# Wireless routers--I admit I'm an idiot.

**URL:** <https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260>\
**Category:** Factual Questions\
**Created:** [May 4, 2010, 5:13am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260 "2010-05-04T05:13:26Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![hellpaso](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@hellpaso](https://boards.straightdope.com/u/hellpaso)\
**Post date:** [May 4, 2010, 5:13am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/1 "2010-05-04T05:13:26Z")

</div>

Inspired by Zsofia’s thread. I have a TWC Roadrunner wireless router. It consistently knocks me off the internet, and shows up as an “unsecured connection”. I’ve had it 3 years. I had my laptop hooked up to a hotel network a couple of weeks ago, with no interruption in service.

I’m thinking (in my totally computer-ignorant mind) that I might need a new wireless router. Please forgive my ignorance (fight it!). Do I have to go through TWC to get a new router? Or can I buy one on Amazon and get it to work with my wireless connection?

My kids (adults) were visiting a few weeks back and were appalled that my connection was not “secured”. Help me–help me!!!:o

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [May 4, 2010, 7:29am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/2 "2010-05-04T07:29:35Z")

</div>

An unsecured connection means that anyone can connect to it and use your bandwidth. Someone could be browsing kiddie porn and it would show up as you.

Your router will have a configuration page. Normally [http://192.168.0.1](http://192.168.0.1) - but it could be different. Look in there and attend to the following:

SSID: Give it a unique name (e.g. hellpasowireless).  
SSID Broadcast: turn this **off**. This stops it from advertising its presence. You have to know that it’s there. You may want to change the channel too.  
Security: set this to WPA or WPA2 to encrypt the traffic between your laptop and the router. Otherwise someone can monitor what you’re doing e.g. steal your credit card info. You should have to have a pass phrase - necessary the first time people connect. No one can connect and use your bandwidth unless they know the name of the wireless link (the SSID), and the pass phrase.

For the tightest security turn on MAC address filtering and plug in the MAC address - those 12 hex digits - of your laptop. This will mean that only a device with the same MAC address as your laptop can connect to the router. This usually means only your laptop.

---

<div class="post-metadata">

**Author:** ![Earl\_E.Bird](https://avatars.discourse-cdn.com/v4/letter/e/c67d28/32.png) [@Earl\_E.Bird](https://boards.straightdope.com/u/Earl_E.Bird)\
**Post date:** [May 4, 2010, 9:43am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/3 "2010-05-04T09:43:49Z")

</div>

You should definitely secure your wireless router. Three words: encryption, encryption, encryption.

To keep out random strangers passing by: turn on WEP, WPA or WPA2.  
Yes, WEP. WEP encryption is cracked in just minutes, but you need to make an effort to do it. It will keep out casual passers-by, and gives much better security than MAC filtering or SSID hiding.

To keep out persistent hackers: Turn on WPA or WPA2. Choose a good pass phrase.

Please, please, please forget SSID hiding and MAC filtering, it does not improve security at all, and is easily defeated by hackers. What’s worse, it gives you a false sense of security, making you think that you have real security when you do not.

[Wireless LAN security hall of shame](http://blogs.zdnet.com/Ou/index.php?p=43)

- MAC filtering
- SSID hiding
- LEAP authentication
- Disable DHCP

[Wireless LAN security myths that won’t die](http://blogs.zdnet.com/Ou/?p=454)

> [@](#):
>
> Rock solid wireless LAN security for the home or small office can be summed up in a single paragraph. All you need to do is use WPA-PSK security with a random alpha-numeric pass-phrase that has a minimum of 10 characters.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [May 4, 2010, 11:53am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/4 "2010-05-04T11:53:36Z")

</div>

> [@Earl\_E.Bird](#):
>
> Please, please, please forget SSID hiding and MAC filtering, it does not improve security at all,

Not true: they give would-be malefactors two more hurdles to jump. Sure they may be relatively easy to circumvent, but they’ve still got to be circumvented. A set-up like the OP’s isn’t going to resist the determined hacker. It’s the casual ones against whom he needs to guard, and both of these are good in that regard.

---

<div class="post-metadata">

**Author:** ![Earl\_E.Bird](https://avatars.discourse-cdn.com/v4/letter/e/c67d28/32.png) [@Earl\_E.Bird](https://boards.straightdope.com/u/Earl_E.Bird)\
**Post date:** [May 4, 2010, 2:57pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/5 "2010-05-04T14:57:02Z")

</div>

> [@Quartz](#):
>
> Not true: they give would-be malefactors two more hurdles to jump. Sure they may be relatively easy to circumvent, but they’ve still got to be circumvented. A set-up like the OP’s isn’t going to resist the determined hacker. It’s the casual ones against whom he needs to guard, and both of these are good in that regard.

But there’s absolutely no point in doing it. A casual passer-by is stopped by any kind of encryption, even WEP. And encryption is needed to keep out the determined hackers, anyway. Encryption is like locking the door. SSID hiding is like slapping a Post-It note over the keyhole.

You didn’t read [this](http://blogs.zdnet.com/Ou/?p=454), did you?

> [@](#):
>
> ```
> * What's the harm? It's a layered approach to security.
> * It makes us harder to see and hack.
> 
> ```
> 
> The problem with these arguments is that they’re based on some fundamentally wrong assumptions and an inadequate knowledge of how wireless LAN security works.
> 
> ```
> * These aren't layered approaches; they're more like buying overlapping warranty coverage, since any benefit against casual bandwidth thieves is already covered by real security measures. **The harm is that people confuse these methods for the real thing, and they spend more money and resources on implementing the wrong security mechanisms and end up skimping on real security.**
> * They don't make you harder to hack. Kismet, which is a free utility, will reveal so-called hidden SSIDs, MAC addresses, and static IP schemes within seconds of scanning the airwaves, sending all that money and time spent on MAC address and static IP management down the toilet. 
> 
> ```

My bolding.

I can (and do) sniff out hidden SSIDs with my _iPod Touch_. Yes, the MAC addresses are there, too. Free and legal program.

MAC filtering and SSID hiding has become a pet peeve of mine. That is because it is not real security, and really should not be presented as such.

And if you’re concerned that your SSID is being broadcast to the world, then you should know that your laptop is broadcasting that very same SSID when you’re on vacation in Aruba.

> [@](#):
>
> I’ve added SSID beacon suppression to the list of “worse than no wireless security at all” because it forces you to spew your wireless LAN configuration from your laptop everywhere you go. Security researcher Joshua Wright recently highlighted these dangers in this article. The problem with turning off SSID beaconing on your access point is that not only is it worthless, since the SSIDs are still easily detectible over the air, but it also forces your laptops to probe for the SSID. That means that all of your laptops will run around the world broadcasting your SSID, which opens them up to data seepage or even evil twin attacks.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [May 4, 2010, 4:32pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/6 "2010-05-04T16:32:29Z")

</div>

> [@Earl\_E.Bird](#):
>
> I can (and do) sniff out hidden SSIDs with my _iPod Touch_. Yes, the MAC addresses are there, too. Free and legal program.

You’re making my point for me. You have an app that does it. Someone who doesn’t have such an app is stymied. As I said, the OP’s setup isn’t going to resist the determined hacker. It’s the casual one, the bandwidth thief or the snooper, that’s the target here.

---

<div class="post-metadata">

**Author:** ![brad\_d](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@brad\_d](https://boards.straightdope.com/u/brad_d)\
**Post date:** [May 4, 2010, 4:57pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/7 "2010-05-04T16:57:32Z")

</div>

I once tried disabling SSID broadcast on my wireless router (while plugged in with a cable), and then could not figure out how to connect to the network wirelessly _myself_. After a few go-rounds of this, I plugged the cable in, turned SSID broadcasting back on, and went on with my life.

This was a couple of years ago on a Windows XP Home machine. I’ve since read several opinions like **Earl E. Bird** ’s suggesting that it wouldn’t have been beneficial anyway, so I have not pursued the matter further.

But…was I being a complete idiot then, when I was unable to connect? It sure felt that way…

---

<div class="post-metadata">

**Author:** ![Dag\_Otto](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Dag\_Otto](https://boards.straightdope.com/u/Dag_Otto)\
**Post date:** [May 4, 2010, 6:40pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/8 "2010-05-04T18:40:09Z")

</div>

> [@Quartz](#):
>
> You’re making my point for me. You have an app that does it. Someone who doesn’t have such an app is stymied. As I said, the OP’s setup isn’t going to resist the determined hacker. It’s the casual one, the bandwidth thief or the snooper, that’s the target here.

I think you are missing the point: WPA or WPA2 stops the casual person also, so why bother with the other items? Put up the big wall and be done with it.

---

<div class="post-metadata">

**Author:** ![Earl\_E.Bird](https://avatars.discourse-cdn.com/v4/letter/e/c67d28/32.png) [@Earl\_E.Bird](https://boards.straightdope.com/u/Earl_E.Bird)\
**Post date:** [May 4, 2010, 7:55pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/9 "2010-05-04T19:55:54Z")

</div>

> [@Quartz](#):
>
> As I said, the OP’s setup isn’t going to resist the determined hacker. It’s the casual one, the bandwidth thief or the snooper, that’s the target here.

Are you suggesting using no encryption at all and only use SSID hiding and MAC filtering? Because that will indeed keep out the most casual of casuals, but still give full access to any half-baked hacker and 14-year-old script-kid in the neighbourhood in less than 20 seconds. If that is what the OP wants, then that is the way to do it.

The TWC Roadrunner has WEP encryption or better. **With WPA encryption, the OP _is_ going to resist the determined hacker.**

> [@brad\_d](#):
>
> I once tried disabling SSID broadcast on my wireless router (while plugged in with a cable), and then could not figure out how to connect to the network wirelessly _myself_.

Yes, you have to do a few extra steps. I initially did this, too, and it was just a royal pain in the butt. Which is why SSID hiding and MAC filtering should never be used. The time and resources wasted on faux security is much better spent on real security.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [May 4, 2010, 10:25pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/10 "2010-05-04T22:25:53Z")

</div>

> [@Earl\_E.Bird](#):
>
> Are you suggesting using no encryption at all and only use SSID hiding and MAC filtering?

If you’d spent more than 2 seconds reading post #2 instead of latching on to your hobbyhorses you’d have spotted this:

> [@Quartz](#):
>
> Security: set this to WPA or WPA2 to encrypt the traffic between your laptop and the router.

---

<div class="post-metadata">

**Author:** ![hellpaso](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@hellpaso](https://boards.straightdope.com/u/hellpaso)\
**Post date:** [May 5, 2010, 3:20am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/11 "2010-05-05T03:20:20Z")

</div>

Thanks for all the responses. But my question was, could I just buy a better router online and use it with my current provider. Told you I was ignorant. But I figure if I could buy a better router, that wouldn’t kick me offline every 20 minutes, I could set it up properly. I’m not worried about cost. (I have a PC)

---

<div class="post-metadata">

**Author:** ![Earl\_E.Bird](https://avatars.discourse-cdn.com/v4/letter/e/c67d28/32.png) [@Earl\_E.Bird](https://boards.straightdope.com/u/Earl_E.Bird)\
**Post date:** [May 5, 2010, 7:12am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/12 "2010-05-05T07:12:46Z")

</div>

> [@Quartz](#):
>
> If you’d spent more than 2 seconds reading post #2 instead of latching on to your hobbyhorses you’d have spotted this:

Then why are you blathering on about SSID hiding and MAC filtering when it adds abso-frickin-lutely nothing except being a huge waste of time? 😕 Do you claim to have superior knowledge of Wi-Fi security to that of George Ou, Microsoft, and Robert Moskowitz, senior technical director at ICSA Labs? Yes, they all advice _against_ SSID hiding.

Seriously, if anyone saddled up any hobbyhorses in this thread, you set an example. :rolleyes:

EOD, and welcome to my ignore list.

To the OP: My apologies for being partly responsible for derailing this thread.

Back on topic: I suggest contacting your internet provider and ask them. Not all routers are created equal, and the one you grab off eBay or wherever may not be compatible. WPA encryption is a must. WPA2 is arguably better, but at least my iPod Touch refuses to play nice with it.

With just WPA or WPA2 encryption and a good pass phrase you will keep out just about the whole dang world. And by giving that pass phrase to select friends and/or family, it will be dead simple to share your Wi-Fi connection with them.

---

<div class="post-metadata">

**Author:** ![CanvasShoes](https://avatars.discourse-cdn.com/v4/letter/c/74df32/32.png) [@CanvasShoes](https://boards.straightdope.com/u/CanvasShoes)\
**Post date:** [May 5, 2010, 7:21am UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/13 "2010-05-05T07:21:50Z")

</div>

Sounds like everyone else here has superior router knowledge over my baby geek status. I would add one small thing though, I’ve had the WORST luck with Linksys routers (as have other people I know).

Good luck!

---

<div class="post-metadata">

**Author:** ![minor7flat5](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/minor7flat5/32/258_2.png) [@minor7flat5](https://boards.straightdope.com/u/minor7flat5)\
**Post date:** [May 5, 2010, 12:20pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/14 "2010-05-05T12:20:53Z")

</div>

Make sure that the problem is not radio interference.

Is there a way to know if wired connections to the same router are still happy while the wireless connection is down?

Most routers come set for channel 6 out of the box. Most folks who change this go for either 1 or 11, to distance themselves from the rest of the crowd.  
You can use a freeware wifi detection app to see what different wireless networks are running in your area, their signal strength, and their channels.

Note that devices such as microwave ovens do affect wifi.

About replacing the router…

What kind of Internet service do you have (cable, satellite, dsl)?  
Is there another box between your current router and the service entry point in your home?

Some ISPs provide a company-branded device that contains modem + firewall + switch + wireless access point. If yours is one of these, then you cannot just replace it with your own device. You would need to talk to the ISP and see if they could provide a new box.  
With such a all-in-one box, you can piggyback your own wifi router on top of it, but there are network details you would need to iron out.

I am firmly against the “hide SSID + use MAC filtering” point of view, FWIW. These are the flimsiest excuse for security and all they do is make your own life harder, while giving you a false sense of security.  
As you pointed out, hiding the SSID made it difficult to configure your other devices. Indeed, I have some devices at home that won’t find the network at all unless the SSID is turned on at least for a moment.

Networking problems are challenging enough to figure out, so it makes it easier if you eliminate unneeded complexities. Imagine sending your computer to the shop for repair and then wasting four hours trying to figure why you couldn’t connect to the Internet, not considering that the new network card they swapped in would have a different MAC address?

Besides, the SSID broadcast allows you to send cute, [passive-aggressive messages](http://www.huffingtonpost.com/2010/01/22/funny-wifi-names-the-most_n_432712.html) to your neighbors.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [May 5, 2010, 2:55pm UTC](https://boards.straightdope.com/t/wireless-routers-i-admit-im-an-idiot/538260/15 "2010-05-05T14:55:18Z")

</div>

> [@Earl\_E.Bird](#):
>
> …Do you claim to have superior knowledge of Wi-Fi security to that of George Ou, Microsoft, and Robert Moskowitz, senior technical director at ICSA Labs? Yes, they all advice _against_ SSID hiding.  
> …

I know this is off-topic, but George Ou’s name doesn’t really help your position. He’s a writer, not a technical person, and I’ve read articles and subsequent comments that really exposed a basic lack of understanding of the topics he was writing about (one that comes to mind was about Sun T2 processor).

Edit: not disagreeing with your point, just making a point about one of the people you listed
