News

Wi-Fi a Welcome Mat for Attackers, Study Finds

AirTight, a provider of Wi-Fi security services, recently scanned 3,632 access points (APs) and nearly 550 clients in seven different financial centers and found that half of these WPAs were either open (unprotected) or used WEP encryption.

The test sites were in New York, Chicago, Boston, Philadelphia, Wilmington (Del.), San Francisco and London.

Lest you dismiss the issue as one of rogue access points or isolated consumer WPAs that were caught up in AirTight's dragnet, 39 percent of so-called "threat-posing" APs could be classified as "enterprise-grade." In many cases, AirTight reported, enterprise-grade APs that could have been configured to support the more robust WPA or WPA2 protocols were instead protected with WEP. AirTight was also careful to distinguish between known or popular open APs -- such as those associated with hotspots -- and enterprise-grade implementations.

In any given financial district, AirTight reported, 13 percent of mobile Wi-Fi clients are configured to operate in ad hoc mode, which makes them vulnerable to wi-phishing or "honeypotting" attacks, researchers pointed out.

AirTight found that 61 percent of open access points were consumer- or SOHO-grade devices. It doesn't strictly associate the use of these devices with home or SOHO scenarios, however; in some cases, these devices are deployed by "impatient" or reckless employees who, frustrated by the slowness of in-house Wi-Fi rollouts, plug rogue (typically consumer) APs into enterprise networks to perpetrate "back-door" schemes.

Moreover, AirTight reported, some enterprises seem to assume that simply obfuscating an AP's SSID is protection enough: 79 of open APs with hidden SSIDs were powered by enterprise-grade devices.

The AirTight report revealed a disappointingly low rate of WPA2 adoption -- just 11 percent, on average. Compare that with WEP, which is used by fully one-third of Wi-Fi networks in the surveyed financial districts. This is in spite of the fact that WEP cracking can take less than five minutes, AirTight researchers caution.

Moreover, AirTight noted, just under a third (32 percent) of Wi-Fi networks use WPA, which is also known to be vulnerable.

About the Author

Stephen Swoyer is a Nashville, TN-based freelance journalist who writes about technology.

Featured

  • Microsoft Offers More Help on Windows Server 2008 Upgrades

    Microsoft this week published additional help resources for organizations stuck on Windows Server 2008, which fell out of support on Jan. 14.

  • Microsoft Ups Its Carbon Reduction Goals

    Microsoft on Thursday announced a corporatewide carbon reduction effort that aims to make the company "carbon negative" by 2030.

  • How To Dynamically Lock Down an Unattended Windows 10 PC

    One of the biggest security risks in any organization happens when a user walks away from their PC without logging out. Microsoft has the solution (and it's not a password-protected screensaver).

  • First Stable Chromium-Based Microsoft Edge Browser Released

    Microsoft on Wednesday announced the first release of its Chromium-based Microsoft Edge browser at the "stable" commercial-release stage.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.