whitefort said: First, encrypting data between me and the mail server.
I understand that Thunderbird can handle this (though I've not yet researched how to set it up), but I'm wondering how this would get decrypted when it reaches the server at my ISP. Perhaps this question is itself a demonstration of how clueless I am at this! Like all analogies, this is suspect, but: imagine buying a safe. You get two keys for it. You fly down to Florida (if you live in Florida, then s/Florida/Seattle/g :)) and give one of the keys to your buddy. Then you fly home. You write a letter and put it into the safe, and send the safe to your buddy via UPS. If you hadn't put the letter into the safe, any of a few dozen people between you and your buddy could have opened the letter, read it, and resealed the envelope. Because the letter is in a safe, you are reasonably confident that no one has read it. When your buddy is done reading the letter, they write a reply, put it back into the safe, and send the safe back to you. Okay we're using the Internet so everything is faster and cheaper than mailing a heavy safe cross-country, but the principal still applies: except here, the ISP's mail server is "your buddy" and "the Internet between you and your ISP's mail server" is UPS. If you are connected to a secure server (https://....) then you are using your safe. If you are not (http://....) then you are just sending your letter out without securing it in any way. It's more detailed than that, of course, but this is a start....
Also, if my SSID is just a name I've chosen to give my home network, what's the real advantage of hiding it? I'm presuming that a potential snooper will still see there's a wireless network there, even if he doesn't get the actual name - why is the name an advantage to him?
As others have said: it doesn't stop a dedicated attacker, just slows them down a little. The biggest thing to take home is that it makes your wireless connection (from your computer to your wireless router) more difficult to attack than other vectors. You know the story about the two guys on safari, they stop to cool their feet in a lake, a lion comes out of the bushes, and one of them starts lacing up his boots? His safari partner asks him why he's bothering, since he can't outrace a lion, and he replies, "I don't have to be faster than the lion, I just have to be faster than you." If you make your WLAN harder to crack than anyone else's WLAN than someone who just wants to crack a WLAN won't attack you. If you make your WLANL harder to crack than any other aspect of your online communications, than someone who wants your info won't attack your WLAN (they'll just attack some other weak point of your communication path).
All of this is still a bit academic for me, as I live in a location where my nearest neighbour is several fields away, but I AM hoping to learn enough to convince various family members that using unsecured WiFi in a built-up area is crazy.
Agreed: securing your WiFi is academic. Securing your WiFi access point-to-the-rest-of-the-Internet is much more important _for_you_.
For your family members:
- someone could drive by, or hang out in a nearby apartment, and take their passwords or credit card numbers
- someone could use their internet access with no malicious intent towards your family, but download something illegal: the courts are still unclear on this: your family members _could_ be held liable (e.g. the RIAA could sue your family members for allowing someone else to use their internet to download mp3s). This is pretty speculative... but is it worth the potential legal hassles? Especially since it just takes an hour or so (or less!) to secure your wireless network?
And at the risk of trying your patience... I'm also trying to teach family members the importance of good passwords (even on my own home PCs).
Good luck :)