<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>Stephen Foskett, Pack Rat &#187; MAC address Archives  &#8211; Stephen Foskett, Pack Rat</title>
	<atom:link href="http://blog.fosketts.net/tag/mac-address/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fosketts.net</link>
	<description>Understanding the accumulation of data</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:40:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
			<item>
		<title>The Future of Home Storage</title>
		<link>http://blog.fosketts.net/2008/10/12/future-home-storage/</link>
		<comments>http://blog.fosketts.net/2008/10/12/future-home-storage/#comments</comments>
		<pubDate>Sun, 12 Oct 2008 19:00:00 +0000</pubDate>
		<dc:creator>Stephen</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Computer History]]></category>
		<category><![CDATA[Terabyte home]]></category>
		<category><![CDATA[AFP]]></category>
		<category><![CDATA[Apple Airport]]></category>
		<category><![CDATA[Apple TV]]></category>
		<category><![CDATA[Bonjour]]></category>
		<category><![CDATA[Buffalo]]></category>
		<category><![CDATA[DAAP]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[Firefly]]></category>
		<category><![CDATA[FireWire]]></category>
		<category><![CDATA[IP storage]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[LifeLine]]></category>
		<category><![CDATA[Linksys]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MAC address]]></category>
		<category><![CDATA[Mac Mini]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[nas storage]]></category>
		<category><![CDATA[NetGear]]></category>
		<category><![CDATA[network attached storage]]></category>
		<category><![CDATA[network storage]]></category>
		<category><![CDATA[NSLU2]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Retrospect]]></category>
		<category><![CDATA[Roku]]></category>
		<category><![CDATA[SAN]]></category>
		<category><![CDATA[SoundBridge]]></category>
		<category><![CDATA[storage area network]]></category>
		<category><![CDATA[Sunday series]]></category>
		<category><![CDATA[Time Capsule]]></category>
		<category><![CDATA[TwokyVision]]></category>
		<category><![CDATA[Untitled]]></category>
		<category><![CDATA[UPNP]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Western Digital]]></category>
		<category><![CDATA[Windows Home Server]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[XBox]]></category>
		<category><![CDATA[Ximeta]]></category>
		<category><![CDATA[Zetera]]></category>

		<guid isPermaLink="false">http://blog.fosketts.net/2008/10/12/the-future-of-home-storage/</guid>
		<description><![CDATA[Consumers demand friendly, flexible solutions. They don't want to fuss with their media, and they don't want simple shared storage. They want integration with multiple devices and flexibility to access their content on any device.]]></description>
			<content:encoded><![CDATA[<div id="attachment_861" class="wp-caption alignright" style="width: 235px;  border: 1px solid #dddddd; background-color: #f3f3f3; padding-top: 4px; margin: 10px; text-align:center; float: right;"><a href="http://blog.fosketts.net/wp-content/uploads/2008/10/img_0077.png" ><img class="size-medium wp-image-861 " title="Computer Closet" src="http://blog.fosketts.net/wp-content/uploads/2008/10/img_0077-225x300.png" alt="Homes now need data storage as well as closets..." width="225" height="300" /></a><p style=' padding: 0 4px 5px; margin: 0;'  class="wp-caption-text">Homes now need data storage as well as closets...</p></div>
<p style="padding-left: 30px;"><em>This is part of an ongoing </em><a href="http://blog.fosketts.net/tag/Sunday-series/"  target="_self"><em>series of longer articles I will be posting every Sunday</em></a><em> as part of an experiment in offering more in-depth content.</em></p>
<p>Along with my professional focus on enterprise storage systems, I&#8217;m enamored of home networking, and recently passed the three terabyte mark at home! This got me thinking about where home storage is heading.</p>
<p>As you can see in the photo, my office closet is overflowing with computer equipment (and one sweet guitar), but my data storage is much better organized. I have a <a href="http://blog.fosketts.net/2007/11/03/another-roku-soundbridge/"  target="_self">hacked Linksys NSLU2</a> with 500 GB as a file server, a <a href="http://blog.fosketts.net/2007/11/29/terabytes-on-the-cheap/"  target="_self">500 GB PC backup disk</a>, a 160 GB <a href="http://blog.fosketts.net/2008/07/26/move-os-x-time-machine-backups-new-disk/"  target="_self">Time Machine disk</a>, 1 TB of TiVo storage, and the rest. But wouldn&#8217;t it be nice if this could all be combined into some kind of super home server?</p>
<p><span id="more-616"></span></p>
<p><strong>Past Failures: Home Servers</strong></p>
<p>Home storage appliances and servers have come and gone over the year, with none seeming to make much of a mark. The market remains littered with UPNP media servers and home NAS boxes dashed on the shoals of an unappreciative public. Nearly every home network device company has produced one or two home storage servers, none of which have succeeded. Although I use a Linksys NSLU2 at home, I had to hack its Linux software and completely replace Linksys&#8217; features to create a useful device! The un-hacked NAS devices of Buffalo, Western Digital, Netgear, and the rest have generally failed to find buyers as well. So far, consumers seem content with simple USB and FireWire external drives.</p>
<p>The most adventurous home storage servers came from <a href="http://www.zetera.com/"  target="_blank">Zetera</a> and <a href="http://www.ximeta.com/web/products/"  target="_blank">Ximeta</a>, both of whom relied on proprietary IP SAN protocols. Note that these were SAN products, sharing block storage over Ethernet, rather than conventional NAS solutions. Both required drivers, limiting client support. The one Zetera buyer I know was pleased by the performance but never used the device as anything but a large hard drive for one PC.</p>
<p><div id="amazon-widget"><SCRIPT charset="utf-8" type="text/javascript" src="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&MarketPlace=US&ID=V20070822/US/bananafishhome/8001/8a642a12-1fa9-4b4e-b8a0-37493412621d"> </SCRIPT> <NOSCRIPT><A HREF="http://ws.amazon.com/widgets/q?ServiceVersion=20070822&MarketPlace=US&ID=V20070822%2FUS%2Fbananafishhome%2F8001%2F8a642a12-1fa9-4b4e-b8a0-37493412621d&Operation=NoScript">Amazon.com Widgets</A></NOSCRIPT></div></p>
<p>Then there is Microsoft. Recall that the latest Windows Home Server is only their latest attempt to enter this market, and yet I know of no one who has adopted the device. The same can be said of the various media center servers from Microsoft and others. At this point, it seems likely that the future of home storage servers will not come from Microsoft, though their two XBox generations have <a href="http://www.zatznotfunny.com/2008-09/cross-platform-xbmc-media-center-beta-released/"  target="_blank">great potential as clients</a>.</p>
<p>Even EMC has entered the market with their nifty (but largely unnoticed) <a href="http://www.emc.com/lifeline"  target="_blank">LifeLine</a> product and <a href="http://store.iomega.com/"  target="_blank">Iomega</a> acquisition. Supporting file services and backup for computers as well as audio and video for media players, EMC positions LifeLine much like their Retrospect backup product, but goes further in offering a complete software solution for hardware OEMs wanting to offer a non-Windows home server. Although <a rel="nofollow" href="http://thestorageanarchist.typepad.com/weblog/2008/07/1016-emc-lifeli.html"  target="_blank">an impressive offering</a>, it is too early to tell if EMC will have much success with this product.</p>
<p><strong>The Sleek, Shiny Elephant in the Living Room</strong></p>
<p>Of course, there is one company that sells media players and servers by the bushel, complete with sleek, shiny interfaces. Apple&#8217;s tremendous success with the iPod has led to their iTunes software becoming the <a href="http://blog.fosketts.net/2008/01/14/i-buy-cds-but-i-dont-listen-to-them/"  target="_self">dominant media organization platform</a>, complete with its own proprietary discovery and sharing protocol. Now, with the Apple TV and video iPods, the company is broadening into more media categories. Surely their dominance here puts them in a special position when it comes to setting the stage for a home server or storage revolution.</p>
<p>They also have a strong position in the world of dedicated home storage. Their Airport products are among the only routers to be widely implemented with shared storage. Although many other companies offer similar products, low customer understanding means that these functions are not widely used. And the new Time Capsule device is surely already the most widely-used home NAS product.</p>
<p>But Apple has not yet shown any home server strategy. Administering multiple iTunes servers can be frustrating for users, with no inter-iTunes synchronization or centralization capability. Although the Mac Mini, Apple TV, or Time Capsule could certainly be seen as a home server, the company does not position them as such in the market. Indeed, some iTunes users like myself rely on compatible third party media servers like Firefly and TwonkyVision rather than using iTunes itself. Still, <a href="http://www.tuaw.com/2008/09/22/what-is-the-brick"  target="_blank">rumors of an Apple home server persist</a>.</p>
<p>One issue for Apple is their reliance on proprietary protocols. Although the Bonjour discovery protocol is certainly simpler than UPnP in practice, Apple stands alone in relying on it. They also steadfastly stick to AFP for NAS and DAAP for remote media streaming. This limits the number of third-party clients and servers that can be used with their hardware and software.</p>
<p><strong>The Future is Friendly</strong></p>
<p>Although Apple has not yet tipped a home storage strategy beyond Time Capsule and Airport Extreme, they are best positioned to deliver a real home storage solution. A simple step would be to create an iTunes media server integrated with Time Capsule and add client/server media synchronization. The company already has OS X backup and file services integrated, and this move would further centralize the digital home around Apple products. But the company&#8217;s reliance on closed protocols like DAAP is worrisome, since it locks consumers into nearly all-Apple solutions.</p>
<p>Microsoft&#8217;s Media Center and Home Server combination, based around UPnP, shows great promise, with many compatible third-party clients and servers already available. But my own experience with the solution has not been at all positive (I still can&#8217;t get <a href="http://blog.fosketts.net/2007/12/17/no-more-cds/"  target="_self">my Roku SoundBridge</a>, Vista Ultimate laptop, and Media Center PC to see each other!), leading me to question the viability of this option.</p>
<p>Although Apple or Microsoft could come to dominate, I suspect the future of home storage is out of both companies hands. A number of others are working on improved home server experiences, including EMC&#8217;s LifeLine and the expanding use of Debian Linux and open source tools. But all could be sidelined by improved Internet-based services. Google, Microsoft, and Apple continue to expand their online consumer suites with greater storage, synchronization, multimedia integration, and all have the potential to reduce or eliminate the need for in-home storage.</p>
<p>Although I cannot yet tell which service will win, one thing is certain: Consumers demand friendly, flexible solutions. They don&#8217;t want to fuss with their media, and they don&#8217;t want simple shared storage. They want integration with multiple devices and flexibility to access their content on any device. The first company to offer a simple, flexible storage server for the home will surely be on the right track!</p>
<div id="crp_related"><h3>You might also want to read these other posts...</h3><ul><li><a href="http://blog.fosketts.net/2010/09/09/itunes-10-breaks-nonapple-streaming/"  rel="bookmark" class="crp_title">iTunes 10 Breaks Non-Apple Streaming (Again)</a></li><li><a href="http://blog.fosketts.net/2007/12/17/no-more-cds/"  rel="bookmark" class="crp_title">No More CDs</a></li><li><a href="http://blog.fosketts.net/2009/01/07/emc-iomega-relevant/"  rel="bookmark" class="crp_title">EMC Makes Iomega Relevant Again</a></li><li><a href="http://blog.fosketts.net/2007/06/21/my-terabyte-house/"  rel="bookmark" class="crp_title">My terabyte house</a></li><li><a href="http://blog.fosketts.net/2007/07/27/making-the-switch-to-digital-music-at-home/"  rel="bookmark" class="crp_title">Making the Switch to Digital Music at Home</a></li></ul></div><script src="http://feeds.feedburner.com/~s/sfoskett?i=http://blog.fosketts.net/2008/10/12/future-home-storage/" type="text/javascript" charset="utf-8"></script><hr />
<p><small>© sfoskett for <a href="http://blog.fosketts.net">Stephen Foskett, Pack Rat</a>, 2008. |
<a href="http://blog.fosketts.net/2008/10/12/future-home-storage/">The Future of Home Storage</a>
<br/>
This post was categorized as <a href="http://blog.fosketts.net/category/everything/apple/" title="View all posts in Apple" rel="category tag">Apple</a>, <a href="http://blog.fosketts.net/category/everything/computerhistory/" title="View all posts in Computer History" rel="category tag">Computer History</a>, <a href="http://blog.fosketts.net/category/everything/terabytehome/" title="View all posts in Terabyte home" rel="category tag">Terabyte home</a>. Each of my categories has its own feed if you'd like to filter out or focus on posts like this.<br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://blog.fosketts.net/2008/10/12/future-home-storage/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>MAC Addresses Are Bad Passwords</title>
		<link>http://blog.fosketts.net/2008/08/19/mac-addresses-bad-passwords/</link>
		<comments>http://blog.fosketts.net/2008/08/19/mac-addresses-bad-passwords/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 03:07:48 +0000</pubDate>
		<dc:creator>Stephen</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Terabyte home]]></category>
		<category><![CDATA[Cradlepoint]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[MAC address]]></category>
		<category><![CDATA[PHS300]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[Wi-Fi]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://blog.fosketts.net/?p=446</guid>
		<description><![CDATA[As I posted the other day, my new Cradlepoint PHS300 3G router is just awesome, and I would happily recommend it to anyone. If you do get one, however, be sure to change the default password immediately. The seemingly-strong password is worse than insecure &#8211; it&#8217;s available to anyone who asks whenever the router is [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_435" class="wp-caption alignright" style="width: 190px;  border: 1px solid #dddddd; background-color: #f3f3f3; padding-top: 4px; margin: 10px; text-align:center; float: right;"><a href="http://blog.fosketts.net/wp-content/uploads/2008/08/img_2073a.png" ><img class="size-medium wp-image-435 " title="Cradlepoint PHS300 and Novatel U720" src="http://blog.fosketts.net/wp-content/uploads/2008/08/img_2073a-300x209.png" alt="Sprint USB EV-DO + Cradlepoint personal hotspot = sweet!" width="180" height="125" /></a><p style=' padding: 0 4px 5px; margin: 0;'  class="wp-caption-text">Sprint USB EV-DO + Cradlepoint personal hotspot = sweet!Default password = bad!</p></div>
<p>As I posted the other day, <a href="http://blog.fosketts.net/2008/08/18/my-iphone-is-on-sprints-ev-do-network-and-so-are-my-pcs/"  target="_self">my new Cradlepoint PHS300 3G router is just awesome</a>, and I would happily recommend it to anyone. If you do get one, however, be sure to change the default password immediately. The seemingly-strong password is worse than insecure &#8211; it&#8217;s available to anyone who asks whenever the router is powered on!</p>
<p>Let&#8217;s back up, though. When I first set up the router, I was impressed by how simple it was. Turn it on and its Wi-Fi LAN appears almost immediately. Connect to the LAN and your browser is redirected to the router&#8217;s management interface (at 192.168.0.1).</p>
<p><span id="more-446"></span></p>
<p>I was happy to see that, unlike nearly all router manufacturers, <strong>Cradlepoint does not use a default password</strong>. Rather, each router has its own unique password &#8211; <strong>the last six hexadecimal characters of the MAC address, which is printed on a sticker on the bottom of the unit</strong>. At the time, this seemed much better than the big manufacturers, which tend to use the easily-guessable &#8220;admin&#8221; or another short, simple-to-crack word.</p>
<p>But the Cradlepoint <em>also</em> uses the last three characters of the MAC address as its default <strong>Wi-Fi SSID</strong>. So three of the password&#8217;s six characters are broadcast constantly to anyone who cares to see, regardless of whether they are even connected to the LAN! This literally makes the password 4,096 times easier to guess. My router&#8217;s SSID was &#8220;PHS-28a&#8221;, and the password was &#8220;02828a&#8221; &#8211; see the problem?  Amazingly enough, though, <strong>this isn&#8217;t the worst problem</strong>!</p>
<p>Most people know that DNS servers translate domain names (like &#8220;blog.fosketts.net&#8221;) into IP addresses (like &#8220;208.113.206.204&#8243;). But Ethernet networks (including Wi-Fi) use a different addressing scheme, and IP addresses themselves must be translated into a MAC address (like &#8220;00:30:44:02:82:8a&#8221;) before it can transmit data. Any connected client can use a command line program called arp to look up a MAC address, which means they can simply ask the router for the MAC thus discover the password. See my password in that example? But wait, it gets worse still!</p>
<p>Cradlepoint suggests setting a connection password, which will keep people from using its 3G connection but will do nothing to prevent them from using arp to find out the router&#8217;s password. Smarter people will turn off the SSID broadcast or use a WEP password, which will keep them from connecting to the router&#8217;s Wi-Fi network. Although this will stop the arp attack, the password is <em>still</em> vulnerable. See, the address is included as part of every Wi-Fi packet in plaintext, and as any wardriver will tell you, it&#8217;s simple to snoop on Wi-Fi packets. So the router is continually transmitting its password, whether one is connected or not. One would need to figure out the WEP password in order to connect, but there are techniques that allow this, and the attacker would then be able to use the administrator password to reconfigure the router.</p>
<p>The Cradlepoint also supports WPA/WPA2, which is <em>much</em> more secure than WEP and would dramatically improve the situation, but not all devices support it. But the real solution is much simpler &#8211; <strong>change the administrator password to something much more secure</strong>. Sadly, most people won&#8217;t do any of this &#8211; they&#8217;ll leave the password as it is and thus leave their router totally open to attack.</p>
<p>But let me just take a moment to beg those who read this post: <strong>Don&#8217;t ever use a MAC address as a password</strong>!</p>
<div id="crp_related"><h3>You might also want to read these other posts...</h3><ul><li><a href="http://blog.fosketts.net/2008/09/03/att-down-sprint-ev-do/"  rel="bookmark" class="crp_title">AT&#038;T Down, Sprint Saves My Bacon</a></li><li><a href="http://blog.fosketts.net/2011/03/02/cradlepoint-phs300-3g-router/"  rel="bookmark" class="crp_title">Get a Cradlepoint PHS300 Portable 3G WiFi Router For Just $79!</a></li><li><a href="http://blog.fosketts.net/2010/12/14/cradlepoint-phs300-portable-3g-wifi-router-99/"  rel="bookmark" class="crp_title">Get a Cradlepoint PHS300 Portable 3G WiFi Router For Just $99!</a></li><li><a href="http://blog.fosketts.net/2008/08/18/iphone-on-sprint-ev-do/"  rel="bookmark" class="crp_title">My iPhone is on Sprint&#8217;s EV-DO Network (and So Are My PCs!)</a></li><li><a href="http://blog.fosketts.net/2009/11/30/configure-drobo-dashboard-email-gmail-google-apps/"  rel="bookmark" class="crp_title">How To Configure Drobo Dashboard Email for Gmail and Google Apps</a></li></ul></div><script src="http://feeds.feedburner.com/~s/sfoskett?i=http://blog.fosketts.net/2008/08/19/mac-addresses-bad-passwords/" type="text/javascript" charset="utf-8"></script><hr />
<p><small>© sfoskett for <a href="http://blog.fosketts.net">Stephen Foskett, Pack Rat</a>, 2008. |
<a href="http://blog.fosketts.net/2008/08/19/mac-addresses-bad-passwords/">MAC Addresses Are Bad Passwords</a>
<br/>
This post was categorized as <a href="http://blog.fosketts.net/category/everything/apple/" title="View all posts in Apple" rel="category tag">Apple</a>, <a href="http://blog.fosketts.net/category/everything/terabytehome/" title="View all posts in Terabyte home" rel="category tag">Terabyte home</a>. Each of my categories has its own feed if you'd like to filter out or focus on posts like this.<br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://blog.fosketts.net/2008/08/19/mac-addresses-bad-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

