Your Data Can be Stolen on Airport Wireless Networks
By Thepeoplechoice on 4:33 AM
Filed Under: Wifi News, Wifi tips and tricks, Wireless Security, WirelessTechnology
Peter Piazza, newsfactor.com Mon Mar 3, 4:55 PM ET
The next time you're in an airport terminal with your wireless notebook on, there's a good chance you're exposing your or your company's data to others. Even worse, the wireless network you're connected to might be completely insecure -- or even be running on the laptop of the guy sitting next to you.
Researchers from AirTight Networks visited 14 airports around the world and discovered that most business travelers aren't taking the basic steps necessary to protect sensitive data. "We found that only three percent of all mobile users were using virtual private networks (VPNs), so most of their data was free and clear to anyone who could sniff the airwaves," said Mike Baglietto, director of product marketing for AirTight Networks.
With little effort the researchers were able to see what Web surfers were looking at, and even capture their cookies (small text files that allow Web sites to identify and track users). "There's a huge data-leakage exposure," Baglietto said. "We're able to track people's cookies in the air, and once you start getting a user's cookies, you could impersonate that user" to steal their banking credentials, for example.
Insecure Access Points
Web surfers weren't the only ones operating insecurely, Baglietto told us. Most of the wireless networks the AirTight researchers checked out were insecure.
The team noted 478 access points, of which 57 percent were completely unprotected, and another 28 percent were protected by WEP (wired equivalent privacy), an encryption protocol that is easily broken. Even worse, 77 percent of the networks were not hot spots (networks offered by the airport or a provider like T-Mobile). Rather, eight out of 10 were insecure networks run by shops, restaurants and even the airport back offices.
The names of some of the access points -- for example, e-Baggage Trial -- gave the researchers clues that those networks were being used for airport operations like baggage handling to airline ticketing. Just like the other access points, Baglietto said these were also insecure.
The potential for an attack on airport systems is enormous, and such an attack would have catastrophic ramifications. "Imagine somebody doing a denial-of-service attack on the baggage infrastructure at San Francisco or Heathrow airports," Baglietto said. "It would send the entire airport into total chaos" and would likely impact air travel around the globe.
Viral Connections
The researchers also noted a huge outbreak of viral ad-hoc wireless networks. A laptop with this infection broadcasts itself as a free mobile hot spot. Other laptops inadvertently connect to it since it has a strong signal that wireless cards search for. Once connected, a laptop becomes infected itself and convinces other computers to connect to it.
"The biggest risk that creates is that all your shared folders are exposed to everyone else on that network, so you could be sitting in the airport completely unaware that your laptop is connected to the guy sitting next to you" with your personal and corporate data exposed, Baglietto said. One out of 10 users was infected, the researchers noted, and in one airport five users were connected to the same viral network.
Simple and common-sense measures can prevent these problems. AirTight advises executives to use VPNs and not to connect to any unknown wireless networks in public places. It also said users should periodically look at their Wi-Fi configuration and remove any unneeded networks from the preferred list. Users should also disable "ad hoc" connectivity in public places and turn off wireless connectivity when it's not being used.
Stephen Lawson, IDG News Service
A startup says it can give subway riders wireless Internet access that's faster than most home broadband in the U.S.
Tests at stations and on a special stretch of track in the Bay Area Rapid Transit (BART) system around San Francisco showed that Wi-Fi Rail's patent-pending technology delivered more than 15M bps (bits per second) of wireless throughput to riders and people waiting for trains, the company said. Wi-Fi Rail hopes to roll out such networks on rail systems around the world and charge commuters for access.
Commuter rail, with thousands of daily riders, could represent a rich opportunity for public wireless Internet access. Wi-Fi hotspots in airports and coffee shops have drawn some paying users, but the hotspots are useful more for occasional than for regular use. And citywide public Wi-Fi networks, often planned out with local governments, have run into political and business problems.
Wi-Fi Rail, founded in 2006 and based near Sacramento, would build two kinds of Wi-Fi networks: one in the cars and one around the tracks, said Michael Cromar, Wi-Fi Rail's chief financial officer. Passengers would log in to access points on each car, and each car's network would lock on to one access point after another along the rail system. The trackside access points, in turn, would feed traffic onto fiber-optic lines. Roaming would be handled by the in-car network and be transparent to users, Cromar said.
Even better than typical home broadband, the network can deliver its average 15M bps speed both upstream and downstream, according to Wi-Fi Rail. Passengers would share that link, but in tests, there was no noticeable slowdown between one passenger and eight passengers using the network, Cromar said. The system worked with the trains moving at speeds as high as 65 miles per hour.
The company tested its technology in both underground and above-ground parts of the BART system. Above ground, Wi-Fi Rail used standard outdoor access points with line-of-sight antennas to form a link from trains as they went by. In an underground test, the company used "leaky" coaxial cable, a technology some rail systems already use for exchanging operational data with cars, according to Cromar. The leaky cable is deliberately unshielded so signals traveling along it can be picked up all through a tunnel.
In-car tests took place on a 2.6-mile BART test track last month, as well as on a stretch of tunnel in San Francisco. Another part of the test proved such a service can draw customers, Cromar said. Wi-Fi Rail set up regular access points in four underground stations in downtown San Francisco and let people waiting for trains register and use the network for free. Without any publicity, more than 6,400 people signed up in less than six months, he said.
Although BART hosted the tests, it hasn't made a deal to have such a network deployed, Cromar said. But Wi-Fi Rail has talked with one interested transit system in the U.S. and is working with a partner to approach a rail system in another country, he said. The company said its technology is ready to go and could be used for anything that follows a predetermined path, including highways.