Wi-Fi Handbook: Building 802.11b Wireless Networks

Unlike wired systems, which can be physically secured, wireless networks are not confined to the inside of buildings. They can be picked up as far as 1,000 feet outside of the premises with a laptop and a gain antenna. This makes wireless local area networks (WLANs) inherently vulnerable to interception.
Knowing this, the 802.11 committee added a first line of defense called Wireless Equivalency Protocol (WEP). WEP is an encryption protocol that provides the same level of security that wired cables provide. The standard provides both 40- and 128-bit (really only 104-bit) encryption at the link layer using the RC4 algorithm, which is allowed for export by the U.S. government.
Amazingly, many users do not use this encryption at all. This has led to a new hobby called war driving or LAN jacking where people pack a wireless-equipped laptop and drive around looking for open networks to surf. However, some people take this same approach to spy on corporations and hack into networks.
Electronics retailer Best Buy Co. ran into trouble in the spring of 2002 when customers who had purchased WLAN cards from Best Buy installed the cards in their laptops before they left the parking lot. The customers noticed unencrypted WLAN traffic that contained customer information and possibly credit card numbers. The Best Buy case is an example of why enterprises should at least encrypt their WLAN traffic with WEP. By the end of 2002, it is expected that 30 percent of enterprises...