CamerasReviewsShopBusinessHelpNewsHandheldsGameSpotNotebooksDownloadsDeveloper
Developer
• New Best Buys

• Dell Small Business

• Free Downloads
 
ZDNet> Developer> Security>WLANS Too

Click here!

Search For:     Search Tips
Power Search
Developer Home
Pick a Topic:

Coding
HTML
CSS/Fonts
JavaScript
DHTML
XML
CGI/Perl/TCL
ASP
ActiveX
Java

Design
Usability
Accessibility
Graphics
Multimedia
Standards

Backend
Management
Networking
Security
Databases
Servers
Community
Web Hosting

Resources
ScriptLibrary
Tag Library
Free Downloads
Dev Forums
Look up a Domain
Free Web Tools
GIFBot
SmartPlanet
Get Our Newsletter

Click here!


Security
clear
M-commerce Security a Moving Target
WLANS Too
clear

eWEEK Even enterprises that haven't started giving outside customers wireless access to their networks are developing wireless security strategies. VF, the $6 billion manufacturer of such apparel as Lee and Wrangler jeans, isn't selling pants online, but it has rolled out a WLAN. Machine operators on VF's manufacturing floor use handheld devices from Symbol Technologies Inc. to access the company's SAP AG enterprise resource planning applications.
 
 

To keep the whole thing secure, Mel Cartwright, VF's project leader for radio frequency scanning, in Greensboro, N.C., uses a combination of tried-and-true password management techniques, and he keeps a tight lid on where and by whom wireless devices are used. The company's handhelds never leave the premises. Every operator has his or her own machine and is required to scan in a personal bar code just to get a user ID prompt. The security doesn't stop there. Each user ID associated with a password has to be changed every 30 days, and it must contain a specific number of capital letters and numbers. Then, to get into VF's SAP application, the user must enter a different user ID and password combination. 

Users are reminded every 14 days to change passwords before the 30-day deadline. And, as with any password—whether it's for wireless devices or not—Cartwright and VF's security managers enforce rules that prohibit users from writing down passwords. VF also conducts routine internal security audits to make sure everything's secure. 

The system, of course, is a recipe for forgotten passwords. But, Cart wright said, it's worth it. "The No. 1 problem our help desk deals with is forgotten passwords," he said. "But it's justifiable because this ensures that proprietary information remains in-house." 

Faced with the complex task of tracking rapidly changing wireless standards and providing security for a profusion of wireless devices, some enterprises are opting to hand the problem to a service provider. John Shields, vice president of wireless initiatives at Patelco, for example, recently chose to outsource his company's wireless implementation and security to MShift Inc., in San Jose, Calif. With $1.9 billion in assets, San Francisco-based Patelco is California's fourth-largest credit union. Patelco launched its wireless banking application in November and recorded more than 1,000 log-ons that month. 

While Patelco has internal expertise in HTML and online content delivery, Shields said, it lacked WAP expertise. Shields told his managers he feared that, as wireless devices proliferated, he'd eventually have to support multiple protocols. He also worried that as an increasing number of applications were wireless-enabled, Patelco would run into trouble guaranteeing security on all of them. In the end, Shields persuaded his managers to buy rather than build a secure mobile infrastructure. 

"WAP protocol is relatively new to us, and there are so many wireless devices you have to keep on top of," Shields said. "Partly because of security concerns, our executives understood why outsourcing was right for us." 

MShift's wireless implementation for Patelco uses WTLS, SSL and digital certificates to protect sensitive data. Patelco, on its end, secures every transaction internally with 128-bit encryption behind a corporate firewall. Patelco also controls what its wireless users can and cannot do. For instance, while users can check their balances, they are not allowed to pay loans and can only transfer money between their own accounts. 

Experts predict that many enterprises will choose to outsource, at least initially, to get a jump on security. "This is definitely a buy-vs.-build type of proposition," said Lonadier of Hurwitz Group. "The wireless market is fairly new, and IT managers should figure out early on if they have the expertise to secure transactions on their own." 

Nor is it a mistake for e-businesses to limit m-commerce bells and whistles until they are sure they can guarantee a level of security that is acceptable to users and business managers. As many organizations learned the hard way during the first phase of e-business, it doesn't matter if the site uses the coolest technology; if it's not secure, it's a failure. 

"It doesn't matter if an application is mobile or not," said Edmunds.com's LaMuraglia. "It has to be secure, no matter what." 
<<< Previous Next >>>
Approach With Caution Where Wireless Leaks


<contents>
  Introduction
  Time to Wake Up
  Approach With Caution
WLANS Too
  Where Wireless Leaks
E-mail this story!
Printer Friendly

<news>
•  Career sites soar as the economy slumps
•  Miramax sells pay-per-view movie online
•  Hotmail trashes users' e-mail
•  Wireless Web fails the screen test
•  More Net News
<reviews>
• 
• 
• 
• 
• 
<downloads>
• 
• 
• 
• 
• 
• 
<resources>
• 
• 
• 
• 







 Sponsored Links
Bargains!  Shop the Basement for big savings on computer products
Let Verio  Host your WEBSITE. Low $$$ Hosting solutions!
Visit Now!  Egghead.com Business Solutions Center-We Mean Business
Everdream  The outsourced IT dept for small offices. Learn more!
Books  Free Shipping on Textbooks at Barnes & Noble.com
POWERHOUSE  Millennia MAX 933MHz&128MB SDRAM from $1749! Click here
 Everything Intel    Find Out More
Shop Now!   Shop at Dell's Home Solution Center - Dell Small Business Center
Shop Now!   Gateway Home Computing Center - TOSHIBA
Shop Now!   Everything Intel
 Featured Links
Cool Gear  Digital Cameras: Get price checks, expert reviews & advice
It's Here!  MSN Explorer is now available. Download it FREE!
Red Herring  RISK-FREE! For insight into the business of technology.
 Magazine Offers
Xbox & PS2  Don't buy your next console until you click this link!

Tech Jobs ZDNet e-centives Free E-mail Newsletters Updates MyZDNet Alerts Rewards Join ZDNet Members SiteBuilder
Feedback Your Privacy Service Terms Advertise About Us
Copyright (c) 2001 ZD Inc. All Rights Reserved. ZDNet and ZDNet logo are registered trademarks of ZD Inc. Content originally published in Ziff Davis Media publications is the copyrighted property of Ziff Davis Media. Copyright (c) 2001 Ziff Davis Media. All Rights Reserved. Titles of Ziff Davis Media publications are trademarks of Ziff Davis Publishing Holdings Inc. This ZDNet article may be reused when licensed.