User Knowledge
In the end, the network needs to be convenient for users as well as secure. The users are the reason the network is there, and if they can’t use the network, it isn’t serving its purpose.
Security is often seen as a direct trade-off with convenience, but it does not have to be an either/or situation. If a security mechanism is difficult to use, users will seek to bypass it whenever possible. When security is bypassed, it isn’t working. So, when implementing security mechanisms, strive to make them both usable and secure. Security mechanisms don’t have to impede usability.
As an example, MAC address filtering is mostly transparent to the end user. It does not impose a burden on them, so most users are not going to try to subvert the filtering. The only time it affects them is when they need to get a new network card added to the filter lists. The burden of work (and inconvenience) for MAC filtering lies with the system administrator. Being the person who implemented the security mechanism, the system administrator will hopefully be diligent in maintaining the list of allowed MAC addresses and not try to defeat his own security mechanism.
A bad example, where security makes it inconvenient for users, is the default method of WEP-key management. The user is responsible for entering the right WEP keys into the system and keeping them up to date. A change to the keys, which should happen on a regular basis, requires every user to change settings or have someone do it for ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access