# Securing a wireless home network- Don't disable the 'SSID Broadcast'

**URL:** <https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989>\
**Category:** Factual Questions\
**Created:** [February 11, 2011, 4:22am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989 "2011-02-11T04:22:24Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![MuleSkinner](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@MuleSkinner](https://boards.straightdope.com/u/MuleSkinner)\
**Post date:** [February 11, 2011, 4:22am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/1 "2011-02-11T04:22:24Z")

</div>

> [@](#):
>
> **Don’t disable the ‘SSID Broadcast’**. Do not disable the ‘SSID Broadcast’ feature of your Access Point or router. This seems counter-intuitive, but it is actually a bad idea.[[3]](http://www.wikihow.com/Secure-Your-Wireless-Home-Network#_note-2) Although this would make your network invisible to your neighbors, any determined hacker can still sniff out your SSID; and you are implicitly forcing your computer to shout out your SSID anywhere you are, while it is trying to connect to it. Anyone could then impersonate your router with that SSID, and get your credentials that way.

> **[How to Secure Your Wireless Home Network: Expert Tips](https://www.wikihow.com/Secure-Your-Wireless-Home-Network)**
>
> Simple & effective ways to keep your wi-fi secureThis wikiHow teaches you how to prevent unauthorized access to your wireless home network by securing your router. You can do this by editing your network's settings from the router's page....

> [@](#):
>
> **Question:** Joshua, please let me know your thoughts on disabling broadcasting your router’s SSID.
> 
> **Joshua Wright:** It’s a bad idea. I know the PCI specification requires you to do this, and I’ve told them they need to remove this requirement from the specification. Imagine you are a government base and you don’t tell your agents where you are located. They have to walk around and keep asking “Are you the government base?” to everyone the meet. Eventually, some wily hacker or bad guy will say “Heck YEAH I’m your base, come on in and share your secrets with me.” This is essentially what happens with SSID cloaking, where you have to ask every AP you meet if their desired SSID is available, allowing an attacker to impersonate your SSID at the airport, coffee shop, in the airplane, etc. In short, don’t cloak your SSID, but don’t make your SSID something like “sexyhackertargethere” either.

[http://www.techrepublic.com/blog/wireless/wi-fi-security-is-always-one-step-behind/205](http://www.techrepublic.com/blog/wireless/wi-fi-security-is-always-one-step-behind/205)  
Is this correct? I don’t really understand the rationale given, but I’ve read a few other guides to securing networks, and they’ve said the opposite.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 11, 2011, 9:59am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/2 "2011-02-11T09:59:00Z")

</div>

I’d say it doesn’t make a difference. Though I don’t follow the rationale of the cites you’ve given either, turning of SSID broadcast isn’t a real security feature, rather security by obscurity. Bad guys with the right sniffer software will see your access point anyway, no matter what your settings for SSID broadcast are. Turn on WPA2, choose a secure and long enough password, and you’ll be as safe as possible for a home user.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 11, 2011, 10:26am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/3 "2011-02-11T10:26:24Z")

</div>

Concur. Disabling the SSID broadcast and setting up connection only to known MAC Addresses are two things people often recommend as security precautions, but neither of them are effective, because SSIDs and MAC addresses can be sniffed and MAC addresses can be spoofed.

The only thing these supposed precautions actually achieve is greater inconvenience for you, the legitimate user/administrator of the system. Experienced hackers will not be even slightly perturbed, and casual intruders should be shut out by strong encryption.

---

<div class="post-metadata">

**Author:** ![MikeS](https://avatars.discourse-cdn.com/v4/letter/m/919ad9/32.png) [@MikeS](https://boards.straightdope.com/u/MikeS)\
**Post date:** [February 11, 2011, 2:49pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/4 "2011-02-11T14:49:51Z")

</div>

I don’t understand the rationale for the first quote either, but the second one seems straightforward enough. If you’re, say, a branch of Chase bank, and you hide your SSID, then someone malicious could set up another network called “ChaseWireless” nearby. Your customers might then assume that this was a secure connection, connect to it, and do their banking while connected. Except they’re not connecting to the official Chase website when they do so, but a phishing site instead. Hilarity ensues.

This isn’t really a concern for the average home user, though. It also wouldn’t be a concern if your users were smart about connecting to unknown wireless networks, but relying on people to make smart decisions is not a valid security strategy.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 11, 2011, 3:25pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/5 "2011-02-11T15:25:09Z")

</div>

> [@MikeS](#):
>
> I don’t understand the rationale for the first quote either.

The first quote is just explaining the general futility of hiding the SSID (basically, you can’t, because although you may hide it on the router, the client computer still broadcasts “Hey! [your SSID]! Are you there?” - and a would-be intruder can just pick it up from that.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [February 11, 2011, 3:42pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/6 "2011-02-11T15:42:52Z")

</div>

ETA: Ref **Mangetout** : I need to type faster or say less …

The point of this is NOT that disabling your home network SSID broadcast makes your home network less secure.

The point is that disabling your home network SSID broadcast makes your home \*laptop \*less secure when you take it out in public and try to connect to \*other \*networks.

In essence, your laptop keeps waving its keys around saying “Hey! Anybody here got a lock to fit this key?” And a bad guy can easily fashion such a lock in seconds and your laptop will glom onto it eagerly. Bad outcomes ensue.  
By setting your home network to broadcast SSID, you also indirectly unset the client laptop(s) from broadcasting the key they think of as home. And that’s where the security gain comes from.  
If you think about it, most of us are at far greater risk from hooking our laptop to an evil network in public than we are from having an evil laptop drive by our residence & hook to our network. Apartment or dorm dwellers might have nearly equal concerns in both directions.

If the only PCs you have never leave your house, then broadcasting or not of SSID is immaterial.

As others have said clearly above, lack of an SSID is about as effective at stopping drive-by hackers as removing the house numbers from your mailbox or front door is at stopping identity theft or burglary. Once the bad guys are parked outside, they already know where you live; the \*name \*of where you live isn’t necessary for them to do evil.

---

<div class="post-metadata">

**Author:** ![MuleSkinner](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@MuleSkinner](https://boards.straightdope.com/u/MuleSkinner)\
**Post date:** [February 11, 2011, 3:56pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/7 "2011-02-11T15:56:14Z")

</div>

> [@Mangetout](#):
>
> The first quote is just explaining the general futility of hiding the SSID (basically, you can’t, because although you may hide it on the router, the client computer still broadcasts “Hey! [your SSID]! Are you there?” - and a would-be intruder can just pick it up from that.

You’re saying it _still_ broadcasts “are you still there.” The first quote in the OP says “you are implicitly forcing your computer to shout out your SSID anywhere you are”, inferring that that is the danger of hiding your SSID.

The first quote used the second as a reference (click the little number 3 I included), so my guess is the author also didn’t understand what message was supposed to be conveyed and explained it wrong.

> [@LSLGuy](#):
>
> ETA: Ref **Mangetout** : I need to type faster or say less …
> 
> The point of this is NOT that disabling your home network SSID broadcast makes your home network less secure.
> 
> The point is that disabling your home network SSID broadcast makes your home \*laptop \*less secure when you take it out in public and try to connect to \*other \*networks.

The first quote was from an article about securing home networks. Maybe the author didn’t understand the point that was being made in his referenced quote and thought it was pertinent to securing a home network?

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 11, 2011, 5:27pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/8 "2011-02-11T17:27:12Z")

</div>

> [@LSLGuy](#):
>
> ETA: Ref **Mangetout** : I need to type faster or say less …
> 
> The point of this is NOT that disabling your home network SSID broadcast makes your home network less secure.
> 
> The point is that disabling your home network SSID broadcast makes your home \*laptop \*less secure when you take it out in public and try to connect to \*other \*networks.
> 
> In essence, your laptop keeps waving its keys around saying “Hey! Anybody here got a lock to fit this key?” And a bad guy can easily fashion such a lock in seconds and your laptop will glom onto it eagerly. Bad outcomes ensue.

Does it not do that regardless? (i.e. even if it’s looking for a connection which normally broadcasts the SSID?)

---

<div class="post-metadata">

**Author:** ![Jragon](https://avatars.discourse-cdn.com/v4/letter/j/e19b73/32.png) [@Jragon](https://boards.straightdope.com/u/Jragon)\
**Post date:** [February 11, 2011, 5:29pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/9 "2011-02-11T17:29:59Z")

</div>

It’s futile from a “protect me from hackers” standpoint, however, it makes sense from a home security standpoint if you ever have to turn off your password temporarily and don’t want your neighbor using your internet.

---

<div class="post-metadata">

**Author:** ![jasg](https://avatars.discourse-cdn.com/v4/letter/j/f0a364/32.png) [@jasg](https://boards.straightdope.com/u/jasg)\
**Post date:** [February 11, 2011, 8:54pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/10 "2011-02-11T20:54:10Z")

</div>

??? I understand the OP’s two links but it seems to me that if you are going to the trouble to hide your router’s SSID you would also block your laptop’s ability to remember and auto-connect to the hidden SSID.

If my laptop does not remember my SSID, I have to type it in - and why would I do that in an airport or coffee shop?

I’m not a networking engineer so what am I missing?

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 11, 2011, 9:09pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/11 "2011-02-11T21:09:56Z")

</div>

> [@jasg](#):
>
> ??? I understand the OP’s two links but it seems to me that if you are going to the trouble to hide your router’s SSID you would also block your laptop’s ability to remember and auto-connect to the hidden SSID.
> 
> If my laptop does not remember my SSID, I have to type it in - and why would I do that in an airport or coffee shop?
> 
> I’m not a networking engineer so what am I missing?

It should be possible to configure a wireless adaptor to connect, as long as the name is known (you should only have to type it in the once, when you set up the connection)

---

<div class="post-metadata">

**Author:** ![MuleSkinner](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@MuleSkinner](https://boards.straightdope.com/u/MuleSkinner)\
**Post date:** [February 11, 2011, 9:24pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/12 "2011-02-11T21:24:07Z")

</div>

> [@jasg](#):
>
> ??? I understand the OP’s two links but it seems to me that if you are going to the trouble to hide your router’s SSID you would also block your laptop’s ability to remember and auto-connect to the hidden SSID.

Not necessarily. In the guides for securing a wireless network that I’ve read so far, many have mentioned it’s a good idea to disable the broadcast of the SSID but haven’t mentioned making sure your wireless devices such as notebooks shouldn’t be set to remember to auto-connect to the hidden SSID. I had no idea that would be a risk, but I don’t connect to anything wirelessly outside of the home.

> [@Mangetout](#):
>
> It should be possible to configure a wireless adaptor to connect, as long as the name is known (you should only have to type it in the once, when you set up the connection)

**jasg** realizes that, hes’ asking why one wouldn’t go through the trouble to make sure it doesn’t auto connect when one has gone through the trouble to hide their SSID on their home network. I think he’s assuming one would necessarily realize it’s a security risk.

---

<div class="post-metadata">

**Author:** ![Kinthalis](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kinthalis/32/16084_2.png) [@Kinthalis](https://boards.straightdope.com/u/Kinthalis)\
**Post date:** [February 11, 2011, 9:33pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/13 "2011-02-11T21:33:12Z")

</div>

So it really doesn’t matter anyway. The whole spoof the SSID would still work even if you weren’t hiding it, right? Either your PC is shouting it, or your router is. Once someone knows it they could, conceivably spoof it, and have your PC log into their network, instead of yours, right? Regardless of whether you’re broadcasting it, or your PC is because your SSID is hidden, correct?

---

<div class="post-metadata">

**Author:** ![FatBaldGuy](https://avatars.discourse-cdn.com/v4/letter/f/ecd19e/32.png) [@FatBaldGuy](https://boards.straightdope.com/u/FatBaldGuy)\
**Post date:** [February 11, 2011, 10:17pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/14 "2011-02-11T22:17:25Z")

</div>

> [@Kinthalis](#):
>
> So it really doesn’t matter anyway. The whole spoof the SSID would still work even if you weren’t hiding it, right? Either your PC is shouting it, or your router is. Once someone knows it they could, conceivably spoof it, and have your PC log into their network, instead of yours, right? Regardless of whether you’re broadcasting it, or your PC is because your SSID is hidden, correct?

Not necessarily. As I understand from what’s been stated above, if your router broadcasts the SSID, a hacker would still need to figure out the password to get in. If your laptop is configured to auto-conneect, it is brodcasting the SSID and the password every time it tries to connect. Is this correct?

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 11, 2011, 10:18pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/15 "2011-02-11T22:18:04Z")

</div>

> [@MuleSkinner](#):
>
> **jasg** realizes that, hes’ asking why one wouldn’t go through the trouble to make sure it doesn’t auto connect when one has gone through the trouble to hide their SSID on their home network. I think he’s assuming one would necessarily realize it’s a security risk.

Ah, Thank you - I see it now. Yes - most people who hide their SSID probably do not know it’s unsafe to let their client machines remember it.

---

<div class="post-metadata">

**Author:** ![MuleSkinner](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@MuleSkinner](https://boards.straightdope.com/u/MuleSkinner)\
**Post date:** [February 12, 2011, 1:30am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/16 "2011-02-12T01:30:12Z")

</div>

I found the following which is basically a re-wording of the explanation given by **LSLGuy** :

> [@](#):
>
> **Hidden Wireless SSIDs Actually Leak Your SSID Name**
> 
> When you hide your wireless SSID on the router side of things, what actually happens behind the scenes is that your laptop or mobile device is going to start pinging over the air to try and find your router—no matter where you are. So you’re sitting there at the neighborhood coffee shop, and your laptop or iPhone is telling anybody with a network scanner that you’ve got a hidden network at your house or job.
> 
> Microsoft’s Technet explains exactly [why hidden SSIDs are not a security feature](http://www.howtogeek.com/howto/28653/debunking-myths-is-hiding-your-wireless-ssid-really-more-secure/), especially with older clients:
> 
> > [@](#):
> >
> > A non-broadcast network is not undetectable. Non-broadcast networks are advertised in the probe requests sent out by wireless clients and in the responses to the probe requests sent by wireless APs. Unlike broadcast networks, wireless clients running Windows XP with Service Pack 2 or Windows Server® 2003 with Service Pack 1 that are configured to connect to non-broadcast networks are constantly disclosing the SSID of those networks, even when those networks are not in range.
> > 
> > Therefore, using non-broadcast networks compromises the privacy of the wireless network configuration of a Windows XP or Windows Server 2003-based wireless client because it is periodically disclosing its set of preferred non-broadcast wireless networks.
> 
> The behavior is a little better in Windows 7 or Vista as long as you don’t have automatic connection enabled—the only way to be sure that you’re not leaking the network name is to disable automatic connection to wireless networks with a hidden SSID. Microsoft’s explanation:
> 
> > [@](#):
> >
> > The **Connect even if the network is not broadcasting** check box determines whether the wireless network broadcasts (cleared, the default value) or does not broadcast (selected) its SSID. When selected, Wireless Auto Configuration sends probe requests to discover if the non-broadcast network is in range.

[http://www.howtogeek.com/howto/28653/debunking-myths-is-hiding-your-wireless-ssid-really-more-secure/](http://www.howtogeek.com/howto/28653/debunking-myths-is-hiding-your-wireless-ssid-really-more-secure/)

---

<div class="post-metadata">

**Author:** ![JoelUpchurch](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@JoelUpchurch](https://boards.straightdope.com/u/JoelUpchurch)\
**Post date:** [February 12, 2011, 6:58am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/17 "2011-02-12T06:58:23Z")

</div>

> [@Mangetout](#):
>
> The first quote is just explaining the general futility of hiding the SSID (basically, you can’t, because although you may hide it on the router, the client computer still broadcasts “Hey! [your SSID]! Are you there?” - and a would-be intruder can just pick it up from that.

It seems to that hiding your SSID would give you more protection from war driving, assuming anyone still does that.

The strategy I use now is leaving my Wi-Fi turned off and just using hard wired connections. I had my house wired for Ethernet when it was built.

---

<div class="post-metadata">

**Author:** ![Crusoe](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Crusoe](https://boards.straightdope.com/u/Crusoe)\
**Post date:** [February 12, 2011, 9:58am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/18 "2011-02-12T09:58:51Z")

</div>

Hiding your SSID doesn’t protect you from war driving if the bad guy is remotely competent. They’d be using tools like NetStumbler or Kismet that couldn’t care less if your SSID is broadcasting or not.

I don’t know how common war driving is these days, but it’s certainly something companies care about and try to guard against, if my last two employers are typical.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 12, 2011, 11:31am UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/19 "2011-02-12T11:31:14Z")

</div>

> [@JoelUpchurch](#):
>
> It seems to that hiding your SSID would give you more protection from war driving, assuming anyone still does that.

I don’t think so, because as **Crusoe** says, anyone out to do that will probably know what they’re doing. It’s not really protection, because that should be taken care of by other measures - specifically strong encryption.

Hiding the SSID might stop your neighbours seeing your connection and casually trying to connect, but that’s irrelevant because again, the right and proper (and only truly reliable) way to shut them out is to employ strong encryption.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [February 12, 2011, 12:39pm UTC](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989/20 "2011-02-12T12:39:54Z")

</div>

The thing that confuses me is that I don’t change any settings on my laptop when I hide the SSID of a connection that’s already been established. So doesn’t that mean it’s broadcasting the same thing whether the SSID is on or off?

Of course I use all the other security options, but I don’t see why hiding the SSID hurts anything.

[Next page](https://boards.straightdope.com/t/securing-a-wireless-home-network-dont-disable-the-ssid-broadcast/570989.md?page=2)
