I've written lists of tips for groups a few times so heres a cut and paste from my notes version since the presentations are full of formatting. Even made brief, it's a long list. It's also the unedited, non spell checked version so don't make fun.

In no particular order...

Try and use WPA over WEP encryption if you have a choice. Both use 128 bit encryption but WEP sends part of the key out in it's very first packet. If the person sniffing your network happens to catch that packet, it can greatly reduce thier hack time.

Wireless is more famous for being wide open because most people don't know or bother to protect it but people can sniff your wireline network too when you are attached to the internet unless you are going through a VPN to somewhere specific.

Use a wireless router that does IP translation so your PC is not using a live IP on the internet.

Use the best firewall you can but even XP's built in one is better than nothing. Make sure it's turned on if you have nothing else. Wireless routers have firewall capabilities as well.

Learn, even just a little, about how your firewall works. Learn what a 'port' is and how to safely block and open them. Short version - A port is a numbered doorway into your computer via a netowork or the internet. Web uses port #80 for instance. A main feature of firewalls is that they can close all the ports that don't need to be used. Some open ports are required, some are relatively harmless while others, if left open, can allow total access to your PC.

Use Anti-virus and anti-spyware. No good having a firewall if you pick up a trojan that is designed to open a hole from the inside. If you won't pay for a mainstream version, at least download the free stuff. It is actually recommended to run multiple forms of antispyware from time to time as there as simply sooo many varieties.

Locking your network down to specific MAC addresses is good to do, but they can be easily spoofed as well. Of course they would need to know what it is first. Of course, even a freeware sniffer will tell them if they are watching your network.

Don't forget to change the administrator password in your wireless router. Change the username "administrator" too if it will let you.

Change the SSID (name of the network) from the default name. It doesn't really make much difference security wise but not changing it flags you as someone who probably didn't know how to secure their network.

Turn Off the SSID (Network ID) broadcast feature. Unless you have a lot of guests, you will have already programmed your PCs with the correct SSID. No need to advertise that you are 'out there'.

Here is one you might not think of. Your network could be fairly secure but if you turn on the 'auto-connect' feature on your wireless laptop, you might accidentally connect to your neighbors network, still be able to surf the net but now be possibly much less protected.

-------
No encryption is unbeatable but the good ones take such effort to break, they have to have a good reason to choose "you" to bother with.

Wireless is more famous for being wide open because most people don't know or bother to protect it but people can sniff your wireline network also when you are attached to the internet unless you are going through a VPN. It depends on how the service provider is set up, how many can directly 'sniff' your network but there almost assuredly a few who can.


All add this for this group....

I'm personally very comfortable with my security behind my wireless router, firewall and in being set up with all of the above precautions. Comfortable enough to make Internet purchases of expensive speakers using my Visa online.

If you are really concerned about the wireless feature, run some cat5 and stick to physical connections but don't forget to still use precautions to keep the Internet baddies out in general.

or....
you can always wrap your house in tin foil!


With great power comes Awesome irresponsibility.