Computerworld
Security fears nix cancer center wireless plan
Bob Brewin  30 August, 2001 08:21

The MD Andersen Cancer Center in Houston last week abruptly put an 18-month effort to provide wireless LAN access to 11,000 users on its five building campus on hold due to security concerns.

Ernest Teves, research and development director at the facility, said research has shown "it is so easy to crack" the built-in security of industry standard 802.11B wireless LANs, the Wired Equivalent Protocol (WEP). Speaking here at a Delphi Group wireless conference yesterday, Teves said that as a result of that research -- some of which was conducted by a student at Rice University, located just five minutes from the center -- he decided to put the ambitious wireless LAN project on hold.

Teves said he doesn't believe WEP will meet the stringent security requirements of the federal Health Insurance Portability and Accountability Act (HIPAA). He said he has asked Cisco Systems Inc. in San Jose, which has already performed an extensive site survey of the MD Andersen campus, to help beef up security.

Additional security measures, Teves said, could throttle down real throughput on the wireless LAN from 7M bit/sec to 4M bit/sec. If that's true, Teves said, the wireless LAN installation could be stalled until manufacturers release products that provide 54M bit/sec raw throughput in the 2.4-GHz frequency band, an industry standard known as 802.11g.

John Pescatore, an analyst at Gartner Inc. in Stamford, Conn., said security concerns about wireless LANs and WEP are justified because of the vulnerability of the over-the-air interface.

"Our basic advice to clients is to treat wireless like the Internet, not like a LAN. Encrypt the data you send over it. Firewall your connection to it. Essentially, run a [virtual private network] or [Secure Sockets Layer] over all connections over WLANs until second-generation standards are stable," which will probably be in the first quarter of 2003, he said.

C. Brian Grimm, a spokesman for the Wireless Ethernet Compatibility Alliance (WECA) in Mountain View, Calif., said that since HIPAA requires end-to-end security, running a VPN would satisfy any concerns a health care provider would have about WEP.

Phil Belanger, marketing director for WECA, said the industry group also recommends additional security measures, such as a VPN.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Discussions on Security
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Understanding Email Marketing: A Guide for SMBs

Email marketing is often viewed as a marketers silver bullet. If used effectively, email campaigns will provide strong results for a limited spend each and every time. Download this white paper to discover how email marketing can work for you and your business.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.