Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

car insurance prices
Tracking System

Popular content

Last viewed:

  • CFP2008 in New Haven
  • iPhone Forensics: Recovering Evidence, Personal Data, and Corporate Assets
  • CNN To Free Debate Footage for Remixing, Re-Use
  • How victim snared ID thief / She chased down woman who had given her 6 months of hell
  • EFF Engages Veteran Lobbyists to Take Fight Against Warrantless Wiretapping to Capitol Hill
  • End Policing for Profit
  • Crime expert backs calls for 'licence to compute'

tags in Topics

Activists Alert Anonymity Companies Copyright Court (US) Databases Data Mining DMCA Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

WiFi Safety Tips from Hacker Convention

Submitted by MacRonin on October 22, 2007 - 9:55pm
  • Alert
  • Exploits
  • Hmmm
  • How-To
  • Infrastructure
  • Privacy
  • Scams
  • Security
  • Software
  • Surveillance
  • Wireless

WiFi Safety Tips from Hacker Convention: "

'The most dangerous places to connect are airports, hotels, convention centers,' say Richard Rushing, Chief Security Officer for AirDefense, which does wireless security. 'And most people use credit cards there.'

Oops. I am hooking up to the San Diego Convention Center's wireless and paying for with a credit card as he says this. Apparently lots of other people are too because a snicker rings through the workshop here at ToorCon9.

By their nature, WiFi hotspots are insecure, he says, though they can be made more secure by using client isolation, which makes it harder to slide up and down the communications links from the server to the client and web.

'Client isolation should be turned on but we can still spoof the address or take the address backwards,' he says, noting that Macs are easily spoofed.

'Hot spots are really set up for the bad guys,' he says.

When Rushing looked at hotspot users, he found 30 percent have no firewalls and 3 percent have active malware they're inadvertantly introducing to the servers.

24 percent of the users never disconnect' after they were done. 'It's like standing at an ATM when you're done, counting your money.'

Most users developed very strong password and then sent over clear text so they can easily be grabbed. Most firewalls designed to defeat the pings and scans but are easily spoofed.

What can a hotspot user do?

-- Use prepaid wireless cards

--Use known hotspots, not airports, hotels, convention centers and libraries; where countless anonymous users come and go and the provider has no social connection to the users. Rushing says there's a growing number of baby boomers using library and hotspot wireless to do their banking because they don't want to set up at home.

--Don't do your banking on public networks. Use prepaid credit cards when you're not sure about the security on the network.

--Fortify your laptop if you're using hotspots, he says, with regret. 'What I've learned from looking at hotspots is that your laptop i's on its own, so you better take care of it.'

'Hotspots are great for browsing, but for personal stuff, be very wary,' Rushing said.


"

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • The Secrecy Double-Standard
  • Fully-qualified Nonsense in the SSL Observatory
  • Appeals Court Strengthens Warrantless Searches at Border
  • Justice Dept. to Congress: Don’t Saddle 4th Amendment on Us
  • Feds, RIAA Ask $22,500 in Damages Per Song
  • Building a better Certificate Authority (CA) infrastructure
  • Where’s EFF? Why EFF Is Sometimes Quiet About Important Cases
  • Congressman Wants YouTube Video Covered Up
  • Man Creates "Creepy" Stalking App
  • Boston College Says Using WiFi Is a Sign of Infringement
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.