Data, network value to drive Wi-Fi security

 

Summary

In wake of Google Wi-Fi spying, Singapore-based analyst notes better wireless security will come about only when users understand the value of data.

Events

IBM Technology Conference & Expo 2012
May 22, 2012

One World Hotel, First Avenue, Bandar Utama City Centre, 47800 Petaling Jaya, Selangor

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

As controversy around Google's admission that its Street View cars had collected data from unsecured wireless networks continues to swirl, an analyst says better Wi-Fi security will only come about when users recognize the value of their networks and data.

Daphne Chung, senior research manager for infrastructure software at IDC Asia-Pacific's domain research group, told ZDNet Asia in an e-mail interview that users are generally becoming more savvy about Wi-Fi network security and are gradually looking toward encrypted Wi-Fi network to ensure secure communications.

Such a change in mindsets, however, takes time.

"People need to understand the value of their networks and their data or information and the potential consequences of the violation of their networks, then they would understand the need to lock their networks just as they lock their houses," Chung pointed out.

"Ultimately, self preservation is usually the best incentive and as users grow in reliance on networks for their sensitive transactions and information exchange, this awareness and adoption of more security around their Wi-Fi networks will also grow."

Google last month announced it had inadvertently accumulated about 600 gigabytes of data transmitted over public Wi-Fi networks in more than 30 countries--a revelation that spurred a class action lawsuit in the United States and probes in Australia, Canada, Germany, Italy and Spain.

Singapore is among the countries affected by Google's collection of what the company calls payload data, or actual data transmitted over the network. A Google spokesperson said in an e-mail to ZDNet Asia that company representatives "had conversations" with local ICT regulator, the Infocomm Development Authority of Singapore (IDA), and will continue to work with the authority "to answer their questions and concerns".

However, Google said it did not collect data from secured networks, suggesting that none of this would have occurred had Wi-Fi access been password-protected.

Ignorance, lack of technical know-how to blame
According to IDC's Chung, ignorance, lack of know-how in securing networks and not understanding the consequences of unprotected access were the main reasons for unsecured wireless networks.

That said, manufacturers have made it easier to configure password protection on wireless routers, she said.

ZDNet Asia blogger Lee Lup Yuen concurred. In an e-mail, he noted that these days, users can use the installation software bundled with the devices to easily perform password configurations.

Still, problems could arise during the installation process, such as whether an owner should opt for the WPA (Wi-Fi Protected Access) or WEP (Wireless Equivalent Privacy) standard, he said. "When users get frustrated with the installation process, they may resort to using no security for their Wi-Fi networks."

Forgetting the router administrator password could also pose a headache for wireless network owners. To solve this problem, Lee suggested product vendors preset the router administrator password to a random number, which can be printed on a sticker attached to the router.

Legal penalties for not securing Wi-Fi?
In at least one country, wireless network owners can be taken to task for their negligence in wireless network encryption. Last month, the BBC reported that a German court fined a man 100 euros (US$122) for not securing his Wi-Fi network with a password. The failure to protect the access had led to the network being used to illegally download and file-share music.

A British lawyer told BBC in the report that it was unlikely a U.K. court would arrive at the same verdict.

Over in Singapore, Keystone Law's Tan noted that there has been a precedent where penalties are meted out for illegal Wi-Fi access. However, there is "currently no specific legislation penalizing those who do not secure wireless access", and such legislation is required for authorities to take legal action, he said in an e-mail.

Even if a civil lawsuit arises where one party alleges that the network owner had been negligent in not securing his wireless access, Tan pointed out that "the current state of Singapore law in the form of its Electronic Transactions Act and the Copyright Act may give network owners what is known as a 'conduit defense'--where network owners are merely conduits and not the perpetuators of the wrongful acts of third-parties".

The lawyer added that users should password-protect their wireless networks, but said enforcement would be "impractical because no one gets into trouble for leaving their door unlocked".

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

RT @zdnetasia: Gartner: Mobile CRM gives better ROI than social. http://t.co/nTgj44H8

China hits back at Pentagon report on spy claims. http://t.co/CccR4SBM

China hits back at Pentagon report on spy claims http://t.co/YP380BYQ http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV China hits back at Pentagon report on spy claims: Annual report by Pent... http://t.co/TvgCi5RE http://t.co/wiqY9ktt

#AntiVirus News: Mac users' indifference toward security 'worrying' http://t.co/spWS0CpU #AdAware

Mac users' indifference toward security 'worrying' http://t.co/BtVn1BAk
> expected! They still remember Mac vs PC ads
#infosec #news #apple

Pentagon report says China exploit US tech, conduct cyberespionage, China says it has been "unjustly criticized" http://t.co/P5wgqy6I #in

Mac users' indifference toward security 'worrying': 59 Jakarta 10350, Indonesia In light of the recent spate of ... http://t.co/Lxgnc1wM

Pakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh

Pakistan lifts block on Twitter http://t.co/WHqoJOqm http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Pakistan lifts block on Twitter: Country restores access after briefly ... http://t.co/5gqegFWK http://t.co/wiqY9ktt

Pakistan lifts block on Twitter. http://t.co/y0arswpE

Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn

Mac users' indifference toward security 'worrying' - ZDNet Asia: Mac users' indifference toward security 'worryi... http://t.co/CD9pvW08

RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

3 hours ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

20 hours ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

2 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

2 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

3 days ago by wykoong on Drop the egos, copy ideas, then innovate