Most homes and businesses do everything they can to keep unauthorised users off their networks, but Wi-Fi access points and routers can give attackers a convenient way in.
That is because Wi-Fi signals are often transmitted beyond the walls of buildings and houses and out into the streets — an attractive invitation for attackers. It is no surprise that wardriving is a favourite pastime among cybercriminals.
Since many companies allow or even actively encourage employees to connect to the network using their own mobile devices, tablets and smartphones as well as laptops, disconnecting Wi-Fi access is not practical for most businesses.
The same applies to home broadband users who may have guests over often.
Here are some tips for making Wi-Fi secure:
1. Use stronger encryption
Some Wi-Fi access points still offer the older WEP (Wired Equivalent Privacy) protection standard, but it is fundamentally broken. That means attackers can get into a WEP-protected network using a cracking suite such as Aircrack-ng in a matter of minutes.
So to keep intruders out it is essential to use some variant of WPA (Wi-Fi Protected Access) protection, whether WPA or the newer WPA2 standard — or WPA3 later on.
For smaller businesses and homes it can be practical to use WPA with a pre-shared key. That means every employee or family member uses the same password to connect, and the security of the network depends on them not sharing that password with outsiders.
It also means the password has to be changed every time an employee leaves the company.
Some Wi-Fi routers offer a feature called Wi-Fi Protected Setup (WPS) that provides an easy way to connect devices to a WPA-protected wireless network. However, attackers can exploit it to recover your WPA password, so it is important to disable WPS in the router's settings.
In larger organisations it makes more sense to use WPA in enterprise mode, which lets each user have their own username and password for connecting to the Wi-Fi network.
That makes it far easier to manage when employees leave regularly, since you can simply disable former employees' accounts. But to use WPA in enterprise mode you have to run a server — known as a RADIUS server — that stores the login information for every employee.
2. Use a strong WPA password
Make sure any password or passphrase protecting your Wi-Fi network is long and random so a determined attacker cannot crack it.
It is very easy to set any equipment up with its default configuration, especially because the default administrator name and password are often printed on the router to allow fast access and set-up. That means attackers will try them to get into your network. Changing both the login name and the password will make it harder for a criminal to get in.
You can test the security of your WPA-protected network — without revealing your password or passphrase — using the CloudCracker service. You will be asked to provide some data, the same data an attacker could capture or 'sniff' out of the air with a laptop from anywhere within range of your network, and the service will try to extract your password.
If the service does not succeed, an attacker is unlikely to either. But if the service finds your password, then you know you need to choose a longer, more secure one.
Bear in mind that even the WPA2 security standard is unlikely to hold out against a well-organised and persistent attacker or group of attackers, thanks to the KRACK Wi-Fi flaw discovered in October 2017.
3. Provide a separate network for guests
If you want to let visitors use your Wi-Fi, it is worth offering a guest network. It means they can connect to the internet without having access to your company's or family's internal network. That matters both for security reasons and to stop them accidentally infecting your network with viruses or other malware.
One way to do it is with a separate internet connection with its own wireless access point. In practice that is rarely necessary, since most business-grade wireless routers — and many newer consumer ones — can run two Wi-Fi networks at once: your main network and another for guests, often with the SSID 'Guest'.
It makes sense to turn WPA protection on for your guest network rather than leaving it open, for two important reasons. The first is to provide a degree of control over who uses it: you can give the password to guests who ask for it, and as long as you change it frequently you can stop the number of people who know it growing too large.
More importantly, this protects your guests from other people on the guest network who might try to eavesdrop on their traffic. That is because although they use the same WPA password to get onto the network, each user's data is encrypted with a different 'session key', which keeps it safe from other guests.
4. Hide your network name
Wi-Fi access points are generally set by default to broadcast the name of your wireless network, known as the service set identifier or SSID, to make it easier to find and connect to. But the SSID can also be set to 'hidden', so you have to know the network's name before you can connect.
Since employees have to know the name of their company's Wi-Fi network — and the same goes for family members and friends at home — there is no point broadcasting it so that anyone else walking past can find it easily too.
It is important to bear in mind that hiding your SSID should never be the only measure you take to protect your Wi-Fi network, because attackers using Wi-Fi scanning tools such as airodump-ng can still detect your network and its SSID even when it is set to hidden.
But security is about providing multiple layers of protection, and by hiding your SSID you can avoid attracting the attention of opportunistic attackers — so it is a simple measure worth taking.
5. Use a firewall
Hardware firewalls provide the first line of defence against attacks coming from outside the network, and most routers have built-in firewalls that check data coming in and going out and block any suspicious activity. The devices generally ship with reasonable defaults that do a decent job.
Most firewalls use packet filtering, which examines a packet's header to determine its source and destination addresses. That information is compared against a set of predefined and/or user-created rules governing whether the packet is legitimate, and therefore whether it should be allowed through or dropped.
Software firewalls generally run on the endpoint desktop or laptop, with the advantage of giving a better picture of the network traffic passing through the device. Beyond which ports are being used and where the data is going, you will know which applications are being used and can allow or block that program's ability to send and receive data.
7. Enable MAC authentication for your users
You can restrict who gets onto your wireless network further by allowing certain devices to connect and blocking the rest. Every wireless device has a unique serial number known as a MAC address, and MAC authentication only allows network access from a set of addresses defined by the administrator.
This stops unauthorised devices reaching network resources and acts as an extra obstacle for attackers wanting to get into your network.



