{"id":237960,"date":"2017-11-28T14:58:06","date_gmt":"2017-11-28T12:58:06","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=237960"},"modified":"2017-11-28T14:59:25","modified_gmt":"2017-11-28T12:59:25","slug":"how-vast-ensures-its-wi-fi-network-is-secure","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/wireless\/237960-how-vast-ensures-its-wi-fi-network-is-secure.html","title":{"rendered":"How VAST ensures its Wi-Fi network is secure"},"content":{"rendered":"<p>VAST\u2019s hotspots do not use Wi-Fi Protected Access (WPA) or similar security, but that does not mean they are unsecure.<\/p>\n<p>This is according to the CEO of VAST Networks, Grant Marais. \u201cWe run a feature called client isolation,\u201d said Marais.<\/p>\n<p>If you run a scan on the network, it will look like you are the only user. The only devices you would see is your own and the gateway.<\/p>\n<p>\u201cWe also run a Generic Routing Encapsulation (GRE) tunnel from the access point to our gateway.&#8221;<\/p>\n<p>A GRE tunnel is a protocol developed by Cisco which can carry different passenger protocols.<\/p>\n<p>These tunnels are virtual point-to-point links, which means every user has their own \u201clane\u201d for data traffic.<\/p>\n<p>Marais said VAST also uses a pop-up login and has mechanisms to identify users which want to use the network for malicious purposes.<\/p>\n<p>You can\u2019t use the network without authenticating, and new subscribers have to input a one-time PIN sent to their cellphone number to create an account.<\/p>\n<p>This means a VAST Wi-Fi account is linked to a payment method and a valid cellphone number, which should be RICA registered.<\/p>\n<p>The pop-up login has the additional benefit of ensuring subscribers won\u2019t connect to VAST\u2019s hotspots and lose throughput on their device if their Wi-Fi package expires, said Marais.<\/p>\n<h3 class=\"my-4\">KRACK<\/h3>\n<p>VAST also stays abreast of new security threats, such as the <a href=\"https:\/\/mybroadband.co.za\/news\/security\/234038-krack-vulnerability-what-you-need-to-know.html\"><strong>key reinstallation attacks (KRACKs)<\/strong><\/a> recently found in the WPA2 standard.<\/p>\n<p>Marais said that in this instance, they have the benefit of not using WPA2 on their public network.<\/p>\n<p>However, in isolated networks such as the one they operate for Netcare, they do use WPA2 &#8211; but not features like fast roaming that allow for KRACKs to be used.<\/p>\n<p>\u201cThe density of our network is such that we don\u2019t have to run fast roaming,\u201d said Marais.<\/p>\n<p>He said there are also several security settings you need to leave \u201cunticked\u201d for KRACKs to be effective.<\/p>\n<p>VAST deployed manufacturer patches to combat the attack, however, in case it needs to run WPA2 on its consumer network in the future.<\/p>\n<p>Another step VAST takes to secure its network is using access control lists.<\/p>\n<p>This ensures that only network elements it trusts will work when plugged into the core network.<\/p>\n<p>\u201cIf you plug in anything on our network, you wouldn\u2019t be able to see any traffic or connect to the Internet,\u201d said Marais.<\/p>\n<p>To test this and other security measures on the network, VAST procures the services of SensePost for penetration testing.<\/p>\n<p>Marais said he does not believe any system is invincible against attacks, with tech giants like Yahoo and LinkedIn falling victim to malicious players in the past.<\/p>\n<p>\u201cUnfortunately, there are a lot of malicious people [out there], but we are taking all the steps we\u2019re able to to mitigate the effects.&#8221;<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/233439-krack-wi-fi-hack-devastating-to-android-and-linux.html\">KRACK Wi-Fi hack \u201cdevastating\u201d to Android and Linux<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>VAST\u2019s hotspots do not use WPA, but they are secure, said the company.<\/p>\n","protected":false},"author":15,"featured_media":237962,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27,13],"tags":[36888,35,19544,45436,36886],"class_list":["post-237960","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-wireless","tag-grant-marais","tag-headline","tag-sensepost","tag-vast","tag-vast-networks"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/237960"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=237960"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/237960\/revisions"}],"predecessor-version":[{"id":238828,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/237960\/revisions\/238828"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/237962"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=237960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=237960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=237960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}