Is WEP sufficient?
My boss thinks that 40 bit WEP running on our wireless LAN access points is sufficient. I disagree. Will you help resolve this dispute?

    Requires Free Membership to View

    SearchMobileComputing.com members gain immediate and unlimited access to expert guides for mobile deployment, management and security, industry trends, and more-- all at no cost. Join me on SearchMobileComputing.com today!

    Kate Gerwig, Editorial Director

    By submitting your registration information to SearchMobileComputing.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchMobileComputing.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Actually, you're both right. You boss is correct in that the flaw in the wired equivalent privacy (WEP) encryption algorithm is independent of the encryption key length (40 bit vs. 128 bit). Therefore, 40 bit encryption works just as well as 128 bit encryption with WEP enabled. This will be resolved in the upcoming WPA/TKIP standards. You are correct in that WEP isn't the only security mechanism that needs to be in place. There are dozens of physical access, AP hardening, and client security issues that need to be addressed to properly deploy a secure wireless LAN. Stay tuned to my future postings where I hope to address these.

This was first published in May 2003