Next test, the website. I wanted to see how easy it was to navigate and manage my account. The other thing that I really needed to know was how I could manage my 5 numbers.
Anyway, since I am using a non-"faves" enabled phone, I wanted to see if I could manage my list of 5 numbers through the website. Sure enough, I can and did. That question answered.
The other thing that I liked about the website is that it shows you how many minutes you've consumed for the month. Unfortunately, it doesn't appear to give detailed information on call data. Perhaps, it will after a monthly statement is generated.
Part 3, Plan | Part 5, Customer Service
Technology Stuff
Saturday, August 25, 2007
Saturday, August 18, 2007
Switching Cell Phone Providers, pt 3 (Plan)
Before I started searching for a plan, I needed to know what type of usage I would need. I was abler to pull my last 6 months of usage records from my current Cingular account. A quick analysis showed that I used about 400 minutes a month and sent/received 110 SMS messages. Turns out I was buying a lot more then I was using.
I got signed up on the base "myFaves" plan with Tmobile. This plan offers unlimited (again, within context) calling to 5 numbers. For all other numbers, 300 minutes.
I now have a Tmobile plan with a temporary number. At least, that is what they called it. I had told them when signing up that I would either cancel the plan or roll my existing Cingular number over. I got the phone home and immediately removed the SIM card and plugged it into my existing phone. Ah, the beauty of GSM... I already own a SLVR which I really like. The free phone that came with the plan was a nice, pink Miami Ink RAZR. Needless to say, that's just not my style.
Anyway, 5 minutes after I got home, my existing SLVR was up and running on Tmobile's network. By the way, the perfect way to evaluate two services is to actually use the exact same device. The Mythbusters would be proud of me. I immediately phoned a friend and walked through the house to see what the service was like. First impression was good. I definitely have some dead spots in the house on Cingular's network. Now, does this alone mean that Tmobile is better then Cingular? Not really, it just means that there is likely a Tmobile tower closer to my house then a Cingular tower.
Over the next week, I continued to check the bars on my phone (which isn't foolproof) and called friends and family from different locations. Overall, in my area, I got just as good, if not better, service with Tmobile then with Cingular. That aspect of my evaluation is looking good.
Part 2, Coverage | Part 4, Website
I got signed up on the base "myFaves" plan with Tmobile. This plan offers unlimited (again, within context) calling to 5 numbers. For all other numbers, 300 minutes.
I now have a Tmobile plan with a temporary number. At least, that is what they called it. I had told them when signing up that I would either cancel the plan or roll my existing Cingular number over. I got the phone home and immediately removed the SIM card and plugged it into my existing phone. Ah, the beauty of GSM... I already own a SLVR which I really like. The free phone that came with the plan was a nice, pink Miami Ink RAZR. Needless to say, that's just not my style.
Anyway, 5 minutes after I got home, my existing SLVR was up and running on Tmobile's network. By the way, the perfect way to evaluate two services is to actually use the exact same device. The Mythbusters would be proud of me. I immediately phoned a friend and walked through the house to see what the service was like. First impression was good. I definitely have some dead spots in the house on Cingular's network. Now, does this alone mean that Tmobile is better then Cingular? Not really, it just means that there is likely a Tmobile tower closer to my house then a Cingular tower.
Over the next week, I continued to check the bars on my phone (which isn't foolproof) and called friends and family from different locations. Overall, in my area, I got just as good, if not better, service with Tmobile then with Cingular. That aspect of my evaluation is looking good.
Part 2, Coverage | Part 4, Website
Saturday, August 11, 2007
4 Things To Think About If You Must Use WEP
Okay, if you've read my previous posts, know how to use WPA to secure your wireless network. For some, this will not be an option. If you absolutely must use WEP, let me give you a few things to keep in mind.
#1) Use the longest password possible. At least 128 bit. This won't buy you much security, but it will mean that someone looking to crack your password will have to sniff more traffic. This means they have to be connected for a longer period of time before being able to discover your password.
#2) Disconnect the devices connected to your wireless network when they aren't in use. If you have a computer that you leave on all the time, it is constantly "checking in" with your access point. This conversational traffic is exactly what a malicious person needs in order to collect the right information to crack your password. If you are like me, you don't like powering down your equipment every day. In this case, just access your wireless configuration on your laptop and disable the connection. When you are ready to use it again, just enable it. Easy.
#3) Use a firewall. If you don't know what this is or how to configure it, don't worry. There are lots of resources available on the 'net. I may also do a basic writeup on it if there is interest. Basically, you want to keep your wireless network separate from the rest of your home network that has your other computers on it. If someone were to access your wireless network, you don't want them getting to your internal resources.
#4) Be smart about the type of data that you transfer over your wireless network. Assume that some stranger is going to get a copy of it and ask yourself if it is something that needs to be more private. Is it something that you would write on a postcard and send through the post office? If so, it's probably okay for use on your wireless network.
#1) Use the longest password possible. At least 128 bit. This won't buy you much security, but it will mean that someone looking to crack your password will have to sniff more traffic. This means they have to be connected for a longer period of time before being able to discover your password.
#2) Disconnect the devices connected to your wireless network when they aren't in use. If you have a computer that you leave on all the time, it is constantly "checking in" with your access point. This conversational traffic is exactly what a malicious person needs in order to collect the right information to crack your password. If you are like me, you don't like powering down your equipment every day. In this case, just access your wireless configuration on your laptop and disable the connection. When you are ready to use it again, just enable it. Easy.
#3) Use a firewall. If you don't know what this is or how to configure it, don't worry. There are lots of resources available on the 'net. I may also do a basic writeup on it if there is interest. Basically, you want to keep your wireless network separate from the rest of your home network that has your other computers on it. If someone were to access your wireless network, you don't want them getting to your internal resources.
#4) Be smart about the type of data that you transfer over your wireless network. Assume that some stranger is going to get a copy of it and ask yourself if it is something that needs to be more private. Is it something that you would write on a postcard and send through the post office? If so, it's probably okay for use on your wireless network.
Thursday, August 2, 2007
Use WPA instead of WEP, pt 2
Lesson #2) Fine. I'll use the instruction manual. What should I be looking to do? Great! Look for instructions on how to connect to the administration function of the device you are setting up. This will usually be accessible on a private address in the 192.168. range. This means that you plug it in and then use your browser to access a special address that is given to you in the instruction manual. Once you have accessed this function, you should be looking for a security section. This will give you options on what kind of wireless security you want. At the time of this writing, most devices give you three options: open, WEP, and WPA. You want to choose WPA. (Specifically, referring to Pre-Shared Key or "Personal". The Enterprise level is not within the scope of this blog.)
The setup of WPA is really not any more difficult then WEP. Which is what makes it frustrating for me to see people still using WEP. There are probably a handful of situations in which folks may still want to use WEP. Most of these being to support older equipment that was purchased before the WPA protocol was developed. We will cover approaches to using WEP safely later.
Lesson #3) Choose a good password. Good passwords are difficult for humans. They are hard to remember, hard to come up with, hard to type. This is unfortunate and typically leads most people to choosing bad passwords. Bad passwords are short and easy to remember. They are things that can be found in dictionaries or on your myspace page (birthday, dog's name, friend's name, etc). When thinking about a good password for your wireless network, you have one thing going for you; you just don't have to type it very often, if ever. Most modern devices allow you to enter the password one time and it will retain it.
When choosing a password, you want to make it as long as possible and as random as possible. WPA allows for a password of up to 64 hexidecimal characters. I know what you're thinking, how am I going to type in a 64 character password? Don't worry, I will walk you through the approach that I use in a bit. You won't have to type a thing. The point here is that you want the longest password possible. It doesn't make any difference on your day-to-day computer use, but it does increase the time needed for a malicious person to gain access to your network.
Now, to get a random password, you need a thing called a "password generator". With OS X, you can create one using the Keychain application. If you are a Firefox user, there is an excellent extension available called SecurePassword. If neither of these are an option for you, there are a few of them available on the web. My favorite website for this is GRC. GRC's password generator will build the perfect password for WPA merely by accessing the link above. They provide a 64 character hexidecimal password along with a 63 character alpha-numeric one. Either one will work for WPA, so let's choose the alpha-numeric one since it is more human-friendly. When I accessed the site, this is the password that I received:
lKAg0kImzxZ3HdDrlojUaUCXfInGNBXbMai4V7Afz2uh9nMNiByqaCfD3KMXqlD
Don't let this scare you. Just highlight it and copy it into your computer's buffer (ctrl+c or Cmd+c). Open up a text editor and paste (ctrl+v or Cmd+v) it into the text editor. Do a quick File|Save and you've got your password (and you didn't have to type a thing). Now, back to the wireless device we were configuring... You've selected WPA and are prompted to enter the password or the "pre shared key". Just switch back to your text editor, copy your random password, and paste it into the password field. Now, look for the save button and you are done with your access point configuration! Once you hit save, your device will probably restart and anyone currently connected to it will be dropped. They will also not be able to re-connect without your new random password.
Lesson #4) Configure only the computers that you want on your wireless network. Your next challenge is how to get that new password to your laptop so that it can access your wireless network. There are, of course, a number of ways in which to do this. The one that I propose is called the sneakernet. Put on your tin foil hat with me and find a blank disk or USB thumb drive. This password isn't something that you want to leave on your computer, transfer to your friend via email, or post on a website. Ever. You must maintain strict control over this password. Find a disk... floppy, CD, DVD, ZIP, whatever. My preference is CD these days. You want something that will be accessible to most types of computers. Remember that file you created with your text editor? Move it to the disk.
Now, take the disk and insert it into the laptop you want to access your wireless network. Open up the text file, highlight the password, and copy it into your buffer. Now, open up your computers wireless configuration and find your network in the list. Hopefully, it will say "secured" or something to that effect. When you select it, it will prompt for a password. No problem! You just paste the new password into the both fields and you're done. If done correctly, your laptop is now authenticated to your wireless network and you are all set. Just take out the disk and repeat the procedure on any other computers that you want to have connected to your wireless network. Friend of yours is visiting and wants to get their email? Hand them the disk. Just make sure you get it back. :)
The setup of WPA is really not any more difficult then WEP. Which is what makes it frustrating for me to see people still using WEP. There are probably a handful of situations in which folks may still want to use WEP. Most of these being to support older equipment that was purchased before the WPA protocol was developed. We will cover approaches to using WEP safely later.
Lesson #3) Choose a good password. Good passwords are difficult for humans. They are hard to remember, hard to come up with, hard to type. This is unfortunate and typically leads most people to choosing bad passwords. Bad passwords are short and easy to remember. They are things that can be found in dictionaries or on your myspace page (birthday, dog's name, friend's name, etc). When thinking about a good password for your wireless network, you have one thing going for you; you just don't have to type it very often, if ever. Most modern devices allow you to enter the password one time and it will retain it.
When choosing a password, you want to make it as long as possible and as random as possible. WPA allows for a password of up to 64 hexidecimal characters. I know what you're thinking, how am I going to type in a 64 character password? Don't worry, I will walk you through the approach that I use in a bit. You won't have to type a thing. The point here is that you want the longest password possible. It doesn't make any difference on your day-to-day computer use, but it does increase the time needed for a malicious person to gain access to your network.
Now, to get a random password, you need a thing called a "password generator". With OS X, you can create one using the Keychain application. If you are a Firefox user, there is an excellent extension available called SecurePassword. If neither of these are an option for you, there are a few of them available on the web. My favorite website for this is GRC. GRC's password generator will build the perfect password for WPA merely by accessing the link above. They provide a 64 character hexidecimal password along with a 63 character alpha-numeric one. Either one will work for WPA, so let's choose the alpha-numeric one since it is more human-friendly. When I accessed the site, this is the password that I received:
lKAg0kImzxZ3HdDrlojUaUCXfInGNBXbMai4V7Afz2uh9nMNiByqaCfD3KMXqlD
Don't let this scare you. Just highlight it and copy it into your computer's buffer (ctrl+c or Cmd+c). Open up a text editor and paste (ctrl+v or Cmd+v) it into the text editor. Do a quick File|Save and you've got your password (and you didn't have to type a thing). Now, back to the wireless device we were configuring... You've selected WPA and are prompted to enter the password or the "pre shared key". Just switch back to your text editor, copy your random password, and paste it into the password field. Now, look for the save button and you are done with your access point configuration! Once you hit save, your device will probably restart and anyone currently connected to it will be dropped. They will also not be able to re-connect without your new random password.
Lesson #4) Configure only the computers that you want on your wireless network. Your next challenge is how to get that new password to your laptop so that it can access your wireless network. There are, of course, a number of ways in which to do this. The one that I propose is called the sneakernet. Put on your tin foil hat with me and find a blank disk or USB thumb drive. This password isn't something that you want to leave on your computer, transfer to your friend via email, or post on a website. Ever. You must maintain strict control over this password. Find a disk... floppy, CD, DVD, ZIP, whatever. My preference is CD these days. You want something that will be accessible to most types of computers. Remember that file you created with your text editor? Move it to the disk.
Now, take the disk and insert it into the laptop you want to access your wireless network. Open up the text file, highlight the password, and copy it into your buffer. Now, open up your computers wireless configuration and find your network in the list. Hopefully, it will say "secured" or something to that effect. When you select it, it will prompt for a password. No problem! You just paste the new password into the both fields and you're done. If done correctly, your laptop is now authenticated to your wireless network and you are all set. Just take out the disk and repeat the procedure on any other computers that you want to have connected to your wireless network. Friend of yours is visiting and wants to get their email? Hand them the disk. Just make sure you get it back. :)
Friday, July 27, 2007
Use WPA instead of WEP
Okay, folks, it is time once again to review the state of today's wireless 802.11 (also known by the marketing term, WiFi) security. This has been documented time and time again, but it has recently became clear to me that it apparently isn't sinking in. One of my goals with this blog is to try and educate friends and family, so I thought I would write something up that is in plain English and implore you to think about your wireless situation at home.
I was recently on vacation in a small town in Idaho when I fired up my laptop and found no fewer then six wireless networks within range. A couple of things surprised me about this. The first being that there were six(!) networks in my immediate vicinity in a town with a population of 4,000. I am not used to seeing this kind of coverage in the smaller mountain towns that I've visited. The second, and probably more, surprising aspect of this was that all of them were secured! That's right, none of them were set to allow open access, nor did they have the all-too-familiar network name "linksys" or "default".
Unfortunately, they had all used WEP as the means for securing their network. This is horribly insecure and merely serves as a means to keep the honest people honest. Perhaps, that is all the owners were after, but I would like to encourage you to go a step farther in securing your own home network. It's really not that hard and will take 10-15 minutes, tops. If you haven't already, please read my post regarding the dangers of using WEP.
If you are still reading, then perhaps I've convinced you to convert your network from WEP or open to WPA. If that is the case, read on...
Lesson #1) Do not buy an access point (also known as "router", "wireless hub", or just plain "wireless"), take it home, plug it in, and just start using it. This is what we would call the "default" or open access. It comes with an instruction manual for a reason. Use it! :)
Next Lessons...
I was recently on vacation in a small town in Idaho when I fired up my laptop and found no fewer then six wireless networks within range. A couple of things surprised me about this. The first being that there were six(!) networks in my immediate vicinity in a town with a population of 4,000. I am not used to seeing this kind of coverage in the smaller mountain towns that I've visited. The second, and probably more, surprising aspect of this was that all of them were secured! That's right, none of them were set to allow open access, nor did they have the all-too-familiar network name "linksys" or "default".
Unfortunately, they had all used WEP as the means for securing their network. This is horribly insecure and merely serves as a means to keep the honest people honest. Perhaps, that is all the owners were after, but I would like to encourage you to go a step farther in securing your own home network. It's really not that hard and will take 10-15 minutes, tops. If you haven't already, please read my post regarding the dangers of using WEP.
If you are still reading, then perhaps I've convinced you to convert your network from WEP or open to WPA. If that is the case, read on...
Lesson #1) Do not buy an access point (also known as "router", "wireless hub", or just plain "wireless"), take it home, plug it in, and just start using it. This is what we would call the "default" or open access. It comes with an instruction manual for a reason. Use it! :)
Next Lessons...
Friday, July 20, 2007
Why WEP Should Be Considered Bad Form
If you have a wireless network at home and you've either left it open (unsecured) or you have secured it using the WEP option, this article is for you. If you have wireless and you have no idea what the preceding sentence means, you need to read this and my follow-up entries on how to secure your wireless network.
If you think WEP is good enough for your wireless security, let me educate you on how incredibly simple it is to bypass. One would need the correct hardware (an Atheros based wireless card - $50), the correct software (available over the Internet - free), and be near enough to your wireless network to pick up a signal (also free). Once all three of these are in place, it takes less then an hour (in some cases, far less!) to come up with the password that you used to supposedly secure your network. At this point, they are on your network. Mostly, they will just be interested in accessing the Internet for free. Mostly. If this doesn't scare you, it should. If you have other computers on your home network that have your financial information on them, this should scare you very much. Kudos to you for choosing to secure your network instead of using the default "open" network. Unfortunately, using WEP isn't much better then just leaving your network open.
Perhaps you are one that doesn't care if someone else uses your network to access the Internet? While that is altruistic and very generous of you, it does leave you open to risks. For starters, most ISPs specifically forbid the sharing of your home Internet service in their terms of service. You can argue how the "Man" is trying to squeeze more money out of us all by doing this and you'd likely be right. But that doesn't stop them from disconnecting you if they feel that you've infringed on the agreement that you submitted to when purchasing their service. Furthermore, these types of companies believe that is a violation of federal or state laws and may seek action against you.
If the risk of the Man disconnecting you isn't enough, think about what kinds of bad things can be done online and will be traced back to your home address. Accessing child porn, probing government networks, and communicating with known terrorists are all things that will raise flags with your federal government and your ISP. From what I've read, it is a legal grey area on whether or not you could be held liable for this. (How believable is your defense of "It wasn't me. Someone must have used my wireless network.") Is it worth the hassle?
Now, I'm really not the doom and gloom type. The chances of this happening to you are small, but not impossible. If you live in a sparsely populated area, the chances of one of your neighbors wanting to break into your network to conduct malicious activity are slim. If it isn't one of your neighbors, but a stranger instead, then ideally you'd notice a car sitting out on your street with a person inside using a laptop. If you live in a larger city or a densely populated area, there are many more people available and interested in using your network. If you are in an apartment building, you would never even see that this is happening.
http://news.com.com/2100-1039-5112000.html
http://money.cnn.com/2005/08/08/technology/personaltech/internet_piracy/?cnn=yes
http://www.pcworld.com/article/id,122153-page,1/article.html
If you think WEP is good enough for your wireless security, let me educate you on how incredibly simple it is to bypass. One would need the correct hardware (an Atheros based wireless card - $50), the correct software (available over the Internet - free), and be near enough to your wireless network to pick up a signal (also free). Once all three of these are in place, it takes less then an hour (in some cases, far less!) to come up with the password that you used to supposedly secure your network. At this point, they are on your network. Mostly, they will just be interested in accessing the Internet for free. Mostly. If this doesn't scare you, it should. If you have other computers on your home network that have your financial information on them, this should scare you very much. Kudos to you for choosing to secure your network instead of using the default "open" network. Unfortunately, using WEP isn't much better then just leaving your network open.
Perhaps you are one that doesn't care if someone else uses your network to access the Internet? While that is altruistic and very generous of you, it does leave you open to risks. For starters, most ISPs specifically forbid the sharing of your home Internet service in their terms of service. You can argue how the "Man" is trying to squeeze more money out of us all by doing this and you'd likely be right. But that doesn't stop them from disconnecting you if they feel that you've infringed on the agreement that you submitted to when purchasing their service. Furthermore, these types of companies believe that is a violation of federal or state laws and may seek action against you.
If the risk of the Man disconnecting you isn't enough, think about what kinds of bad things can be done online and will be traced back to your home address. Accessing child porn, probing government networks, and communicating with known terrorists are all things that will raise flags with your federal government and your ISP. From what I've read, it is a legal grey area on whether or not you could be held liable for this. (How believable is your defense of "It wasn't me. Someone must have used my wireless network.") Is it worth the hassle?
Now, I'm really not the doom and gloom type. The chances of this happening to you are small, but not impossible. If you live in a sparsely populated area, the chances of one of your neighbors wanting to break into your network to conduct malicious activity are slim. If it isn't one of your neighbors, but a stranger instead, then ideally you'd notice a car sitting out on your street with a person inside using a laptop. If you live in a larger city or a densely populated area, there are many more people available and interested in using your network. If you are in an apartment building, you would never even see that this is happening.
http://news.com.com/2100-1039-5112000.html
http://money.cnn.com/2005/08/08/technology/personaltech/internet_piracy/?cnn=yes
http://www.pcworld.com/article/id,122153-page,1/article.html
Monday, July 16, 2007
Switching Cell Phone Providers, pt 2 (Coverage)
Okay, so I start researching Tmobile. First off, I need to learn about their coverage. I check out their website to see if they have a coverage map. I was impressed on two fronts. First of all, they offer a method to search on an address basis, so that you can drill down exactly. Secondly, they offer a view of how strong the signal is, not just whether or not there is one. I found this encouraging even if I might have a lower signal on a particular search. I like it when companies are just upfront about things.
My next dilemma is figuring out how to test the service without getting locked into a contract. (side note: I hate the fact that every company out there wants to lock you into a two year contract.) A friend of mine pointed me to Costco. Probably wouldn't have occurred to me to check there, but I swung by after work one day to take a look. They have a small kiosk where they offer phones and plans from multiple providers. The really cool thing about this is that they have worked out some deal with each provider where you have two weeks to change your mind and get out of the contract. This was my perfect solution!
Part 1, Intro | Part 3, Plan
My next dilemma is figuring out how to test the service without getting locked into a contract. (side note: I hate the fact that every company out there wants to lock you into a two year contract.) A friend of mine pointed me to Costco. Probably wouldn't have occurred to me to check there, but I swung by after work one day to take a look. They have a small kiosk where they offer phones and plans from multiple providers. The really cool thing about this is that they have worked out some deal with each provider where you have two weeks to change your mind and get out of the contract. This was my perfect solution!
Part 1, Intro | Part 3, Plan
Subscribe to:
Posts (Atom)
