Hidden SSIDs. Safe or not?

Posted by: Taym

Hidden SSIDs. Safe or not? - 05/04/2011 06:57

What is you opinion on safety of Hidden SSIDs?

There's some debate on line on whether hidden SSID is actually safer than broadcasting SSID, the argument against hidden being that while it is not being broadcasted by the WAPs, it is instead being broadcasted by clients looking for it, essentially; so, unless you have no legitimate client around, which in most organizations is extremely unlikely, there's no increased safety, and some claim there's LESS of it.
Of course, data security is in encryption, but what do you think specifically of hidden SSIDs? Does it really add some security or not, in your view?
Posted by: Shonky

Re: Hidden SSIDs. Safe or not? - 05/04/2011 07:51

It only prevents a very casual hacker from seeing it. And that's not even really a hacker. That's just someone nearby looking for free internet most likely. Anyone who wants to will be able to see it. I believe it's very easy to find it if you have the right tools.

For the added overhead (adding it manually) it's not worth the effort IMO. Just leave it on and make sure you use the best security (i.e. not WEP) your hardware/drivers can handle.
Posted by: tman

Re: Hidden SSIDs. Safe or not? - 05/04/2011 21:14

I leave it on. Disabling SSID broadcasts breaks more stuff than its worth.

There is the client broadcast issue which also means laptops taken away from the network will continue to be broadcasting your SSID.

Some equipment just doesn't like the fact SSIDs aren't broadcast and take a long time to discover or even never discover the network.
Posted by: drakino

Re: Hidden SSIDs. Safe or not? - 05/04/2011 21:53

Free Public WiFi
Posted by: frog51

Re: Hidden SSIDs. Safe or not? - 06/04/2011 07:51

There is no real security benefit - all security/hacking tools for wireless will still find it (the SSID is still broadcast, just not with every beacon frame, which is why it upsets some clients which timeout before grabbing it)

I say enable it and rely on WPA2/TKIP plus MAC address filtering, and if you are really concerned enable a VPN over that:-)
Posted by: Taym

Re: Hidden SSIDs. Safe or not? - 10/04/2011 14:08

I am now broadcasting one of our 9 SSIDs, and all is fine (of course). I will probably start broadcassting the others if that is needed.
The fun part is that now at work we all seem to agree that hidden SSID is not useful.

I had never looked into this before, and just assumed, without data, that we were hiding it for security reasons. Once I looked into it, and asked you all, I can't find a reason why SSID should be hidden, and nobody in our organization even remembers why SSIDs were hidden in the first place. smile
Posted by: Shonky

Re: Hidden SSIDs. Safe or not? - 11/04/2011 00:21

I'd guess that at some point, someone read something that (misleadingly) said hiding SSIDs would increase security. Or they decided themselves it would increase security.

It is fairly well accepted that it's of no use. That said, I work for one of the largest companies in the world and they insist on hiding SSIDs. They also force other "security" policies that provide little to no benefit or simply don't make sense.
Posted by: frog51

Re: Hidden SSIDs. Safe or not? - 12/04/2011 08:51

Originally Posted By: Shonky
I work for one of the largest companies in the world and they insist on hiding SSIDs. They also force other "security" policies that provide little to no benefit or simply don't make sense.


Sounds like the majority of my Fortune 350 client base :-)

They can be moved but it's like turning a supertanker.
Posted by: Taym

Re: Hidden SSIDs. Safe or not? - 05/05/2011 19:31

... so, after 1 month of SSID broadcasting, we're not having any issue anymore with those devices - iPhones mostly - which would not work nicely with hitten Sdids.

Also, WP7 has now a dedicated thrid party App that allows using hidden SSIDs. It seems to work, but not 100% reliabily.