Wi-Fi Week: Mobility at the cost of security
The mass media has had a lot of fun with wireless security: war driving, virus insertion and bandwidth stealing have all had their day in the sun. Public hot spots are more vulnerable to attack than private networks, where individual users can have their hardware authenticated as permanent network members. This means when you log onto a hot spot, there is a possibility that it has been compromised. It's not unknown for people to mount man-in-the-middle attacks, where they set up a bogus hot spot that overlaps with the provider's legitimate one, and then intercept logins.
If you are not connected to a service securely -- using SSL for websites, SSH for text services or a corporate VPN -- then you should be aware that your link may be transmitted in the clear and open to interception. Some service providers do have extra security in their wireless links, but if they also allow roaming then you should check that the security is in place no matter who's running the hot spot.
By Rupert Goodwins at ZDNet.
[ Read more ]
- Article: Increasing Security Awareness: Visualizing WEP Insecurity (3 March 2004)
- Article: Interview with Jon Edney, author of "Real 802.11 Security" (18 December 2003)
- Review: Wireless Hacks (12 December 2003)
- Review: Real 802.11 Security: Wi-Fi Protected Access and 802.11i (3 November 2003)
- Review: 802.11 Security (3 October 2003)
- Article: Wireless Security: Preventing Your Data From Vanishing Into Thin Air (16 September 2003)
- Review: Installing, Troubleshooting, and Repairing Wireless Networks (5 September 2003)
- Review: Building Secure Wireless Networks with 802.11 (28 August 2003)
- Review: How Secure is Your Wireless Network? Safeguarding Your Wi-Fi LAN (22 August 2003)
- Article: Lack of Security at Wireless Conferences (6 August 2003)
- Review: WiFi Security (9 July 2003)
- Review: Wireless Security End to End (4 June 2003)
- Review: The Complete Wireless Internet and Mobile Business Programming Training Course (28 May 2003)
- Review: Deploying License-Free Wireless Wide-Area Networks (14 May 2003)
- Article: Positive Identification in a Wireless World (6 May 2003)
- Article: Warchalking and Other Wireless Worries (3 April 2003)
- Article: How to Make Wireless Networks Secure (26 March 2003)
- Article: Interview with Cyrus Peikari, CEO of AirScanner Mobile Security (24 February 2003)
- Review: Maximum Wireless Security (17 February 2003)
- Article: Detecting Wireless LAN MAC Address Spoofing (22 January 2003)
- Article: Avoid Wireless LAN Security Pitfalls (17 January 2003)
- Article: Interview with Jay Chaudhry, CEO of AirDefense (7 January 2003)
- Review: Wireless Security and Privacy: Best Practices and Design Techniques (17 December 2002)
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.