News

Wi-Fi a Welcome Mat for Attackers, Study Finds

AirTight, a provider of Wi-Fi security services, recently scanned 3,632 access points (APs) and nearly 550 clients in seven different financial centers and found that half of these WPAs were either open (unprotected) or used WEP encryption.

The test sites were in New York, Chicago, Boston, Philadelphia, Wilmington (Del.), San Francisco and London.

Lest you dismiss the issue as one of rogue access points or isolated consumer WPAs that were caught up in AirTight's dragnet, 39 percent of so-called "threat-posing" APs could be classified as "enterprise-grade." In many cases, AirTight reported, enterprise-grade APs that could have been configured to support the more robust WPA or WPA2 protocols were instead protected with WEP. AirTight was also careful to distinguish between known or popular open APs -- such as those associated with hotspots -- and enterprise-grade implementations.

In any given financial district, AirTight reported, 13 percent of mobile Wi-Fi clients are configured to operate in ad hoc mode, which makes them vulnerable to wi-phishing or "honeypotting" attacks, researchers pointed out.

AirTight found that 61 percent of open access points were consumer- or SOHO-grade devices. It doesn't strictly associate the use of these devices with home or SOHO scenarios, however; in some cases, these devices are deployed by "impatient" or reckless employees who, frustrated by the slowness of in-house Wi-Fi rollouts, plug rogue (typically consumer) APs into enterprise networks to perpetrate "back-door" schemes.

Moreover, AirTight reported, some enterprises seem to assume that simply obfuscating an AP's SSID is protection enough: 79 of open APs with hidden SSIDs were powered by enterprise-grade devices.

The AirTight report revealed a disappointingly low rate of WPA2 adoption -- just 11 percent, on average. Compare that with WEP, which is used by fully one-third of Wi-Fi networks in the surveyed financial districts. This is in spite of the fact that WEP cracking can take less than five minutes, AirTight researchers caution.

Moreover, AirTight noted, just under a third (32 percent) of Wi-Fi networks use WPA, which is also known to be vulnerable.

About the Author

Stephen Swoyer is a Nashville, TN-based freelance journalist who writes about technology.

comments powered by Disqus

Featured

  • VS Code v1.99 Is All About Copilot Chat AI, Including Agent Mode

    Agent Mode provides an autonomous editing experience where Copilot plans and executes tasks to fulfill requests. It determines relevant files, applies code changes, suggests terminal commands, and iterates to resolve issues, all while keeping users in control to review and confirm actions.

  • Windows Community Toolkit v8.2 Adds Native AOT Support

    Microsoft shipped Windows Community Toolkit v8.2, an incremental update to the open-source collection of helper functions and other resources designed to simplify the development of Windows applications. The main new feature is support for native ahead-of-time (AOT) compilation.

  • New 'Visual Studio Hub' 1-Stop-Shop for GitHub Copilot Resources, More

    Unsurprisingly, GitHub Copilot resources are front-and-center in Microsoft's new Visual Studio Hub, a one-stop-shop for all things concerning your favorite IDE.

  • Mastering Blazor Authentication and Authorization

    At the Visual Studio Live! @ Microsoft HQ developer conference set for August, Rockford Lhotka will explain the ins and outs of authentication across Blazor Server, WebAssembly, and .NET MAUI Hybrid apps, and show how to use identity and claims to customize application behavior through fine-grained authorization.

  • Linear Support Vector Regression from Scratch Using C# with Evolutionary Training

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of the linear support vector regression (linear SVR) technique, where the goal is to predict a single numeric value. A linear SVR model uses an unusual error/loss function and cannot be trained using standard simple techniques, and so evolutionary optimization training is used.

Subscribe on YouTube