Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Judge's decision leaves RIAA with lose-lose situation in Elektra v. Santangelo
  • Two New Judges for the FISA Court
  • Anonymity of Netflix Prize Dataset Broken
  • Hackers on a plane
  • Yahoo! Human Rights Program
  • Top Internet Threats: Censorship to Warrantless Surveillance
  • What you buy and where you shop may affect your credit

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

WiFi Safety Tips from Hacker Convention

Submitted by MacRonin on October 22, 2007 - 9:55pm
  • Alert
  • Exploits
  • Hmmm
  • How-To
  • Infrastructure
  • Privacy
  • Scams
  • Security
  • Software
  • Surveillance
  • Wireless

WiFi Safety Tips from Hacker Convention: "

'The most dangerous places to connect are airports, hotels, convention centers,' say Richard Rushing, Chief Security Officer for AirDefense, which does wireless security. 'And most people use credit cards there.'

Oops. I am hooking up to the San Diego Convention Center's wireless and paying for with a credit card as he says this. Apparently lots of other people are too because a snicker rings through the workshop here at ToorCon9.

By their nature, WiFi hotspots are insecure, he says, though they can be made more secure by using client isolation, which makes it harder to slide up and down the communications links from the server to the client and web.

'Client isolation should be turned on but we can still spoof the address or take the address backwards,' he says, noting that Macs are easily spoofed.

'Hot spots are really set up for the bad guys,' he says.

When Rushing looked at hotspot users, he found 30 percent have no firewalls and 3 percent have active malware they're inadvertantly introducing to the servers.

24 percent of the users never disconnect' after they were done. 'It's like standing at an ATM when you're done, counting your money.'

Most users developed very strong password and then sent over clear text so they can easily be grabbed. Most firewalls designed to defeat the pings and scans but are easily spoofed.

What can a hotspot user do?

-- Use prepaid wireless cards

--Use known hotspots, not airports, hotels, convention centers and libraries; where countless anonymous users come and go and the provider has no social connection to the users. Rushing says there's a growing number of baby boomers using library and hotspot wireless to do their banking because they don't want to set up at home.

--Don't do your banking on public networks. Use prepaid credit cards when you're not sure about the security on the network.

--Fortify your laptop if you're using hotspots, he says, with regret. 'What I've learned from looking at hotspots is that your laptop i's on its own, so you better take care of it.'

'Hotspots are great for browsing, but for personal stuff, be very wary,' Rushing said.


"

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • FBI Hoaxes Boost Online Fraud
  • NetFlix Cancels Recommendation Contest After Privacy Lawsuit
  • Advertising - Instant Ads Set the Pace on the Web
  • Best Practices for Government Datasets: Wrap-Up
  • TJX Hacking Conspirator Gets 4 Years
  • The Beginning of the End of Data Retention
  • Wanted: Trust Detector
  • Wikibooks Cryptography Textbook
  • Feds: TSA Worker Tried to Sabotage Terror Database
  • Hi-tech governments growing keener on snooping, says report
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.