 00:10:49,320
And if not, what feedback
might you give the owners?

232
00:10:49,320 --> 00:10:51,720
So just a quick recap here, right?

233
00:10:51,720 --> 00:10:53,580
You're at your neighborhood
coffee shop, right?

234
00:10:53,580 --> 00:10:55,110
So just a small little coffee shop.

235
00:10:55,110 --> 00:10:56,430
And you know, the owners

236
00:10:56,430 --> 00:10:58,110
and the managers are
really much more concerned

237
00:10:58,110 --> 00:11:01,500
with making your espresso
than security probably.

238
00:11:01,500 --> 00:11:05,610
So it's WPS, it's 802.11n,

239
00:11:05,610 --> 00:11:08,640
and it's using we for authentication.

240
00:11:08,640 --> 00:11:10,290
Are you gonna connect to the network?

241
00:11:10,290 --> 00:11:11,370
And if you're not going to,

242
00:11:11,370 --> 00:11:13,380
what feedback do you
wanna give the owners?

243
00:11:13,380 --> 00:11:15,300
Go ahead and put me on pause,
write down your feedback,

244
00:11:15,300 --> 00:11:16,400
and then come on back.

245
00:11:19,320 --> 00:11:22,537
You should not connect to
a web wireless network.

246
00:11:22,537 --> 00:11:24,030
Period.

247
00:11:24,030 --> 00:11:26,790
Web has been broken, it's not secure

248
00:11:26,790 --> 00:11:29,613
and it would put you and
every other customer at risk.

249
00:11:30,990 --> 00:11:34,770
The customer wireless network
should be configured for WPA2

250
00:11:34,770 --> 00:11:38,193
or WPA3 with backward
compatibility enabled.

251
00:11:39,120 --> 00:11:41,670
WPS should be disabled.

252
00:11:41,670 --> 00:11:43,560
There shouldn't be any
reason why anyone's getting

253
00:11:43,560 --> 00:11:47,460
next to the router and having
to click a button and connect.

254
00:11:47,460 --> 00:11:50,790
And we know that WPS,
you know, potentially

255
00:11:50,790 --> 00:11:55,260
introduces a flaw where the
WPA2 key could be captured

256
00:11:55,260 --> 00:11:56,760
and that could be problematic.

257
00:11:58,170 --> 00:12:00,180
They should also be
aware that their signal

258
00:12:00,180 --> 00:12:05,010
because they're using n, can
broadcast up to 250 meters.

259
00:12:05,010 --> 00:12:07,860
Now, they may have a big
space and they may want that

260
00:12:07,860 --> 00:12:08,693
or they might say,

261
00:12:08,693 --> 00:12:10,320
"No, we don't need to be broadcasting that

262
00:12:10,320 --> 00:12:14,220
out on the sidewalk and over
into our neighbor's property."

263
00:12:14,220 --> 00:12:16,170
So having this conversation
with them, again,

264
00:12:16,170 --> 00:12:17,762
this isn't at work.

265
00:12:17,762 --> 00:12:18,960
This is just your neighborhood coffee shop

266
00:12:18,960 --> 00:12:21,690
but helping out others, helping
other people to understand

267
00:12:21,690 --> 00:12:25,775
and really working to help
secure our community in general.

268
00:12:25,775 --> 00:12:28,860
Definitely, that's security-in-action.

269
00:12:28,860 --> 00:12:30,060
There's your word cloud.

270
00:12:30,060 --> 00:12:31,350
You know what to do.

271
00:12:31,350 --> 00:12:33,743
When you're ready, I'll
see you the next lesson.
