Welcome, Bill  |  Member Center  |  Log out              Site Index  
ajc accessAtlanta classifieds jobs homes cars archives
Search: Site/Web enhanced by   Yellow Pages

 
  Monday
  Tuesday
  Wednesday
  Thursday
    News
    Metro
    Sports
    Business
    Living
    Opinion
    Access Atlanta
    Food & Drink
    Gwinnett News
    City Life
    Cherokee
    Clayton/Henry
    East Cobb
    Cobb
    Coweta
    DeKalb
    East Metro
    Fayette
    NorthSide
    South Metro
    Front page
        image
  Friday
  Saturday
  Sunday
  Full index

Hackers haunt hotspots
Passwords, e-mail float unprotected at most wireless access locations
Bill Husted - Staff
Thursday, April 28, 2005

It's hacker heaven here at the Starbucks near North Point Mall in Alpharetta. The names and passwords of patrons roll by on Richard Rushing's computer screen like closing credits for a movie.

Customers using a wireless Internet connection busily type e-mail messages and check Web pages --- unaware that Rushing's laptop computer sees much of what they are doing.

As is true at most public wireless connection points --- or hotspots --- there is not even the most rudimentary security between users' computers and prying eyes. Rushing explains he could repeat the performance at almost any place that offers wireless access.

Fortunately for these Starbucks customers, Rushing isn't a thief. He's chief security officer for AirDefense, a wireless security company based in Alpharetta, and his demonstration is purely for the benefit of a reporter.

But here's the troubling part: Almost anyone can do the same thing if armed with an unhealthy curiosity and free software downloaded from the Internet. They can see passwords, read your e-mail and determine what Web sites you visit while using a hotspot.

Hotspots are growing in popularity along with the proliferation of wireless computers and other devices, and many users may be unaware of the security risks. One Web site that tracks hotspots --- www.jiwire.com --- estimates there are 25,500 in the United States and nearly 850 in Georgia, though numbers are imprecise.

"We're predicting a 100 percent growth of hotspots in 2005," said Kevin McKenzie, chief executive of Jiwire. "Hotels and other location types that naturally cater to the business traveler will be large contributors to this rapid growth."

A hotspot works like a wireless network for home computers, where all computers in a given area can share an Internet connection. The difference is that strangers share hotspot connections, making them wide open to eavesdroppers.

"Using an open public hotspot would be analogous to leaving your front door open, all your file cabinets open and your bank accounts sitting on your dining room table," said Chris Rouland, a security expert at Internet Security Systems in Atlanta.

"All it takes is the software," said Ron Hutchins, head of academic and research technologies for Georgia Tech's Office of Information Technology. "All they have to know is how to push 'go.' "

How worried should computer users be? That's hard to say, as data on the frequency of hacking is anecdotal. Rouland said he detects about two break-in attempts an hour when he uses a wireless computer in metro Atlanta hotspots.

Experts say most hotspot hacking involves casual snooping by people who do it for the technical challenge and perverse pleasure of reading strangers' e-mails.

Professional thieves

But the dangers can go beyond snooping. Rushing said professional data thieves may haunt hotspots at places that attract executives, such as expensive hotels and airport frequent-flier lounges. Hotspot attacks in those places are often attempts to steal business data for resale to competitors. Hackers can also steal credit card numbers or other personal information, experts warn.

There's also what security experts call "the evil twin."

A hacker picks a promising hotspot and uses a laptop to set up a second hotspot that imitates the real one. If the signal is stronger from that second hotspot, "the evil twin," users mistakenly connect to it, opening their computers to the hacker.

Said Rouland: "There aren't many effective ways today to defend against that."

Hotspot user Ed Lorek of Marietta understands the risks --- and has taken precautions.

Lorek, vice president of a local technology company, travels frequently and often uses hotspots to connect to the Internet.

"The onus is on me to protect my data," he said. So Lorek uses what is called a virtual private network when he logs on from a public hotspot. The software encrypts the data sent back to work and protects him from snoopers.

Almost no public hotspots in Atlanta use even basic encryption, even though wireless computers are capable of using WEP, wireless encryption protocol, which scrambles transmitted data. Users type in a WEP key --- which works like a password --- to enable the security.

It's not foolproof, as there are free tools to intercept even scrambled transmissions. But it is secure enough to stop casual snoopers and many would-be hackers.

Some hotspots avoid adding WEP protection because it would add complexity for users, and require more work and expense for the business offering the service. Many users would need assistance to enable WEP on their computers.

For a hotspot offering free service, that's a headache.

"It's just too difficult for the user experience if people have to enter a WEP key," said Richard Tanksley, head of business development for Atlanta-based Third Wave, which has created free hotspots for about 57 locations in Atlanta, including Lenox Square mall.

"It's not going to be a benefit for the coffee shop if every 20 minutes they have to show someone how to do it," he said. "It's free, so people complain less."

Even so, two days after talking to a reporter about hotspots, Tanksley called to say that Third Wave would post security tips and warnings at all the Atlanta sites it maintains.

While WEP doesn't guarantee safety, "there is absolutely less risk with WEP," said Georgia Tech's Hutchins. "Everything you do lowers your risk. It's like buying a padlock. It might not stop everyone, but it makes it more difficult. The more padlocks, the lower the risk."

It's not just naive computer users who fall victim to hotspot hacking.

Hutchins recently attended a seminar for security experts. During one speech, many participants listened with half an ear while logging on to a wireless connection to catch up with e-mail.

"When it was over, someone stood up and said, 'OK folks, I have 67 passwords that I've just snooped off the network,' " Hutchins said. "All these were people that I knew, professionals, and they were sending their passwords right over the air."

HOW HOTSPOTS WORK
Hotspots allow multiple computers to share a single connection to the Internet. Wireless-equipped computers and other devices receive signals from a base station via antennas or software. Hotspots usually have a range of a few hundred feet.

HOW TO THWART HACKERS
> Use a software firewall in your computer.
> Use Web sites that scramble data. If you see an icon that looks like a lock at the bottom of your screen, the Web site is secure. You can also check the address: Instead of the familiar "http," you should see "https."
> When checking e-mail, use secure Web sites that most Net providers offer.
> Install a program with pop-up alerts if someone tries to invade your computer. A free program called AirDefense Personal can be downloaded at www.airdefense.net/products/adpersonal/
> Be wary when using hotspots in places where business executives congregate. Data thieves target such areas.
> Disable file sharing on your computer. If you don't know how, open Windows help section and type in "file sharing."
> Use a virtual private network, called a VPN. Some businesses give employees a way to use a VPN to communicate with work.
> Consider storing sensitive information on removable storage such as a key-fob-sized storage unit that plugs into a USB port. That way you can simply remove the storage unit when connected to a hotspot.






Saturday - Sunday home delivery for as little as $1.47 a week- Subscribe now!
  EMAIL THIS PRINT THIS MOST POPULAR   Search our archives (back to 1985)
© 2005 The Atlanta Journal-Constitution | Customer care | | Visitor Agreement | Privacy Statement | Permissions