Taking a moment's reflection, TV Slug mused: | | So what you are saying is that, as long as all clients with filtered MACs | maintain active connections, a hacker can sniff the signal but cannot | actually connect to the access point, no matter what.
Yes. But, most people do not leave their computers powered on 24/7 ... especially laptops.
| Sounds like a system of perfect security to me. Wow!
Save for DOS attacks that could cause clients to shutdown/reboot to attempt to solve the issue, thus allowing the attacker to then connect. And, without encryption, all packets can be reassembled and the contents of traffic known.
WPA (in some form) is the only robust security measure with wireless. WEP is crackable, MAC filtering alone is no good for the above reasons, and SSID broadcast disabling is an illusion of security.