[00:04.790 --> 00:19.390] A couple months ago, I had a Verizon DSL, which was the suckiest thing to ever suck, and it was down again, and so I was infuriating because I had to get some stuff to some clients. [00:19.690 --> 00:25.270] So I just got my laptop and walked across the street and sat on the sidewalk in front of my neighbor's house. [00:26.610 --> 00:31.150] And I was doing that, and he walks out, and he says, with this lip on his face, he's like, what are you doing? [00:31.150 --> 00:32.490] I said, I'm on your network, dude. [00:32.570 --> 00:33.790] I need a little connectivity here. [00:33.870 --> 00:34.990] You know, you've got to help a brother out. [00:35.230 --> 00:42.790] And he was really freaked out, had no idea that somebody could just come up and get on his system. [00:44.130 --> 00:52.770] Wi-Fi and wireless is an increasingly interesting issue, especially people leave their networks open. [00:53.310 --> 00:56.470] The name of this panel is Wireless Wi-Fi, the Good, the Bad, and the Ugly. [00:56.470 --> 01:02.290] We have Dragorn, IrishMASMS, Mike Lynn, Porkchop. [01:02.870 --> 01:10.210] You might remember from such films as Freedom of Downtime, and some wet t-shirt hacker thing. [01:12.410 --> 01:13.810] What about the last one? [01:14.690 --> 01:15.330] You guys ready? [01:17.010 --> 01:17.970] Take it away. [01:20.270 --> 01:21.410] My name is Dragorn. [01:21.730 --> 01:22.690] I wrote Kismet. [01:22.830 --> 01:25.290] I'm helping with the wireless network here at Oak 5. [01:26.230 --> 01:28.050] And hopefully it will be interesting today. [01:28.270 --> 01:30.350] We've got a brief itinerator. [01:30.550 --> 01:33.750] We're going to basically do a roundtable discussion of various wireless topics. [01:33.990 --> 01:38.470] And then we'll open it up for a lot of audience questions, since they seem to be quite a good work. [01:38.910 --> 01:42.630] And you may even have something to give away at the end, so we'll see how it is. [01:43.350 --> 01:45.590] I'll let everyone introduce themselves, and then we'll get going. [01:53.610 --> 01:55.050] I'm Mike Lynn. [01:55.310 --> 01:59.070] I right now work at ISS X-Force, doing various kinds of research. [01:59.270 --> 02:06.490] I've done wireless stuff since shortly before the first premiums of having screens were ratified. [02:08.210 --> 02:11.530] And I've written wireless drivers for just about all the chipsets. [02:13.110 --> 02:16.710] I've written a couple of wireless devices, what schools have probably heard about. [02:16.930 --> 02:17.610] I adaptor. [02:17.610 --> 02:17.650] I adaptor. [02:18.330 --> 02:18.330] Uh, [02:23.110 --> 02:25.130] IrishMASMS, how are you all doing today? [02:26.030 --> 02:26.270] Great. [02:26.510 --> 02:26.770] Thank you. [02:26.850 --> 02:27.050] Woo! [02:27.870 --> 02:28.310] Mmm, [02:31.360 --> 02:32.840] so I'm sure you guys jet lagged today. [02:33.080 --> 02:33.380] All right. [02:34.960 --> 02:42.620] I'm IrishMASMS, I get to play with wireless as much as I can on my off time, other than what you haven't already read in my bio. [02:43.880 --> 02:48.340] And, uh, it's an honor to be at this table, uh, talking about wireless and Wi-Fi with these guys. [02:50.080 --> 03:04.500] I'm Porkchop, uh, I am, uh, what'd you read in the bio, and on top of that, I just play around with wireless and, uh, try to do wireless security work, so, so, try to keep everything straight, try to keep everything as safe as possible with maintain usability. [03:08.740 --> 03:17.160] We have a, uh, presentation, a little slideshow of sorts to, uh, guide our clock, and that's firing up really slowly. [03:17.980 --> 03:19.920] Just sort of come along with the dots. [03:20.880 --> 03:31.600] We'll, uh, might as well start now while it learns, uh, starting, uh, wireless is a lot older than everybody thinks it is, didn't come around in 99, and, uh, like Glenn has a few comments about it. [03:34.120 --> 03:36.080] Okay, he wants me to talk about AlohaNet. [03:36.220 --> 03:38.300] I don't really know enough about AlohaNet to really talk about it. [03:38.840 --> 03:44.540] Um, somebody just brought up earlier that, you know, when I was in 99, like, no, it predates Ethernet. [03:45.340 --> 03:46.920] And, so, I wanted me to talk about AlohaNet. [03:47.200 --> 03:51.720] Um, Ethernet, some of the, uh, occlusion avoidance stuff, uh, CD made things that Ethernet's based on. [03:52.000 --> 03:54.760] It's AlohaNet, University of Hawaii, a long time ago. [03:55.180 --> 03:56.560] So, before Ethernet was made. [03:56.820 --> 03:57.080] Whatever. [03:57.260 --> 03:59.800] That's what I wanted me to say. [04:01.180 --> 04:04.280] So, it's kind of come full circle with, uh, it started as... [04:04.280 --> 04:04.480] Yeah. [04:05.080 --> 04:07.660] ...wireless, now it then went to wired, now it's sort of back. [04:07.820 --> 04:14.700] Yeah, so if you really want to call something wireless Ethernet, um, I, I promise I won't drive it in the NIFCOM pool like I've written somebody, uh, last year. [04:14.880 --> 04:17.720] But, uh, AlohaNet would be closer to wireless Ethernet than that. [04:21.220 --> 04:30.160] And just because it has, uh, Wi-Fi compatible logo on there, does not necessarily mean that any of us on the panel, or this presentation is Wi-Fi compatible? [04:31.000 --> 04:33.960] Some of us may be distinctly non-Wi-Fi compatible. [04:34.340 --> 04:35.660] Especially, especially regular. [04:37.420 --> 04:41.980] Some people do very funny things with, uh, with packets and, and, and... [04:43.160 --> 04:47.140] There are vulnerabilities that are not really widely known. [04:47.400 --> 04:49.200] I mean, it's sometimes published on the Internet. [04:49.460 --> 04:53.920] There are things you can do to, uh, mess with the firmware of cars, or things you can do to... [04:53.920 --> 05:00.100] Uh, basically protocol level, uh, attacks that you can do against, uh, different, um, clients. [05:00.400 --> 05:02.160] Uh, things that you wouldn't really... [05:02.160 --> 05:05.540] Just by using the protocol in a different way than it was expected. [05:05.680 --> 05:06.260] It was just... [05:06.260 --> 05:09.280] There are problems with it before it leaves the paper, is what I'm trying to say. [05:09.520 --> 05:11.220] It was very naively designed. [05:12.060 --> 05:12.460] And... [05:12.980 --> 05:14.220] Some people work to break it. [05:14.300 --> 05:15.400] Some people work to fix it. [05:15.780 --> 05:17.220] Like, something works to fix it. [05:17.720 --> 05:19.720] I would argue that we're all trying to fix it. [05:19.720 --> 05:23.400] Um, of course, you know, by fixing it, you first have to break it. [05:23.920 --> 05:25.560] So, one sort of requires the other. [05:26.140 --> 05:30.600] But usually, in terms of the, the design process, though, is that's when you want to try and do the most breaking of it. [05:30.740 --> 05:32.220] And this one, the other thing we did most of it. [05:32.780 --> 05:35.100] The, WEP was broken back in 1995. [05:35.500 --> 05:36.640] It was a paper published to say... [05:36.640 --> 05:40.780] This was before WEP was conceived, if you're trying to work about the timeline there. [05:41.020 --> 05:43.620] Um, so, paper published called My Weak RC4 Keys. [05:43.940 --> 05:55.860] It was trying to knock down a potential limitation of a future SSL, uh, that was going to be vulnerable to the exact same, uh, related key, uh, vulnerability, that, uh, WEP has in the key scheduling algorithm. [05:56.640 --> 05:59.260] Then 19, the four years later, 1999 comes around. [05:59.380 --> 06:00.960] Nobody bothered to read anything about that. [06:01.100 --> 06:03.880] They go and implement the exact same thing that paper discussed, never implementing. [06:04.380 --> 06:10.500] And, um, essentially, the attack you have is the exact same attack with a few modifications that were described in a paper called... [06:10.500 --> 06:11.320] Just Google for it. [06:11.500 --> 06:12.660] My Week RC4 Keys. [06:13.000 --> 06:17.500] And nobody at IEEE seemed to go and look into this when they came up with a great idea of the web. [06:17.660 --> 06:18.240] That's what I mean by... [06:18.240 --> 06:20.400] They didn't exactly look into it initially. [06:21.000 --> 06:26.720] And they didn't do the sort of trying to, to break it to see, um, how the things they were doing would have been a bad idea initially. [06:26.940 --> 06:29.200] So, that's why everybody's kind of scrambling to fix it in. [06:29.820 --> 06:30.800] Advents is kind of... [06:30.800 --> 06:38.720] So, even if you comment on, uh, on things that have been developed already, uh, in the, uh, pre-will, what do you call it this? [06:39.780 --> 06:41.980] Before you actually implement it, um... [06:41.980 --> 06:42.620] Design phase. [06:42.840 --> 06:43.760] Design phase, thank you. [06:43.760 --> 06:47.600] Even though you're commenting on the design phase, it doesn't actually mean that people are going to pay attention to you. [06:47.740 --> 06:51.060] And you still have to keep in mind everything that you've learned in the past. [06:52.200 --> 06:52.580] Yeah. [06:53.000 --> 07:00.640] Well, just, just the amount of information, just go out and Google, doing a Google search on wireless or Wi-Fi security will give you a plethora of information. [07:00.640 --> 07:10.420] But does that mean that the IT professionals out there that got stuck by the boss to say, here, I want Wi-Fi so I can check my email while I'm on the loo. [07:12.500 --> 07:13.340] No, they don't bother. [07:13.480 --> 07:14.720] They just throw it in there and run on. [07:14.900 --> 07:20.620] Well, that creates some vulnerabilities and some problems for your organization and for yourself as an IT professional. [07:21.100 --> 07:23.520] Well, it's, it's worse than that, though, because you... [07:24.000 --> 07:27.000] Everywhere the initial reaction to it was, no, not on my network. [07:27.080 --> 07:28.020] You can't have this on my network. [07:28.180 --> 07:30.320] And then, either, one of the few things happened. [07:30.520 --> 07:40.880] Either the user's overran because as much as we like to control the network, sometimes the only way we can maintain control at that level is we can either turn it off or we can sort of work with you to do what you're going to do anyways. [07:41.600 --> 07:49.780] Like, I-56 tunnels have sort of a similar problem with that and the wireless is a huge one because it's difficult in a lot of these places, especially with the interconnection sharing. [07:49.940 --> 07:54.500] So, either some VP, some hotshot VP gets in and you're not going to tell him that what he's going to say. [07:54.540 --> 07:56.420] You figure it out and it's going to be your problem. [07:56.640 --> 08:00.380] Or he's going to, basically, you're going to be overrun with all these unauthorized ones. [08:00.480 --> 08:06.680] It's going to be done either out of your control, completely out of your control, so, in other words, you say, we can't do this enough. [08:06.840 --> 08:08.940] Since you can't do it, you have no control over how it's done. [08:09.100 --> 08:09.860] It's going to be done anyways. [08:10.160 --> 08:14.320] So, they end up having to implement it just so they can have a controlled, allowable way. [08:14.520 --> 08:17.240] One of those two ways, but you can't stop it from going everywhere. [08:17.380 --> 08:19.460] People want it too much because it's too easy and we're all lazy. [08:21.800 --> 08:24.720] You also have a situation that I've found on a couple different occasions. [08:24.940 --> 08:36.120] If you go, we're driving down in the business centers of town, you'll find these certain access points that are wide open, and then you drive by later that evening or that night and the access point is gone. [08:36.280 --> 08:41.460] But, miraculously, you find it in some house out in the western part of town. [08:43.620 --> 08:46.620] And I'll lead you to have your own conclusions about that. [08:46.620 --> 08:49.780] Which brings up the next interesting point. [08:50.200 --> 08:55.940] How many people think their home network is secure or think they're interesting enough that they have to worry a great deal about their home network? [08:56.200 --> 08:57.080] Just raise your hands. [08:59.000 --> 08:59.860] One or two. [09:00.500 --> 09:01.220] What's your address? [09:03.740 --> 09:10.380] How many people are positive that their lawyer or their doctor doesn't have someone in their office plugged into a wireless access point? [09:12.600 --> 09:12.880] One. [09:13.420 --> 09:13.920] One guy. [09:14.560 --> 09:15.680] Someone's actually checked. [09:16.920 --> 09:18.920] There's another issue, too, at your home why it's an issue. [09:19.200 --> 09:20.180] Especially everyone here. [09:20.520 --> 09:22.700] Because you guys might be the worst time talking your way out of this one. [09:24.000 --> 09:31.040] The type of people you will most likely get on there, aside from the, you know, I'm 15, I'm upset at my father, I don't want to go break something type. [09:31.400 --> 09:39.540] Aside from that type, the only people you really have to worry about are people who, let's see, I have an anonymous, high-speed connection to the internet, and somebody else is going to take the fall when I get caught. [09:39.840 --> 09:44.160] And if you're in this room, you're probably going to have a harder time talking your way out of that rap than most people. [09:45.380 --> 09:48.560] So, because you're going to tell them, no, no, I don't know how to do any of this stuff. [09:48.620 --> 09:49.140] It wasn't me. [09:49.240 --> 09:50.400] And then they're going to look around your room. [09:50.520 --> 09:51.580] They're going to see your HOPE badge. [09:53.040 --> 09:55.380] They're going to talk to your friends and be like, no, this was you. [09:56.020 --> 09:56.840] And you're in trouble. [09:56.840 --> 10:02.960] So, even if you don't think any of the stuff on your network is all that important, or that anybody's really going to want. [10:03.160 --> 10:05.980] Just imagine, they don't necessarily want your things on your network. [10:06.140 --> 10:07.260] They just want your network access. [10:07.880 --> 10:09.760] So they can remain anonymous and do whatever they want. [10:10.240 --> 10:14.520] And that's a fairly common use for wireless networks as far as elicit use of them. [10:15.140 --> 10:19.560] I would never drive around town finding an open access point and start up Kazaa. [10:19.800 --> 10:20.980] I would never do that. [10:27.490 --> 10:28.350] Obviously not. [10:30.230 --> 10:30.750] Good. [10:34.250 --> 10:38.750] There are a couple of things you can do to prevent ward drivers from finding your stuff. [10:40.270 --> 10:42.110] To a certain degree. [10:42.110 --> 10:46.670] I'm going to argue that the best thing to do to prevent ward drivers from finding your file... [10:47.710 --> 10:49.330] Any members of the tinfoil half brigade here? [10:49.890 --> 10:50.330] Anyone? [10:51.390 --> 10:52.990] You basically have the right idea. [10:53.170 --> 10:54.270] Line your place with tinfoil. [10:54.330 --> 10:57.450] Or do something to prevent the signals from leaving your house in the first place. [10:57.510 --> 11:02.350] That's probably the best way to prevent ward drivers from finding you, of course. [11:03.070 --> 11:05.090] A lot of people try the SSID cloaking. [11:05.230 --> 11:06.770] A lot of people try the no beaconing. [11:07.930 --> 11:09.890] Well, they do no beaconing exactly. [11:10.370 --> 11:10.810] Sorry. [11:10.810 --> 11:12.410] You can't actually do no beaconing. [11:12.610 --> 11:13.750] Some access points you can. [11:14.250 --> 11:15.630] Well, the cards won't sort of get it. [11:15.850 --> 11:17.970] They'll detect a leg failure. [11:19.130 --> 11:21.390] Probably different from point to points, but it's still being decent. [11:22.190 --> 11:27.810] But if you decrease the beacon interval, though, it will make it a lot harder for people to get on the network out of long range. [11:27.930 --> 11:31.770] Because if they have packet loss at all, it's not going to have a good enough length as far as they're concerned they're strong. [11:32.610 --> 11:36.790] So decreasing the beacon interval will sometimes all those access points where you can't increase the signal is another way to do it. [11:37.630 --> 11:42.270] So for people who don't know anything about what we're saying right now, there's a feel on the thing. [11:42.370 --> 11:42.970] It's a beacon interval. [11:43.230 --> 11:43.850] Just make it small. [11:45.270 --> 11:52.190] Every access point out there a certain number of times a second says, hi, here I am, this is my name, connect to me. [11:52.730 --> 11:53.950] They're designed to do it. [11:54.130 --> 11:55.090] They're meant to be connected to. [11:56.450 --> 12:00.490] Some access points, some manufacturers decided to hide that name. [12:00.690 --> 12:02.270] So you can only connect to it if you know that name. [12:02.770 --> 12:03.650] It's a great idea. [12:03.870 --> 12:07.090] Except that the protocol never meant that to be a secret field. [12:07.350 --> 12:10.930] So as soon as you connect, the access point says, yes, I'm such and such. [12:11.090 --> 12:11.810] You're allowed in. [12:12.170 --> 12:12.910] There's your name. [12:12.910 --> 12:17.410] One thing that turning that off that will do, it's not actually going to stop an attacker. [12:17.690 --> 12:18.850] Because it's not a password. [12:19.110 --> 12:19.810] It's just a network name. [12:19.950 --> 12:21.410] It's no more password than an IP address is. [12:22.390 --> 12:27.290] But what it will do is it kind of puts a do not disturb sign up. [12:27.310 --> 12:30.190] If you see a closed network, it's not broadcasting the SSID and the beacons. [12:30.430 --> 12:34.010] It says, hey, please don't get on this network because it's not meant for you. [12:35.290 --> 12:37.270] So there are a lot of people who are war driving around. [12:37.370 --> 12:38.410] They just have to see what's out there. [12:38.630 --> 12:41.130] You know, if there's an open access point, it's still default settings. [12:41.250 --> 12:41.590] Who knows? [12:41.730 --> 12:43.350] I mean, at my house, I don't care if people get on. [12:43.630 --> 12:44.590] I'm perfectly happy. [12:44.930 --> 12:45.910] I log what you do. [12:46.030 --> 12:47.370] You're on a completely different network segment. [12:47.630 --> 12:48.350] I don't care. [12:49.250 --> 12:51.810] So at my house, I would have a problem with somebody getting on there. [12:51.870 --> 12:54.130] And if I did, I would not broadcast the SSID. [12:54.410 --> 12:56.390] So it's a gray area. [12:56.530 --> 13:02.010] If you want to tell people it's not appropriate for them to get on your network, I'd turn off the SSID, but it doesn't stop anybody. [13:03.470 --> 13:06.190] It's a measure of how important is it. [13:06.590 --> 13:16.970] For most people at home, web, turning off the SSID will probably keep anyone, unless you live next door to someone who really wants internet access without paying for it, will probably keep them out. [13:17.930 --> 13:20.570] There's too many access points for them to care and pick you out. [13:20.710 --> 13:23.910] Just don't be the low-hanging fruit if you're the home user. [13:24.730 --> 13:29.250] Generally speaking, the home user doesn't, you specifically don't have anything they want except for perhaps network access. [13:29.810 --> 13:30.830] Don't be the low-hanging fruit. [13:30.990 --> 13:34.230] Let your neighbor be the guy who links this on channel 6 with no web. [13:36.290 --> 13:38.250] Password and you be the guy that sets... [13:39.810 --> 13:44.370] Are you the low-hanging fruit or are you the rotting piece of fruit on the ground with the worms crawling through it? [13:45.030 --> 13:45.930] Start at that point. [13:46.350 --> 13:46.650] Yeah. [13:47.050 --> 13:52.210] But yeah, as these guys are talking about, there's some real simple basic steps to take to secure your network. [13:52.610 --> 13:56.210] You know, if you're in a house, put the access point in the basement. [13:56.810 --> 14:00.350] Because the dirt and concrete is pushing all the waves up. [14:00.510 --> 14:04.430] So unless you're war-driving in an airplane, you're going to have a hard time finding it. [14:04.430 --> 14:16.890] And as these guys also alluded to, it's really easy just to drive another block or, as in here, stick your antenna out the window and you find another three or four wide open access points on it and you don't have to worry about trying to crack your web keys. [14:17.090 --> 14:18.310] Not that we ever would. [14:18.310 --> 14:24.010] Another obscure suggestion, though, that's just sort of a funny thing we were doing for a while and it works. [14:24.650 --> 14:28.790] Turn off the broadcast of your SSID and then make the SSID ANY in all caps, A-N-Y. [14:29.050 --> 14:33.750] Because a lot of clients, if you say ANY in all caps, try and connect to the broadcast SSID, which is not you. [14:33.950 --> 14:35.370] You are actually A-N-Y. [14:35.990 --> 14:43.490] So that will actually prevent a lot of actual configuration utilities from being able to connect to you if you don't broadcast the SSID in the beacons. [14:45.270 --> 14:46.690] Interesting unintended application. [14:47.590 --> 14:50.970] Sort of a roundabout kind of workaround to stop that. [14:51.190 --> 14:53.650] But it might actually stop you from connecting, though. [14:53.730 --> 14:54.310] That's the problem. [14:54.450 --> 14:55.950] But if you have the right client, you can. [14:57.370 --> 15:06.650] Speaking of home construction and workplace or access point, I suggest 1940s work program housing construction for eating your signal. [15:07.090 --> 15:11.810] So if you live in one of them and you can't reach their next floor over, that's probably why. [15:12.430 --> 15:25.090] What they actually did was you put plywood up, and then you put chicken wire over the plywood, and then you plaster a cop with chicken wire, and the chicken wire pulls up and plaster, which puts in effect your entire house inside a Faraday cage. [15:30.630 --> 15:32.990] So how many here in the audience were a drive? [15:35.510 --> 15:36.310] I've got a bunch. [15:38.450 --> 15:39.910] How many people have told you it's a crime? [15:42.490 --> 15:42.850] Wow. [15:43.170 --> 15:44.350] I guess I'm pretty... [15:46.970 --> 15:54.070] When you get into theft of services or you're doing other things, just war driving around is not a crime. [15:54.770 --> 15:57.330] It's kind of a gray area, though, when you do get onto the network. [15:57.470 --> 15:59.730] Like I said, there are plenty of networks that are open and meant to be open. [15:59.850 --> 16:01.810] My access point in my house is meant to be open. [16:01.810 --> 16:03.830] I have one that isn't, I think, at my house. [16:04.010 --> 16:05.510] But there are plenty that are, because why bother? [16:07.470 --> 16:13.550] But I don't believe that anybody's going to really hold you accountable if you connect to license channel 6 in a web, you don't do anything for their network. [16:13.730 --> 16:15.710] And you don't really do anything from the network you shouldn't be doing. [16:15.810 --> 16:22.250] But at the same time, it is a crime, arguably, when you go that extra step further and you do things that would be a crime on any other network. [16:23.490 --> 16:25.230] Just because it's out there doesn't mean it's okay. [16:25.390 --> 16:27.350] They'll just stack all the violations up against you. [16:27.350 --> 16:31.430] And then they'll charge anything else they had on the solve for, like, the last 6 months or a year. [16:31.630 --> 16:35.790] Just looking around, it's fairly legal in the U.S. [16:36.090 --> 16:38.230] Of course, depending on which exact town you're in. [16:38.470 --> 16:39.470] Local audiences. [16:40.010 --> 16:40.850] Well, local audiences. [16:40.970 --> 16:42.390] And all your lawyers are moving at a local level. [16:42.710 --> 16:48.610] But also in Germany and a lot of other countries, it's also legal to go forward driving. [16:48.770 --> 16:52.050] And actually, Germany specifically does work. [16:52.510 --> 16:55.850] Their version of the Secret Service, I don't know if that's FBI. [16:55.850 --> 17:02.050] Okay, the version of the FBI, that's a more accurate version, actually does go forward driving themselves. [17:02.530 --> 17:05.450] They try to find doctors' offices, doctors' offices, et cetera, et cetera. [17:05.610 --> 17:10.010] People who have open access points and transmit personal data. [17:10.830 --> 17:12.310] Things like your medical records. [17:12.610 --> 17:23.650] My somewhat fuzzy understanding of the law that defines it in Germany is that a company that handles private data of citizens is required by law to provide a certain level of protection. [17:24.170 --> 17:29.950] And they're legally accountable if they leave an access point open on their network that allows someone to steal your personal data. [17:30.270 --> 17:31.410] In the U.S.? [17:32.430 --> 17:33.210] Well, yes. [17:33.330 --> 17:37.130] Now we have HIPAA, but that doesn't necessarily mean people follow it. [17:37.270 --> 17:39.310] And it's not enforced that well. [17:40.390 --> 17:42.130] Now, mind you, it might not be illegal. [17:42.910 --> 17:46.110] And they might still have their access points wide open broadcasting. [17:47.210 --> 18:01.630] But the people that own them, such as if you're war driving a local college and the head professor of information security just happens to drive up to get his paperwork from his office, and we're sitting here war driving outside his office, they might not like that. [18:03.830 --> 18:05.750] Not speaking from experience, mind you. [18:05.970 --> 18:08.430] Just a really hypothetical situation. [18:11.070 --> 18:15.910] And just that it's, again, just that it's not against federal regulation or state regulation. [18:15.990 --> 18:28.110] It could be against local regulation, or in this case, your college's regulations, in which point they'd be probably enough in the right legally to kick you out or do something. [18:28.710 --> 18:32.110] Still, as long as you keep it passive, it is an unlicensed band. [18:32.470 --> 18:36.510] I mean, essentially, there's kind of saying you can't listen to a microwave oven in the color green at that point. [18:37.590 --> 18:39.550] I mean, it's all just photons, you know. [18:39.650 --> 18:41.450] But it's an unlicensed spectrum of photons. [18:42.050 --> 18:46.850] And it's one you're generally allowed to listen to. [18:46.850 --> 18:52.250] So I wouldn't be too concerned, provided that you're not up to any other trouble on top of it. [18:52.390 --> 18:53.450] In which case, that was on or anything. [18:54.190 --> 18:54.650] So... [18:54.650 --> 18:55.690] With some restrictions. [18:56.470 --> 19:04.130] I've been told by some people that logging data was a tool like Kismet, as opposed to NetStumbler, which simply detects the network's presence. [19:04.770 --> 19:09.430] Logging other people's data without permission could be considered an unlicensed wiretap. [19:09.430 --> 19:16.670] And if they need to find another thing to pin on you once you've done something wrong and they caught you at it, that's a very good one for them to pin on you. [19:18.210 --> 19:21.610] Case in point, the guys in... was it North Carolina? [19:21.990 --> 19:22.910] With Lois Harbor? [19:24.710 --> 19:25.510] Who, uh... [19:25.510 --> 19:25.970] Michigan? [19:28.850 --> 19:30.270] Okay, someone's saying it was Michigan. [19:30.510 --> 19:31.050] I'll go with that. [19:32.170 --> 19:32.570] Um... [19:32.570 --> 19:33.770] They weren't border driving. [19:34.010 --> 19:40.070] They just found an open access point into the network and then used that to exploit servers inside and gather credit card data. [19:40.250 --> 19:42.130] Had nothing to do with wireless other than... [19:42.610 --> 19:45.390] It was like finding an open jack on the outside of the, uh, building. [19:46.350 --> 19:49.030] Well, another issue with that, though, is I'm... [19:49.030 --> 19:55.090] You know, I could be wrong with this, but my understanding is there's actually separate laws about possessing credit card numbers themselves to handle these things. [19:55.090 --> 19:59.290] So, recording that data itself is probably the biggest crime that they, uh... [19:59.290 --> 20:05.650] But not recording the data because it's wireless, simply recording it knowingly and storing it on their system than someone else's credit card. [20:07.290 --> 20:12.310] So, don't run outside one of those retail stores that you know has these things and just sit there looking at credit card numbers. [20:12.870 --> 20:13.910] You brought up a point a minute ago... [20:13.910 --> 20:14.930] It's not a good idea, it's a whole thing. [20:15.770 --> 20:23.750] You brought up a point a minute ago with, uh, some interesting implications that, um, the 2.4 GHz band that we're talking about here is unlicensed. [20:23.750 --> 20:26.450] You can do pretty much whatever you want with that band. [20:27.230 --> 20:28.510] Which means that, uh... [20:28.510 --> 20:30.190] The 5 GHz band is unlicensed, by the way. [20:30.490 --> 20:32.030] The 8.4 GHz band is not completely unlicensed. [20:32.130 --> 20:34.410] You actually have to adhere to certain things. [20:34.950 --> 20:38.930] That's shared, uh, I've heard from somewhere, it's shared with, uh, military radar. [20:39.090 --> 20:40.270] Military radar, one of the things. [20:40.350 --> 20:46.290] Which, I don't know, it seems like with the right equipment or with the right Wi-Fi equipment, just easily modified, I don't know. [20:47.150 --> 20:51.070] It just seems like it could create some havoc, kind of like microwave levels. [20:51.070 --> 20:53.830] There are reasons why your paddles drivers are not open to source. [20:55.570 --> 20:56.410] That's kind of scary. [20:56.550 --> 20:57.070] And they won't be. [20:58.050 --> 20:59.230] So the interesting point? [20:59.390 --> 21:05.910] The interesting point is, um, there's a lot of stuff that can interfere with your signals. [21:05.910 --> 21:10.330] Um, as you're wardriving through the area, um, you can... [21:10.890 --> 21:19.010] Or as a person is wardriving through an area, if your network is there, you can cause interference, if you really wanted to, um, [21:22.750 --> 21:25.290] towards a, uh, towards the street or something like that. [21:25.430 --> 21:28.770] And still be with, within good grounds in the FCC. [21:29.190 --> 21:32.990] Um, if you're using, uh, some, some cordless phones will do it. [21:37.990 --> 21:40.450] Um, there's actually a low level attack. [21:40.810 --> 21:51.630] At one point there was a company developing a variant of fluorescent lights, which microwaved a lump of tungsten, which then emitted a nice range around 2.4. [21:52.210 --> 21:55.930] Well, all of that interference is going to drop off with the inverse square long. [21:56.170 --> 22:11.290] And the problem with that is, as soon as the signal gets kind of far away, um, the, uh, it's not a problem, it's actually a feature, but if you were trying to exploit it, is that, uh, the, uh, spread spectrum and OFDM are, OFDM being what, uh, A12G uses and A12A uses, [22:11.510 --> 22:13.850] and spread, direct sequence spread spectrum may get 12B. [22:14.210 --> 22:17.330] Um, they're pretty resilient to it. [22:17.390 --> 22:23.530] Once the, once the signal gets pretty far away, you're going to cause probably some packet loss, but I wouldn't worry too terribly much, but it's not the real issue with all snacks. [22:24.910 --> 22:28.410] You also have other Wi-Fi, uh, hardware. [22:28.690 --> 22:37.390] Uh, for example, uh, we're driving through a town I live in, we found this particular access point all over town, the same SSID. [22:38.350 --> 22:53.590] Well, doing a little social engineering, finding out that the local, uh, government, due to the, uh, political layer of the OSI model, decided they wanted one access point, with one omnidirectional antenna, and boosted the signal like you would not believe. [22:55.750 --> 22:57.710] Of course, they're from a very flat area. [22:58.310 --> 22:58.450] Yeah. [22:59.070 --> 22:59.630] Yes and no. [23:00.230 --> 23:01.030] But yeah, pretty much. [23:09.970 --> 23:11.850] Um, got any questions so far? [23:12.170 --> 23:14.110] There's a microphone right there in front of us. [23:14.290 --> 23:14.990] Don't be shy. [23:15.710 --> 23:17.230] So come to the microphone if you have questions. [23:21.500 --> 23:22.720] What are you gonna do, Liz? [23:23.220 --> 23:23.360] Cool. [23:23.780 --> 23:27.220] So, uh, you guys are talking a lot about the attacker host model. [23:27.380 --> 23:30.020] So you have someone who's attacking, they have to go access point. [23:30.260 --> 23:36.080] But we haven't talked about the reverse model, where somebody sets up an access point, and lures the clients. [23:36.800 --> 23:38.480] So let's, uh, let's do that. [23:38.700 --> 23:39.480] Very good point. [23:40.100 --> 23:43.180] Um, we actually didn't get to that. [23:43.560 --> 23:47.800] Um, one of the major problems with 802.11, you connect to the network. [23:47.800 --> 23:50.460] The network says, okay, my name is Bob. [23:50.940 --> 23:52.940] And you keep treating that like it's Bob. [23:53.720 --> 23:54.500] It doesn't mean it's Bob. [23:55.440 --> 23:56.740] Uh, software's already been written. [23:56.880 --> 23:59.540] It was demoed in Black Hat last year, which is actually quite simplistic. [23:59.820 --> 24:02.200] Where it simply spoofed the network name. [24:03.000 --> 24:08.880] Uh, kicked all the clients off their own network, and brought up a webpage that looked like the T-Mobile network at Starbucks. [24:10.640 --> 24:13.720] How many people plugged your credit cards into Starbucks in the past week? [24:14.080 --> 24:14.820] Or month? [24:15.960 --> 24:16.700] Show my hands. [24:17.380 --> 24:17.740] Yeah. [24:18.840 --> 24:19.440] A couple. [24:19.700 --> 24:21.060] Not many coffee drinkers, I guess. [24:21.820 --> 24:24.740] No, because I can just drive another block and find an open access point. [24:24.860 --> 24:25.820] Why don't I want to pay for it? [24:27.240 --> 24:29.360] People who are more careful with their credit card numbers, perhaps. [24:29.780 --> 24:32.260] There are, uh, some solutions to this. [24:32.660 --> 24:34.520] Um, I'd love to do it. [24:34.520 --> 24:34.960] I have. [24:35.100 --> 24:36.080] I've worked for coming in from the past. [24:36.180 --> 24:37.320] Fortunately, I'm under NDAs with them. [24:37.460 --> 24:39.500] I can't really release very many wireless drivers at this point. [24:40.160 --> 24:45.220] But, um, they're, the easy solution to this can be solved in the drivers. [24:45.420 --> 24:52.480] And that is, right now, the cards themselves will not let you choose the network itself, the MAC address and various other authentication characteristics you want. [24:52.540 --> 24:53.020] They'll just connect. [24:53.140 --> 24:54.040] They'll just start sending traffic. [24:54.880 --> 25:00.700] Um, well, some cards will, some cards and drivers will let you choose the MAC address of the network you're going to associate with. [25:01.840 --> 25:05.320] But, just because the network says it's that MAC address doesn't mean it's the same network. [25:05.600 --> 25:05.720] Still. [25:06.400 --> 25:08.860] There's no strong cryptographic authentication yet. [25:09.840 --> 25:11.760] Most of these problems can be solved on drivers. [25:11.900 --> 25:17.600] Most of them in the middle issues can be solved by simply refusing to switch channels whenever somebody disconnects you off. [25:18.300 --> 25:20.520] And, they need to have hooks in the drivers. [25:20.760 --> 25:22.840] And I've talked to a bunch of people in Atheris and things like that. [25:22.840 --> 25:25.980] And they don't really get much response from them because, I guess, there's not as much demand. [25:26.260 --> 25:35.640] But, you need to have hooks in the drivers or modify something in the card's firmware to be a little more intelligent, a little more choosy about who it connects to you rather than just connecting on a whim to whoever. [25:36.220 --> 25:39.940] Uh, the problem with that is, a lot of these things, you can't even tell which network you're on. [25:40.300 --> 25:43.300] So, you know, MAC address, you know, authentication, anything like that. [25:43.380 --> 25:43.760] You don't even know. [25:43.860 --> 25:44.860] You connected to a totally different network. [25:44.940 --> 25:48.860] You didn't have the same authentication scheme that you had expected, like, your network is supposed to have. [25:49.300 --> 25:50.040] And, you're just on. [25:50.700 --> 25:53.440] That's something that can be fixed in drivers, in port, or in firmware. [25:53.760 --> 25:55.080] It's not very difficult to do. [25:55.260 --> 25:55.540] You just... [25:55.960 --> 26:00.180] The card gets an interrupt whenever it's configured, its current link status, or whatever changes. [26:00.280 --> 26:04.280] You just need to validate those values, make sure they're kosher, and then make sure your authentication is still current. [26:04.460 --> 26:05.220] And they don't do that. [26:05.700 --> 26:10.760] So, if they did that, then you would start to see some real security in some of the more advanced attacks on these things. [26:10.760 --> 26:12.460] Including an access point attack. [26:14.460 --> 26:19.800] My point of view is always towards usability, towards the drivers and everything staying out of your way. [26:19.960 --> 26:23.000] At what point do you think that it's important for the driver to stay out of your way? [26:24.680 --> 26:28.420] How bitchy do you want your drivers to be about what access points is connected to? [26:28.500 --> 26:29.080] Where is the cutoff? [26:29.080 --> 26:36.180] Well, I mean, having worked in the wireless industry, writing wireless drivers, I can tell you the cutoff is wherever the customer demands it to be. [26:36.900 --> 26:39.260] If I had my choice, I would make it very configurable. [26:39.420 --> 26:43.080] You can have a mode to where it's done and does whatever, and you should have a mode to where it is very particular. [26:43.900 --> 26:46.160] And it knows this is the right piece of hardware I'm talking to. [26:46.580 --> 26:53.280] You know, like when I plug my cable into a switch, I'm fairly sure nobody's man-in-the-middle attacking my physical switch. [26:53.380 --> 26:55.880] Like they didn't swap it out without it, it looks just like it in my house. [26:55.980 --> 26:58.800] And if they did, I'm kind of glad they didn't steal my computer while they're at it. [26:59.540 --> 27:01.480] But with wireless, it's a totally different deal. [27:01.600 --> 27:02.880] Who knows what they did there? [27:02.940 --> 27:04.260] They can essentially swap it out. [27:04.360 --> 27:04.960] You don't even know. [27:06.580 --> 27:09.060] The problem is they just need to have demand from the users. [27:09.160 --> 27:14.600] And that's just not something that's come from this, because what you'll get from a lot of the wireless industry is a whole lot of just... [27:15.100 --> 27:18.540] Blanket, nope, nope, well, there were some problems with the security, but Web fixes it. [27:18.640 --> 27:21.720] Oh, no, there were some problems with Web, but Leap fixes it. [27:21.880 --> 27:24.600] There were some problems with Leap, but... And it just goes on. [27:25.500 --> 27:32.660] And instead of actually fixing it, it's easier to throw far fewer resources at it because they don't perceive a real demand. [27:33.000 --> 27:36.040] You guys are the ones who can actually make them have this in there. [27:36.140 --> 27:38.920] And the cutoff, as you asked, is where the customer wants it. [27:39.040 --> 27:40.060] That's what they're going to do. [27:40.320 --> 27:41.600] And they just don't see that demand. [27:41.740 --> 27:44.020] They're really kind of driving them to not do it because it's more work for them. [27:44.180 --> 27:45.680] Not much, but it is more work. [27:46.860 --> 27:53.220] On a similar note about the customer driving the network security levels, check your doctor out. [27:53.220 --> 27:54.120] Check your lure out. [27:54.300 --> 27:55.520] Bring your laptop next time. [27:55.640 --> 27:56.880] Kill a little time in their office. [27:57.140 --> 27:59.080] See if you see your records flying by. [27:59.360 --> 28:00.420] Ask them about it. [28:01.060 --> 28:04.620] Just be careful, because no good deed goes unpunished. [28:04.680 --> 28:06.340] That's correct, in certain cases. [28:06.580 --> 28:10.740] So make sure you very carefully approach that. [28:10.820 --> 28:14.660] I think the next talk in this room is about no good deed goes unpunished, actually. [28:15.580 --> 28:21.720] I definitely not suggest knocking on a random law firm's door and saying, hey, all your customers are exposed. [28:23.640 --> 28:25.240] They probably wouldn't take it very well. [28:25.360 --> 28:27.800] If it's your lawyer, you might be able to get away with it. [28:28.000 --> 28:28.940] But be very careful. [28:29.160 --> 28:35.260] If it is a doctor's office or a hospital or something to that effect, I think that would throw them pretty squarely in violation of HIPAA. [28:35.460 --> 28:42.580] And I'm sure they have a HIPAA compliance officer who would be more than happy to, in a panicked rush, go and find whatever it is you were freaking out about and make sure it was okay. [28:43.280 --> 28:45.680] I don't know if he'll fix it, but he'll at least freak out for a little while. [28:47.440 --> 28:49.000] I would approach them... [28:49.000 --> 28:53.780] Generally speaking, you can get on a webpage or get through the operator there and just talk to the HIPAA compliance officer. [28:53.880 --> 28:54.420] That's difficult. [28:54.580 --> 28:55.680] I don't know how you really approach them. [28:55.760 --> 28:58.340] But I'd approach them saying, hey, we might have a HIPAA compliance issue. [29:01.540 --> 29:03.520] Although, again, no good deed goes unpunished. [29:03.520 --> 29:08.840] So, a lot of times, what you'll see in certain situations is, the knee-jerk reaction is people will just try and... [29:08.840 --> 29:09.860] You found the problem. [29:10.000 --> 29:11.320] Well, you're the one who made it. [29:11.700 --> 29:12.700] You are the problem. [29:13.020 --> 29:14.880] And that's not a really good security model. [29:15.080 --> 29:17.160] You need to move away from that and accept that we have problems. [29:17.400 --> 29:19.640] Just because something I found doesn't mean it was there. [29:20.020 --> 29:21.560] You know, you don't shoot the message. [29:21.780 --> 29:23.460] I'd worry for them shooting the message. [29:23.740 --> 29:24.520] So, be careful. [29:26.200 --> 29:28.440] And some of these examples aren't that hypothetical. [29:28.440 --> 29:38.280] I've encountered law firms that have their entire network open, completely unsecured power plants. [29:40.160 --> 29:44.900] And even when you told the lawyer that the access point is wide open, they still haven't fixed it. [29:45.360 --> 29:49.040] Actually, I took my own advice on that one and kept driving. [29:49.300 --> 29:51.840] My lawyer's access point was totally wide open. [29:52.660 --> 29:53.980] Did you get him to fix it? [29:54.720 --> 29:56.120] I forgot to plug it. [29:58.640 --> 30:01.140] As far as I was concerned, the problem was fixed at that point. [30:02.220 --> 30:04.500] I mean, you know, she could have, I'm sure... [30:04.500 --> 30:07.480] If she wanted to cut me a deal on the stuff she was doing, I'm sure she could have... [30:08.060 --> 30:12.680] She could have somehow paid me or done some trade or whatever for me to secure it. [30:12.880 --> 30:14.760] But the simple solution was I had to plug it in. [30:15.920 --> 30:19.280] Well, we have a bit of a queue, so let me take some more questions. [30:21.220 --> 30:21.780] Ask away. [30:22.280 --> 30:30.000] The first thing I wanted to mention, where there are tools out there for MITM and, of course, to determine the SSID for cloaked access points. [30:30.300 --> 30:31.320] They are available. [30:31.740 --> 30:31.820] Right. [30:32.260 --> 30:34.200] Kismet will do it automatically, passively. [30:34.740 --> 30:35.960] There are active tools as well. [30:36.500 --> 30:36.680] Also, right. [30:36.820 --> 30:42.320] If there's any client on a cloaked network, you can force that client off. [30:42.440 --> 30:46.000] The client will automatically reconnect and the network will automatically disclose what its name is. [30:46.000 --> 30:54.560] Also, should we capture an intelligent access point, detect MAC spoofing and or disconnections, and deauthenticate that SSID user? [30:56.420 --> 30:57.900] Could you angle the mic a little bit down? [30:58.080 --> 30:58.560] Sure. [30:58.960 --> 31:03.940] If you have an access point that there's a spoof point disconnection request, it doesn't come from the AP. [31:04.180 --> 31:07.520] The AP detects it and deauthenticates that MAC address. [31:08.200 --> 31:08.240] Right. [31:09.500 --> 31:11.000] That's where I think it should go. [31:11.520 --> 31:24.640] You can kick a user off the network by telling the network that you're the user and you're going away, or you can take a user off the network by telling the user that you're the network and the network has gone away. [31:25.740 --> 31:34.500] Certainly, there's no way to protect against that because the ETO TEA protocol has to be backwards compatible, like G is backwards compatible with B and A is using the same standard layer. [31:34.500 --> 31:36.020] It's not entirely correct. [31:36.360 --> 31:38.680] Certain cards do that in software. [31:39.280 --> 31:41.160] You can't fix that problem in software. [31:41.580 --> 31:43.120] We got an extra cable. [31:43.340 --> 31:44.360] It isn't. [31:44.440 --> 31:46.040] It's incorrect unless it's done. [31:46.300 --> 31:47.640] Certain cards can't. [31:48.100 --> 31:49.680] Certain cards are pretty much software right now. [31:50.000 --> 31:52.420] Are they technically compliant then? [31:52.940 --> 31:54.360] No, not even close. [31:55.040 --> 31:58.920] But I mean, very few FTP servers are fully RFC compliant for a reason. [31:59.520 --> 32:01.400] The RFC has problems. [32:01.680 --> 32:09.500] And I'd say that especially with the old legacy of the element B and G and A specs, anything prior to I, I still have this issue. [32:09.640 --> 32:17.780] But any of those, it's probably not a bad thing to be, to skip a little bit of compliance for security. [32:18.020 --> 32:21.580] That and very few of them are even approaching compliance AIs. [32:22.640 --> 32:26.860] Which brings us back to any drivers that allow us to define the level of security we want. [32:27.700 --> 32:30.340] But they're not going to do it until people actually sort of command it. [32:32.380 --> 32:37.900] Open source drivers are, of course, always going to run into those issues with the right group of people. [32:38.080 --> 32:40.340] I need to angle the mic down. [32:40.500 --> 32:43.080] Open source drivers are always going to have those issues. [32:43.240 --> 32:45.600] If somebody knows they'll manipulate their radio chips in. [32:46.240 --> 32:46.380] Right. [32:46.760 --> 32:48.600] Well, closed source drivers have the issues too. [32:48.880 --> 32:52.400] I mean, open source lets us be able to fix some of the problems. [32:53.900 --> 32:55.280] Wait, can you get there on sound? [32:55.840 --> 33:01.480] Having read lots of closed source drivers I assure you they have problems just like open source. [33:01.700 --> 33:02.080] It's code. [33:03.480 --> 33:08.440] They have in some cases more problems with fewer eyes are looking at it. [33:09.680 --> 33:14.140] But, what they do have is the closed source ones typically have access to the hardware space. [33:20.860 --> 33:23.800] I have two small war driving questions. [33:24.400 --> 33:31.420] One, do you know anything about legal implications involving fetching the AP name? [33:31.880 --> 33:35.080] Because that's an actual active connection, whether that differs from just passive. [33:35.400 --> 33:43.120] And also, the box that I threw in my truck is this little ultra-made case that doesn't support PCI slots. [33:43.240 --> 33:44.120] Are there any U.S. [33:44.120 --> 33:46.800] game-based wireless devices that you can afford? [33:48.420 --> 33:57.940] For the first one, I doubt that you ever get prosecuted or arrested solely for forcing the disclosure of a network name. [33:58.960 --> 34:04.380] I think it gets into that big gray area of let's make up charges to get you more of a jail sentence. [34:05.220 --> 34:11.400] I'm sure some of our other speakers this conference can attest to some first-hand experience on that. [34:12.620 --> 34:16.560] As for the second, what operating system are you doing with it? [34:17.740 --> 34:18.660] Probably 2K. [34:20.400 --> 34:22.260] Irish might know better. [34:22.540 --> 34:25.460] There are a number of USB drivers, or USB cards. [34:26.040 --> 34:29.720] Yeah, there are wireless products out there that connect right into the USB port. [34:30.240 --> 34:35.680] I've helped some friends troubleshoot some connectivity issues or just the things not working at all because they were crap. [34:36.280 --> 34:36.780] Belkin. [34:50.710 --> 34:51.830] This is how the experience is out there. [34:51.950 --> 34:55.090] You can post it on the net and let us know. [34:55.990 --> 34:56.490] Thanks. [34:56.830 --> 35:09.250] If you're using something like Linux, oddly enough, the Microsoft USB card adapter is one of the few adapters that works well in Linux because it uses the Prism2 chipset. [35:09.670 --> 35:18.830] Linksys used to use it and then moved to Atmel, I believe, which isn't well supported and you can't do on or on or on or on or on or on or on or on or on or on. [35:19.630 --> 35:24.690] So it hurts me to recommend Microsoft and you better look quick because they stopped leaking, though. [35:25.850 --> 35:27.970] But it actually works pretty well. [35:28.690 --> 35:31.690] I actually have a comment on your first question here, just a brief one. [35:33.130 --> 35:41.390] When forcing actively to discover the network name, I presume you were talking about the same way the previous question was about you can kick somebody off and listen to it. [35:41.990 --> 35:48.570] Or actually, like in Game Stumblr, there's a flag just to want the AT&A where you want to not even fetch for it in general. [35:49.030 --> 35:49.450] Well, I'm not sure. [35:49.630 --> 35:50.610] Is that what that's doing? [35:50.810 --> 35:51.810] I don't know how to listen to it. [35:52.070 --> 35:53.110] I'm not exactly heard of it. [35:53.110 --> 36:07.950] Well, if it is the one that you're talking about where you have to kick somebody off, it is, I've heard the argument, you'd have to be Perry Mason to probably pull this up before, but I've heard the argument that you would be violating the license for that ban and that you are causing, [36:08.190 --> 36:12.590] you are knowingly, intentionally causing interference to someone's network by forcing them along. [36:12.930 --> 36:18.210] I think you would have to be Perry Mason to get that argument against you, but if on top of that you're up to no good, I think they'd throw it to you. [36:19.350 --> 36:22.250] And is any jury going to understand all that? [36:23.290 --> 36:27.870] Of course, none of us are lawyers, so you're going to want to talk to your lawyer if you have any pending, is this a legal question? [36:27.990 --> 36:33.070] Generally, the best rule of thumb is don't do it if you have that strong of, you know, oh my god, am I getting in trouble for this type of reaction. [36:40.870 --> 36:45.050] First off, just a kind of comment about accessing networks. [36:45.830 --> 36:56.430] I contacted a friend of mine who works in a TOA, and he was commenting about the fact of the active, actively connecting to an unwanted network. [36:56.670 --> 36:56.950] What? [36:57.730 --> 36:59.290] Unwanted connecting to it. [36:59.450 --> 37:10.990] And he was stating the fact that even just the default Windows XP to be signed on zero, yeah, oh look, I found it, I connected, could very well put you in that gray area. [37:11.230 --> 37:21.350] But it also is a great example for the fact that this is automatic, it's not an active thing you were seeking to do, and therefore it was probably pretty clear. [37:22.130 --> 37:32.810] Second off, I wanted to ask you guys' opinion information, what not about mesh networks, and the future of 802LU large base mesh networks. [37:33.010 --> 37:43.190] I live very near Rio Rancho, which of course just recently got slashed on it, for the fact that they're going to be one of the first municipalities around, of that size, trying to do a large mesh network. [37:43.370 --> 37:50.150] And I know, front end, they're 802.11B to the clients, back end, they're 802.11A from tower to tower. [37:50.570 --> 37:52.330] And I wanted to know... [37:52.330 --> 37:53.730] Yeah, mesh is very interesting. [37:53.910 --> 37:55.070] There's a couple of different ways of doing it. [37:55.230 --> 37:57.950] I actually meant to mention it and forgot, so I'm glad you brought it up. [37:59.670 --> 38:00.790] There's a couple of ways of doing mesh. [38:00.870 --> 38:07.430] I think what you're talking about is more of a, it's just a distribution to end users rather than the actual mesh. [38:08.410 --> 38:14.110] In a lot of cases, a mesh network means that each node in the network can also function as another access point for the network. [38:14.370 --> 38:20.230] So the more users you have, instead of getting more and more bogged down, it gets larger and larger and support even more users. [38:21.070 --> 38:33.510] So like a college campus could put a few main mesh nodes on the main buildings and then if all the students ran mesh networking, then as they spread across the campus using the network, they'll be able to route through each other back to the main buildings. [38:34.750 --> 38:36.450] MIT is doing something like that. [38:36.570 --> 38:38.230] I believe they're using mostly fixed nodes. [38:38.810 --> 38:43.730] But again, people around MIT itself form the core of the network. [38:43.730 --> 38:51.190] And then if you're near someone who's near someone who's near someone who's near MIT, you can join the mesh network and it keeps growing that way. [38:51.630 --> 38:55.530] And it's a, they're often used as an alternative to internet access for the community. [38:56.250 --> 39:07.370] I mean, each person might have their own internet or DSL or whatever for their own personal stuff, but they can also share with everyone in the community without having to pay bandwidth fees or having bandwidth caps and things like that. [39:09.130 --> 39:12.350] So mesh networks are cool if you're in an area that can support them. [39:12.350 --> 39:14.310] if there's enough interest in the GR interface right there. [39:15.950 --> 39:18.350] I've got yet another logistics question. [39:20.030 --> 39:33.630] If I understand it correctly, if I understand it correctly, with some ISPs broadcasting their signal openly, you could be, I mean, as the subscriber, you're at fault of breaking the wall. [39:33.870 --> 39:34.410] Is that not correct? [39:35.430 --> 39:38.110] I think it all comes down to intention, really. [39:39.510 --> 39:41.290] It is an unlicensed band. [39:41.290 --> 39:51.710] What it's going to come down to is if you're Windows XP connected because you turned your laptop on, I don't think there's anyone anywhere who's going to commit you to that unless they already really don't like you. [39:53.210 --> 39:57.190] If they already really don't like you, they didn't need you to do this to get you on something. [39:59.810 --> 40:01.470] So it just comes down to this. [40:01.610 --> 40:04.890] If you're pretty sure you shouldn't be doing it, you probably shouldn't do it. [40:06.810 --> 40:10.890] Otherwise, if you're pretty sure there's nothing wrong with what you're doing, you're probably fine. [40:11.350 --> 40:12.270] Or don't get caught. [40:13.310 --> 40:15.110] Or you could probably use that as an excuse. [40:15.690 --> 40:16.610] Don't talk about it. [40:16.830 --> 40:18.010] The rest of them, they're broadcasting. [40:19.070 --> 40:32.230] Now, there's going to be some ISPs, as I'm sure some of us have read on Slashdot and other places, that if you're openly sharing your high-speed internet connection through Wi-Fi, and they sent letters of stop this because you're violating your terms of service. [40:32.470 --> 40:46.590] Time Warner in New York City actually hired someone who went to all of the New York City or the NYC wireless hotspots and sat outside them, connected to them, tracer acted out, and then shut down the person on the cable door if they were sharing their cable connection. [40:46.810 --> 40:48.790] I guess Time Warner has a lot of money. [40:49.770 --> 40:50.750] Or a lot of time. [40:52.210 --> 40:53.030] Or a lot of time. [40:54.150 --> 40:58.090] But I mean, really, with more driving stuff, I think everybody has to come to their own. [40:58.090 --> 41:02.450] moral compass about what they consider acceptable and what they don't. [41:02.550 --> 41:10.150] I mean, driving around, finding what networks are around you, you'd be hard put to find anyone who really doesn't think that's appropriate or there's anything wrong with that. [41:10.470 --> 41:16.870] Recording people's data, watching people's email, that's probably a lot closer to something that most people wouldn't find acceptable. [41:18.010 --> 41:20.770] And, you know, everybody has to come to their own decision. [41:21.130 --> 41:23.130] You connect to someone's open network and check your email. [41:23.570 --> 41:24.490] It's not going to probably hurt. [41:25.390 --> 41:27.510] You'll go to someone's network and fire Kazaa. [41:27.590 --> 41:30.790] You're probably sucking up some of their bandwidth and exposing them to lawsuits. [41:30.950 --> 41:32.210] And you have to decide if that's acceptable. [41:32.670 --> 41:34.270] What it comes down to is legislature. [41:34.690 --> 41:35.870] You know, all of your legislators. [41:36.770 --> 41:40.350] You know, you're lucky if you have one that knows what you're talking about when you say war driving one. [41:40.450 --> 41:40.630] Okay? [41:41.070 --> 41:48.250] When you say war driving, they're probably getting this envision, you know, a bunch of guys in bandanas and guns running around looking for somebody who, like, went on their turf. [41:48.250 --> 41:49.090] They're war driving. [41:49.490 --> 41:49.630] No. [41:51.370 --> 42:00.250] So, you need to understand that, like, asking us whether it's a leader or not is kind of a silly question that no one knows. [42:00.370 --> 42:01.690] Your legislators don't know they're working out. [42:01.750 --> 42:02.570] They're going to come up with something. [42:02.690 --> 42:06.530] But the bottom line is, you know whatever it is you shouldn't be doing, you shouldn't be doing it. [42:06.530 --> 42:09.410] So, if you're worried about them getting in trouble with that, then don't do it. [42:09.850 --> 42:15.870] If whatever you're doing, you think it's perfectly fine, it's probably going to come down on your side that it's perfectly fine. [42:15.990 --> 42:19.470] If anything accidental or you're just looking around to see what's in the spectrum, it's an unlicensed spectrum. [42:20.490 --> 42:20.630] You know? [42:20.990 --> 42:25.370] But whenever you start actively doing things in other people's networks is when you start getting a gray area. [42:25.630 --> 42:30.030] But there's not really, nationally at least, any solid walls on this issue yet. [42:31.190 --> 42:32.750] This is just like any other issue. [42:33.850 --> 42:38.070] Negality and morality are two entirely separate entities and not necessarily related. [42:38.390 --> 42:40.150] Well, in perfect world they would be. [42:40.450 --> 42:40.550] Sure. [42:40.730 --> 42:43.490] That's just not the case in planet Earth. [42:44.150 --> 42:45.450] So, keep that in mind. [42:45.830 --> 42:47.850] What you do, be sure that it's right. [42:48.470 --> 42:50.110] And if you can, be sure that it's legal. [42:50.510 --> 42:51.950] Because you're going to get in trouble. [42:52.270 --> 42:53.970] Well, you're going to get in trouble either way, really. [42:54.310 --> 43:04.290] And even if they come down with some silly law, just because it's silly doesn't mean that you alone should go down as the martyr against it. [43:04.450 --> 43:07.650] If I were you, I'd maybe make another way of trying to defeat the law. [43:07.810 --> 43:10.390] But I wouldn't just run around doing it just because they come down with some silly rule. [43:10.630 --> 43:13.290] Whatever it is, they're probably going to come down with something a little too harsh. [43:13.430 --> 43:14.110] And it should be. [43:14.230 --> 43:18.970] But it'll probably be mostly reasonable because he's just listening to, you know. [43:19.070 --> 43:23.150] And not being that one martyr is kind of one of the messages of this entire conference. [43:23.150 --> 43:25.330] And especially the last conference, become the media. [43:26.210 --> 43:26.770] Oh, sure. [43:26.910 --> 43:28.370] Talk about it as you should have. [43:28.650 --> 43:30.690] I mean, the internet actually will let you have a voice. [43:30.850 --> 43:33.530] There's, you know, decades ago there's no way you're going to have that. [43:33.830 --> 43:33.930] You know. [43:34.510 --> 43:37.830] Nowadays, you can actually have a voice in a way of being the media. [43:38.850 --> 43:41.210] Part of it too is, don't be a dumbass. [43:41.970 --> 43:43.170] We can all agree to that. [43:44.150 --> 43:44.570] Don't be a dumbass. [43:44.570 --> 43:45.570] I mean like the guys in Lowe's. [43:45.790 --> 43:47.550] The guys who hacked into Lowe's. [43:47.630 --> 43:50.170] We're very obviously hacking into Lowe's. [43:50.170 --> 43:53.830] And they're sitting in the parking lot with a whole bunch of antennas coming off their cars. [43:54.510 --> 43:55.670] With laptops open. [43:55.870 --> 43:58.410] And the FBI went, hmm, I wonder. [43:59.730 --> 44:01.890] So, I mean, if you're worried about it. [44:01.970 --> 44:03.650] And you're morally comfortable with what you're doing. [44:03.710 --> 44:05.210] But you're worried about the legal implications. [44:06.130 --> 44:07.490] Just don't be obvious about it. [44:07.550 --> 44:09.050] You can get little back mounts for your roof. [44:09.870 --> 44:11.690] I mean, not to bash the guys with bumper stickers. [44:11.830 --> 44:13.230] I have bumper stickers on my car. [44:13.370 --> 44:14.870] Like, stop the MPAA and what not. [44:14.890 --> 44:15.750] I'm pretty obvious. [44:16.090 --> 44:18.170] But, don't have an obvious car. [44:18.170 --> 44:20.630] Don't, obviously, have it bristling with antennas. [44:20.910 --> 44:23.710] How would anybody know what you're doing if you're worried about the legal implications? [44:23.950 --> 44:24.770] And you're not actually doing it. [44:24.910 --> 44:25.690] You're legally just scanning. [44:25.890 --> 44:26.290] Right. [44:26.430 --> 44:27.350] I mean... [44:27.350 --> 44:27.790] Right. [44:28.310 --> 44:30.830] Whatever you decide is morally acceptable for what you're doing. [44:31.570 --> 44:32.830] Just don't be dumb about it. [44:34.270 --> 44:35.710] We've kept you standing long enough. [44:37.530 --> 44:39.070] Okay, well, I'm from Canada. [44:39.870 --> 44:40.270] So... [44:40.270 --> 44:40.590] Woohoo! [44:41.190 --> 44:41.610] Thank you. [44:42.190 --> 44:45.550] We don't have quite as many laws about this as you guys do. [44:45.550 --> 44:46.310] I'll rub it in though. [44:46.570 --> 44:46.630] Why not? [44:46.630 --> 44:47.330] Yeah, thanks. [44:47.970 --> 44:48.650] I appreciate it. [44:48.670 --> 44:51.130] Oh, and by the way, file sharing is legal in my country. [44:51.610 --> 44:53.950] But you do have the blank CD tax. [44:54.630 --> 44:55.050] True. [44:55.290 --> 44:55.870] We do too, don't we? [44:56.070 --> 44:56.210] Yeah. [44:56.270 --> 45:00.530] And they also make it real hard for people in the States to try to move up to Canada. [45:00.950 --> 45:00.990] Yeah. [45:01.870 --> 45:02.130] Well... [45:02.130 --> 45:02.850] Do you want us up there? [45:04.150 --> 45:04.570] Sorry? [45:04.650 --> 45:05.210] What was your question? [45:07.910 --> 45:14.470] Well, it's interesting because Canada, I'm not sure if it has as many wonderful secrets and whatnot as the U.S. government does. [45:14.670 --> 45:30.530] However, one of the horror stories which I've heard from some of my friends who live up in Ottawa around our parliament buildings and go war driving there, is that you drive around the parliament buildings, you just find hotspot after hotspot. [45:30.530 --> 45:42.610] And it's kind of like, huh, okay, parliament buildings where, you know, they're passing all sorts of laws and possibly having, you know, secret communications and they're broadcasting it all over wireless. [45:42.610 --> 45:44.010] It's just unbelievable. [45:45.370 --> 45:51.890] What you got to look at is, you know, you're in an apartment where you're only going to be for, you know, a couple of years. [45:52.150 --> 45:57.150] You don't want to invest in running Cat5 and probably the management company won't like it if you do that. [45:57.250 --> 45:57.970] Trust me, they don't. [46:00.010 --> 46:03.930] Well, I live in a, you know, crack house, so they never come around. [46:04.370 --> 46:05.550] So I just do whatever I want. [46:05.610 --> 46:07.610] I guess the network management rules there are pretty nice. [46:07.610 --> 46:08.110] Yeah. [46:09.390 --> 46:10.670] So what's the easiest thing to do? [46:10.770 --> 46:13.510] You get an access point, you slap it in, and you're good to go. [46:14.270 --> 46:16.310] And then you don't think about the security implications. [46:16.730 --> 46:19.910] Because there's no paperwork in the box that says, hey, you should do this. [46:20.050 --> 46:21.910] The other thing is, they don't know. [46:22.370 --> 46:22.730] All right. [46:22.850 --> 46:25.170] How many here has a mom or dad that has absolutely... [46:25.170 --> 46:26.790] Who thinks you look at ones and zeros all day? [46:26.910 --> 46:27.450] Just on the screen. [46:27.710 --> 46:32.250] You look at ones and zeros, click things around, you do something with the modem, you know? [46:34.750 --> 46:36.910] They don't have any real clue about this. [46:36.910 --> 46:41.850] And the second you kind of tell them about it, then the light bulb will go up like, oh, yeah. [46:43.630 --> 46:58.070] But whether you like it or not, you guys have somehow managed to just, through random, you know, circumstance and decisions in your life, just like I have, you've sort of become the ambassador of, you know, technology and security to all of your friends and family, [46:58.110 --> 46:59.130] whether you like it or not. [46:59.450 --> 46:59.850] Okay? [46:59.970 --> 47:12.890] So the next time you're there with your relatives over, you know, Christmas vacation or whatever, you're having to fix whatever thing they got themselves into, whatever random worm they ran or stupid thing that they installed or just totally sabotage any hopeful security that could happen. [47:13.310 --> 47:16.750] You might want to try and sit them down and just explain to them how so those things work. [47:16.850 --> 47:17.510] They're not stupid. [47:17.630 --> 47:18.110] They're just ignorant. [47:18.250 --> 47:19.070] There's a big difference. [47:19.250 --> 47:19.450] Okay? [47:19.610 --> 47:20.650] They just don't know... [47:20.650 --> 47:21.890] They don't know what it is. [47:21.890 --> 47:26.590] And you guys, kind of like it or not, have sort of put yourself in a position of responsibility to kind of tell them. [47:26.750 --> 47:32.130] You'll see a lot fewer retarded, ignorant laws about technology when people understand it. [47:32.490 --> 47:32.870] Okay? [47:33.370 --> 47:36.270] A lot of these things, it's just they just don't understand the ramifications of it. [47:36.290 --> 47:38.550] So they make something that's wide and sweeping and don't really get it. [47:39.390 --> 47:44.390] But if collectively we can sort of educate people, you know, just friends and family. [47:44.390 --> 47:48.930] You know, you go out on the street corners with big signs demanding that people listen about security. [47:49.030 --> 47:49.370] Because they won't. [47:49.530 --> 47:50.550] They'll just think they're crazy. [47:51.110 --> 47:52.310] But your relatives will. [47:52.630 --> 47:54.210] And I think that's really what's happening. [47:54.690 --> 47:56.630] Okay, my relatives will probably a little bit. [47:56.690 --> 47:57.170] And yours might. [47:57.790 --> 47:58.450] His won't. [47:59.890 --> 48:00.650] But you guys... [48:00.650 --> 48:03.850] You're describing a conversation I had 48 hours ago, man. [48:04.050 --> 48:07.090] Well, the bottom line is when it comes down to it, they don't get it. [48:07.170 --> 48:08.090] Just say, look, just do it. [48:08.250 --> 48:09.090] Okay, just do this. [48:10.090 --> 48:12.490] So even if they don't understand it, they'll be doing the secure thing. [48:12.490 --> 48:14.630] But if we can do that... [48:14.630 --> 48:17.110] You'll see fewer of these things in the apartment complex. [48:17.230 --> 48:19.370] And what you'll get is more of them that are open that are meant to be open. [48:19.450 --> 48:20.030] Like at my house. [48:20.150 --> 48:20.790] You come out of my house. [48:20.870 --> 48:21.490] You get on my network. [48:21.690 --> 48:22.610] I'll notice you're there. [48:22.850 --> 48:23.630] It's washed. [48:23.710 --> 48:24.270] It's locked. [48:24.530 --> 48:26.470] It's locked to an offline machine. [48:26.470 --> 48:29.290] So you can't have a scenario of hacking somebody from my house and me getting in trouble. [48:31.870 --> 48:34.610] But the fact of the matter is it's ignorance. [48:34.830 --> 48:35.470] It's not stupidity. [48:35.570 --> 48:37.130] And you guys can actually talk to some of these people. [48:37.170 --> 48:39.270] Although I wouldn't go ahead up to brand people you don't know. [48:39.350 --> 48:42.170] Because they will take that as sort of a threat, whether it is or not. [48:42.170 --> 48:44.470] But keep it to friends and family for the time being. [48:44.590 --> 48:44.950] All right. [48:45.090 --> 48:46.330] Well, we're being in a run short on time. [48:46.530 --> 48:48.170] So we'll try to get to the last questions. [48:48.770 --> 48:51.370] So I'll try to be quick since we answered a couple of things. [48:51.450 --> 48:52.070] I'll be real quick. [48:52.090 --> 48:59.370] The big one that I have is what is the difference in the TurboCell implementation versus straight 802 and 11B between master and CRB? [48:59.470 --> 48:59.830] TurboCell. [49:00.030 --> 49:01.190] That's a kind of long one. [49:01.490 --> 49:02.870] A real quick version. [49:03.390 --> 49:07.510] TurboCell is custom firmware that works on Lucent access points. [49:07.510 --> 49:10.030] That's basically meant for point to point bridging. [49:10.670 --> 49:15.630] Usually over long range stuff that aggregates a bunch of packets into a larger frame. [49:15.990 --> 49:19.390] Also, second to that, what is the Lucent site survey process? [49:19.590 --> 49:21.510] Is that assuming packet types or...? [49:22.550 --> 49:23.710] I don't know much about it. [49:23.790 --> 49:25.470] I think it's basically just kind of like a net stumble. [49:25.810 --> 49:28.330] We can answer some of these questions after the thing. [49:28.330 --> 49:29.030] It would be really important. [49:29.350 --> 49:31.070] We've got a lot of people who haven't actually asked questions. [49:31.230 --> 49:32.370] I'd like to see if we can get some more. [49:33.130 --> 49:33.970] So come by afterwards. [49:34.130 --> 49:36.150] I'll see if we can answer some of your questions. [49:36.790 --> 49:41.650] Do you guys know about the SCC getting hospitals run out of Wi-Fi frequency? [49:42.850 --> 49:44.050] I've not actually heard that. [49:44.290 --> 49:47.590] The things that I've seen, it's not really indicated that. [49:47.750 --> 49:49.110] They'd have to have a special run of things. [49:49.270 --> 49:51.690] I've heard about a year ago that they were... [49:53.510 --> 49:55.670] If they did, it was because of HIPAA compliance. [49:55.670 --> 49:57.930] And the doctors are just really convenient for them. [49:58.110 --> 49:59.090] All the hospitals have it. [49:59.190 --> 50:01.850] Because they have to carry around lots of medical information. [50:02.150 --> 50:02.570] Charts and things. [50:02.730 --> 50:03.890] A lot easier to have them on a little PDA. [50:04.030 --> 50:05.470] They've got wireless access. [50:05.690 --> 50:07.450] But I've not heard about that. [50:07.490 --> 50:07.810] I've not seen it. [50:07.810 --> 50:09.670] The only people I've actually seen that have custom hardware. [50:10.130 --> 50:12.370] Custom hardware and custom implementation of this. [50:12.490 --> 50:13.790] In fact, the New York Stock Exchange. [50:13.810 --> 50:15.610] Some will make them some very custom equipment. [50:16.410 --> 50:17.110] For the wireless. [50:21.710 --> 50:23.690] I was just wondering as far as... [50:23.690 --> 50:26.890] Yeah, I worked with some Alvary on stuff at the job. [50:27.150 --> 50:28.770] And how come... [50:29.390 --> 50:30.690] To adjust power... [50:31.610 --> 50:32.870] As far as... [50:32.870 --> 50:33.650] It's just like... [50:33.650 --> 50:34.670] You're speaking a little more. [50:34.670 --> 50:35.230] I can't hear you. [50:35.590 --> 50:36.810] Low, medium, and high. [50:37.290 --> 50:38.490] As far as the power goes. [50:38.790 --> 50:40.910] How come there isn't more of like a linear adjustment? [50:41.530 --> 50:43.350] You know, to kind of walk around your house or whatever. [50:43.350 --> 50:46.350] Do a site survey and see how far the signal will go off? [50:46.470 --> 50:47.170] Some haven't. [50:47.350 --> 50:49.530] You just haven't demanded enough and enough numbers. [50:50.030 --> 50:52.070] It's a UI issue probably more than anything else. [50:52.070 --> 50:55.650] And not every part gives you the exact control you're looking for. [50:56.590 --> 50:57.170] But most do. [50:57.670 --> 50:57.950] Cool. [51:01.350 --> 51:02.670] On the 2.4... [51:02.670 --> 51:05.250] You know, 2.4, everything's getting kind of polluted. [51:05.670 --> 51:06.110] If... [51:06.110 --> 51:07.230] Probably a little closer than the mic. [51:07.390 --> 51:08.310] Sorry, it's a little more clear. [51:08.470 --> 51:08.850] No problem. [51:09.370 --> 51:12.090] On the 2.4, everything's getting kind of polluted. [51:12.090 --> 51:24.290] If you want to do a secure network, is there any licensed frequencies that you guys know or the equipment that you would know to basically point to point or point to repeater that you can broadcast out? [51:24.790 --> 51:25.950] 2.4 is... [51:25.950 --> 51:26.270] 2.4 is... [51:26.270 --> 51:26.990] You're fine on... [51:26.990 --> 51:30.450] 5 GHz rate of 211A are fine but don't have anything in the way. [51:30.650 --> 51:35.030] If you don't have anything in the way, 211A is much nicer, but it'll bounce on the glass wall. [51:35.250 --> 51:36.750] I mean, it doesn't go through anything. [51:37.010 --> 51:37.090] Right. [51:37.090 --> 51:43.190] But I mean, is there anything else other than 2.4 or 5.8 that you would know of that the equipment would handle? [51:43.550 --> 51:44.890] Some high data pass? [51:44.890 --> 51:49.510] They make some that's licensed as far as I know that it runs on some UHF as far as I'm concerned. [51:49.950 --> 51:51.330] I remember, but I don't remember who it is. [51:51.490 --> 51:52.030] You don't remember? [51:52.170 --> 51:52.530] I don't remember. [51:52.830 --> 51:52.970] I'm sorry. [51:53.090 --> 51:53.970] I'm not ready as long as... [51:53.970 --> 51:54.390] Thank you, Joey. [51:55.850 --> 51:58.150] And if you have a lot of money, actually, keep in mind laser. [51:59.970 --> 52:00.610] Excellent point. [52:00.970 --> 52:02.170] For point to point, perfect. [52:02.450 --> 52:09.130] Point to point laser as long as you're within 1,600 feet. [52:09.970 --> 52:16.110] The actual 802.11, the initial 802.11, in fact, the support frequency mapping as well, had an extension for laser. [52:16.450 --> 52:20.350] Not that there's some reason for all the obfuscation of 802.11 and laser. [52:20.930 --> 52:27.670] We were actually considering laser to get the conference bandwidth from 802 briefly. [52:28.310 --> 52:30.090] Of course, that's kind of a crisis. [52:37.130 --> 52:38.490] Let me ask a question here. [52:38.490 --> 52:43.550] How many of you guys want to get into board driving, but haven't really figured it out? [52:43.670 --> 52:46.010] Haven't really decided how you're going to go about it? [52:46.410 --> 52:47.290] A couple of people? [52:47.930 --> 52:48.870] Come on up to the front. [52:49.730 --> 52:51.750] First, one, two, three, and four. [52:56.370 --> 52:59.030] We've got some books from Synchrist Corporation. [52:59.030 --> 52:59.390] Here they are. [52:59.490 --> 52:59.690] Give them. [52:59.810 --> 53:04.130] This is the board driving, drive, detect, and defend. [53:05.210 --> 53:10.770] There are a bunch more of these books, a whole lot more of these books, back at Synchrist Publishing's table all the way in the back. [53:11.710 --> 53:15.970] And actually, one of us is going to be signing some of these books later today. [53:15.970 --> 53:17.470] Even though all I have is a cover quote, yeah. [53:19.050 --> 53:19.410] So... [53:19.410 --> 53:23.210] But if you want to talk, ask us some more questions, we'll probably be back by the vendors. [53:23.770 --> 53:36.550] So, anybody who had questions they didn't want to ask in front of everyone, or just didn't get a chance to, or wanted more detailed answers, come back, look at the books that all the different vendors have, look at Synchrist's book, and talk to us. [53:38.170 --> 53:38.630] Smile. [53:50.110 --> 53:52.190] So many celebrity hackers here today. [53:52.410 --> 53:53.350] It's very exciting. [53:54.050 --> 54:06.090] The next panel, in a few minutes, is going to be when corporations attack, with Dan Morgan, who knows more than a lot of people that you can get in a lot of trouble for telling people how things work.