Users don't understand public Wi-Fi risks

 

Summary

People accessing public Wi-Fi aware data theft and industrial espionage could happen with unsecured networks but see risks as "theoretical", say Astaro execs.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Users have not fully comprehended the threats associated with accessing Wi-Fi via a public hotspot, and the proliferation of mobile devices and the move toward a wireless mesh network will only compound these network risks.

Norbert Kiss, vice president of network security at Astaro Asia-Pacific, told ZDNet Asia in an interview on Tuesday that public Wi-Fi users are aware of the threats such as data theft. However, he pointed out that people do not protect themselves when using such networks because they do not understand how the theft will be conducted, the money invested in cybercrime and how valuable the stolen information is.

He added that people view these threats as "theoretical" as the risks have been repeated too often without them understanding how real the threats are and how they will be compromised.

Benjamin Hodge, director of technical services at Astaro Asia-Pacific, added on to Kiss's point, saying that users do not see what happens when their user ID or passwords are obtained by cybercriminals. The payoff for the hackers could be for sending spam and malicious links or the money made by selling the information online, he explained.

"There is a real economy and industry for cybercrime," Hodge said. "It is more profitable than the drug trade and almost impossible to prosecute especially if the hacker and victim are in different continents."

The executives were responding to a recent study by Wakefield Research on behalf of the Wi-Fi Alliance, which found that close to 85 of respondents in the United States knew that they should turn off automatic sharing on Wi-Fi devices but only 62 percent actually did. It was also found that only 18 percent of the people using Wi-Fi in a public hotspot are using virtual private networking (VPN) software to protect their corporate network.

Mobile workers beware
Elaborating on public Wi-Fi vulnerabilities, Hodge said with the packet-sniffing software, which is "easily available" for free online, hackers can gain access to the data on one's computer via the network. This threat is particularly pertinent to mobile workers who frequent hotspots such as Starbucks or airports as cybercriminals can not only access information on the computer, but "insert themselves" into the network to launch man-in-the-middle attacks, he added.

"Thirty years ago, people looked through garbage and trash for company data," Kiss said. "Today, they can easily do that with Wi-Fi."

Wireless Encryption Protocol (WEP) was previously the main barrier against such network penetration but the Astaro director noted that it "has been broken many times". Newer devices today use Wi-Fi Protected Access 2 (WPA2) but the security code can be easily and quickly cracked using modern hardware, CPU and graphic cards, he stated.

Wi-Fi networks at home are not spared, too, even though they are encrypted as relying on such security measure is a "big mistake", Hodge said. The encryption can be easily broken so home systems are also at risk of being hacked, he noted.

The proliferation of mobile devices also contribute to the rise of users accessing Wi-Fi that are "dangerous", but would also depends on the prices of data plans in various countries, Kiss noted, adding that the use of 3G is safer than that of Wi-Fi.

The severity of public Wi-Fi threats is also directly related to the price of data plans in one's country, Kiss noted, adding that 3G networks are safer than Wi-Fi. In Singapore, for example, data plans are relatively cheap so people are less hesitant to sign up for and use 3G plans.

However, places that have more expensive data plans, such as Australia, would see more people turning to free Wi-Fi networks while countries that cannot afford to set up widespread 3G network infrastructure such as the Philippines, Wi-Fi is the only choice for mobile Internet access, the vice president said.

Countries are also moving toward a "wireless mesh network" whereby all systems are overlapping, constant connection is present and every device is connected all the time, Hodge added.

While this is "still very new", the fact that this will make countries "more wired" mean that threats will be more prevalent, he warned.

Ultimately, Hodge said mobile workers that use public Wi-Fi should always connect to their VPN (virtual private network) for secured access to corporate information. They should also check whether device settings such as firewalls are turned on, he suggested.

"Most importantly, be very suspicious when Wi-Fi is available but do not require passwords," Kiss urged. "Don't be in a rush to use the Internet and end up compromising security."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Malaysia organizations don't realize severity of cyberattacks http://t.co/PUCv68Rd

News: Radio Costa Rica by EnjoyIT 1.0: Radio Costa Rica allows you to listen to a great var... http://t.co/BLzVT5As http://t.co/1Dhcy6ki

The key for mobile operators is identifying the applications that are popular with subscribers on their network. They can then work partn...

1 hour ago by camcullen on Experience trumps content in apps monetization

Experience trumps content in apps monetization | ZDNet http://t.co/gBXcjbGd

Experience trumps content in apps monetization - ZDNet Asia News: "What we are doing currently is not to monetiz... http://t.co/S2EZtd8m

Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said at the Sec... http://t.co/bgVlOBvx

#security Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said ... http://t.co/hkFb4zrI

Malaysia organizations don't realize severity of cyberattacks http://t.co/EEEmRM3j via @zdnetasia

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia News http://t.co/YpNMYgb5

Malaysia organizations don't realize severity of cyberattacks http://t.co/FFems54Q

China solar cell makers seek Taiwan partnerships http://t.co/p5Hh7kJD

Big data acquisitions pave way to fast, effective innovation http://t.co/hdiEfBsz via @zdnetasia

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 hours a... http://t.co/E7tsZbHJ

Integration, focused investments to propel Windows Phone http://t.co/u9TqjQ8C

ZDNet Asia IT Salary Benchmark 2012 http://t.co/rVwYlV7H

AsiaClassifiedToday. Integration, focused investments to propel Windows Phone - ZDNet Asia: S... http://t.co/47tdjZyG #asia #google #biz

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate