United Business Media EE Times


Search

HOMEMARKET INTELLIGENCE UNITFORUMSDESIGNNEW PRODUCTSCAREERSBLOGSCONTACTEVENTSSIGN UP!RSSMost Popular contentTrusted Sources

 


Insecurity stalks public WLAN
Print this article Email this article Reprints RSS Digital Edition

EE Times


MATHIAS_CRAIGOK, here's the scenario: You're getting on a public wireless-LAN network, and up comes the splash screen asking for your credit card number and expiration date, or your user name and password. The little Secure Sockets Layer lock glyph is on, so off you go. But the response is a message like "system down for maintenance" or, worse, you get connected.

I say "worse" here because you've just been spoofed-the access point you associated with is actually a soft AP on a notebook, and someone is now merrily capturing everything you send and receive. At best, your ID or credit card info has been compromised.

Has something like this actually happened yet? Not to my knowledge, but this hypothetical scenario can strike a cautionary note for one of the most important emerging elements of the wireless industry today. Private WLANs will play a critical role in the ubiquity of Wi-Fi, as well as in the future of cellular operators.

I'm very cautious when I use a private WLAN, which is rarely. The problem has its roots in two areas. First, operators want to allow essentially anyone with the right hardware to pay the (sometimes exorbitant) fee. This means that potential users aren't always pre-authenticated and, thus, otherwise secret data needs to be exchanged. The connection can be secured against eavesdroppers, except, of course, for the spoofer. The second problem is that users don't often check for the validity of digital certificates and, clearly, these can be spoofed as well. This is completely unlike the world of the cellular phone, where authentication information is pre-shared and the protocol for its exchange difficult to spoof.

The public WLAN industry doesn't yet view this as a major problem, and therefore isn't devoting the resources required to fix it. I think the solution will ultimately be in client software, like that available from PCTEL, Smith Micro and Boingo, to name a few. What's needed

is a single client that logs into the public wireless network, carefully checks certificates and builds the VPN tunnel to where the user really wants to go. There is, I must stress here, no such thing as absolute, total security-but such an approach would take much of the worry out of the process.

Craig J. Mathias is principal of Farpoint Group (Ashland, Mass.).





The views and opinions expressed in this column are strictly those of the author and should not be taken as an editorial position of EE Times or any of its other editors, publications or Web sites.


  Free Subscription to EE Times
First Name Last Name
Company Name Title
Email address
  Click here for your Free Subscription to EETimes Europe
 
CAREER CENTER
Looking for a new job?
SEARCH JOBS
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
Engineers take a bad year in stride
According to the findings of the 2009 EE Times Global Salary & Opinion Survey, generally, engineers are satisfied with their career choices.

For more great jobs, career related news, features and services, please visit EETimes' Career Center.


All White Papers »   

 
Education and
Learning


Learn Now:












Home | About | Editorial Calendar | Feedback | Subscriptions | Newsletter | Media Kit | Contact | Reprints|  RSS|   Digital|  Mobile
Network Websites
International
Network Features




All materials on this site Copyright © 2009 TechInsights, a Division of United Business Media LLC All rights reserved.
Privacy Statement | Terms of Service | About