Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Letter: Privacy and security in the cloud and at Wi-Fi hotspots

I largely agree with John Harris's analysis (Why hackers and spooks want our heads in the cloud, 26 April), but his fixation with the idea of "cloud computing" is misplaced. "Cloud computing" is just another way of describing the "back end". We have had back ends in one form or another since computer-based systems were invented. Hackers from the criminal world and state-sponsored intelligence communities were just as active before the term "cloud computing" was popularised as they are now. The only real difference is one of scale.

Harris picking on Google was, of course, entirely justified. However, governments are not necessarily always going to be allies of big hi-tech companies. For example, in the last month alone the US Federal Trade Commission (FTC) has announced that it has entered into a binding consent decree under which Google has agreed to submit to a biennial independent audit of its privacy practices for the next 20 years. That is half as long again as the company has existed. And then two weeks after that the FTC also announced it was thinking about reviewing Google's potential monopoly dominance of the search engine market in the US, where it claims between 63% and 72% of the market. In Europe Google's share is over 90%. This is one reason why the European commission is already doing the same.

John Carr

London

•?Your article (Public Wi-Fi users risk identity theft as fraudsters create 'Evil Twin' fake hotspots, 26 April) served readers well in alerting them to the fact that care must be taken to preserve the security of user details when accessing the internet via Wi-Fi. What was less clear was the fact that they can protect their data by taking relatively simple steps.

First, anyone accessing the internet via Wi-Fi should make sure to look for the locked padlock symbol before entering login or other personal details. This symbol should appear at the bottom right-hand side of the web page you have accessed, or in the address bar. If it isn't there, think twice before using the page you have called up and beware of entering any confidential data. Second, if you are on a Wi-Fi service other than your own one at home, and you want to enter financial or other sensitive information, visit only sites that begin with "https" on every page (some use "https" only at login). These sites are more secure.

Users should also consider our free BT Openzone virtual private network download; this creates a secure link between devices and hotspots. Customers can find information on this and other aspects of security at www.btopenzone.com/help/security. At BT, we are proud to have provided the UK with more than 2.5m Wi-Fi hotspots. We take seriously the need to protect the security of people's data.

Chris Bruce

Chief executive officer, BT Openzone



View the original article here

READ MORE » Letter: Privacy and security in the cloud and at Wi-Fi hotspots

Xbox Live security alert follows PlayStation Network hack

In the midst of Sony's PlayStation Network security breach, Microsoft has had to issue its own security alert today. On the company's Xbox Live Status page, the following warning has been issued:

"Users may receive potential phishing attempts via title specific messaging while playing Modern Warfare 2.

"We are aware of the problem and are working to resolve the issue. We apologise for any inconvenience this may cause and thank you for your patience."

The problem appears to be restricted to one title, and is centred around the system's matchmaking process, which arranges online multiplayer gaming sessions. It seems to be a reasonably routine problem, but with fears over online security riding high, several industry news sources have picked up on it.

US games blog Kotaku has also reported that dozens of modified Xbox 360 machines previously banned from Xbox Live have been allowed back on to the service – but only for a short time. Users who had 'modded' their machines to run unnofficial applications and pirated games found that they could suddenly sign in to the Xbox Live service – even though they had previously been ejected in one of Microsoft's regular 'banhammer' sessions. However, shortly afterwards all the machines were reportedly banned again.

The speculation is that Microsoft may have been testing its infrastructure in the wake of the PlayStation Network hack, or that it was trialling its new Xbox 360 disc format, which is partially intended to prevent piracy by blocking the DVD firmware hack that's been exploitable on Xbox 360 for several years.



View the original article here

READ MORE » Xbox Live security alert follows PlayStation Network hack

Wi-Fi security flaw puts credit cards at risk

Guardian Wi-Fi security test The Guardian tests equipment to set up fake Wi-Fi hotspots at St Pancras International station in London. Photograph: Frank Baron for the Guardian

Millions of smartphone users and BT customers who use Wi-Fi wireless internet "hotspot" connections in public are vulnerable to fraud and identity theft, a Guardian investigation has established.

In tests conducted with volunteers – to avoid breaching telecommunications and computer misuse laws – security experts were able to gather usernames, passwords and messages from phones using Wi-Fi in public places.

In the case of the best-selling Apple iPhone 4 and other smartphone handsets, the information could be harvested without the users' knowledge and even when they were not actively surfing the web if the phone was turned on.

BT, the UK's biggest provider of such hotspots with five million of its "Openzone" connections in the UK in train stations, hotels and airports, admitted that it has known of the weakness for "years" and that it is working on a permanent fix. But it has no timetable for when it might be implemented.

Using a £49 piece of communications equipment and software freely available for download from the internet, the investigation established that crooks could set up bogus Wi-Fi "gateways" to which the latest generation of mobile phones would automatically connect. Once a connection is established, all the information passing through the gateway can be either be read directly or decrypted using software that will run on a laptop.

In another test, a fake Wi-Fi hotspot invited people to "pay" for internet access with their credit card – but required them to click a box to accept terms and conditions which clearly stated "you agree we can do anything we like with your credit card details and personal logins".

A number of people entered their details. The Guardian did not retain any users' details in the experiment.

Not only could the information be used to steal identities, hijack email accounts and commit fraud but also to gather information about individuals and company employees. With the information gained in our investigation, fraudsters could have bought goods online or sent multiple e-gift vouchers worth as much as £1,000 each to pre-set email addresses. It is believed that such vouchers are already being traded by crooks over the internet.

The attack works because public Wi-Fi hotspots have no form of identification except their name, which an off-the-shelf device can mimic. Many smartphones are sold with automatic connectivity to BT's Openzone Wi-Fi hotspots to enhance the contract and reduce the load on the mobile carrier's data network from the phones, while offering faster connectivity.

Jason Hart, chief executive of the security company Cryptocard in Europe, said: "An O2 iPhone will automatically connect, because BT Openzone connectivity is usually part of the package for free internet access. It will pass over its credentials and because it can see the internet through the hotspot, it will start sending and receiving data."

BT, which boasts of having 2.5 million Wi-Fi hotspots available to its 5 million broadband customers said: "This hack is known as 'Evil Twin' and has been known to the industry and others for some years."

The company is working with the Wireless Broadband Alliance, an industry group which aims to help hotspot providers deliver a "reliable and trustworthy" service, to introduce a security system known as 802.1x, which forces detailed authorisation when devices connect. But it is not clear whether the devices themselves will be able to detect fake hotspots.

Apple, manufacturer of the top-selling iPhone series, declined to comment. O2 did not respond to requests for comment.

BT broadband customers who agree to allow a part of their Wi-Fi bandwidth to be used publicly are, in turn, allowed to use the Wi-Fi of other subscribers. The resultant Wi-Fi community is called BT Fon and utilises wireless routers – boxes which broadcast the Wi-Fi signals – in people's homes. BT Openzone users have to provide usernames and passwords. Subscribers may use both services through their smartphones. On the first use anywhere, they must give a username and password – but after that, their phones forever hunt out hotspots with the names "BT Fon" and "BT Openzone" hotspots automatically, and will join them.

Stuart Hyde, the Association of Chief Police Officers' lead on e-crime prevention, said: "We became aware of the potential for criminals to use Wi-Fi in this way last year and have become increasingly concerned. All they need is to set themselves up in a public place with a laptop and a mobile router called 'BTOpenzone' or 'Free Wifi' and unsuspecting members of the public come along and connect to them.

"Once that happens, there is software out there that enables them to gather usernames and passwords for each site a user signs in to while surfing the net. And once criminals have access to your email accounts, Facebook account, Amazon history and so on, the potential for fraud and identity theft is very serious indeed.

"Until there are improvements in security, I would advise people to be very wary indeed when using insecure Wi-Fi in public places."

Professor Peter Sommer, a cyber-security expert at the London School of Economics, said: "This is all very alarming. It means that literally millions of people who use Wi-Fi in public could be at risk. If criminals are able to harvest the usernames and passwords of all the websites you visit, they could do significant damage in terms of identity theft and fraud.

"The safest route for existing users of mobile phones, particularly if they use BT Fon or Openzone, is to switch off their Wi-Fi when they leave home and only use it on systems they know to be secure – such as at home or at work. Everywhere else you use Wi-Fi – whether in a coffee shop, an airport, a railway station and especially out in the street – you are taking a calculated risk."

Experts commissioned by the Guardian conducted two exploits to demonstrate how crooks could cash in on bogus Wi-Fi gateways. In the first, Jason Hart set up his mobile Wi-Fi router, the size of a cigar packet, at St Pancras International station in London and soon saw half a dozen smartphones try to connect to it.

Only the phones of our volunteers were allowed to connect. Because modern smartphones regularly "push" email and other updates automatically, they sent the owners' usernames, passwords and messages through the bogus BT Wi-Fi gateway, in one case while the phone was in a volunteer's pocket. Free software downloaded from the internet was then used to decrypt and display the information on a computer attached to the router.

The Guardian is withholding details of this software, but was shown details of its workings, which uses the power of modern graphics chips to decode encrypted data.

For the second exploit, Adam Laurie, director of Aperture Labs Ltd, demonstrated how bogus Wi-Fi gateways can be used to harvest credit card numbers. He established a fake paid-for gateway with its own website at Waterloo station. Users are allowed on to a gateway web page but must pay to use it to access the internet.

First they must provide their name and credit card details – including the CCV security code on the back and the expiry date – and agree to a terms and conditions policy. Our usage policy warned potential subscribers that it provided no protection for their private information. Incredibly, during a 30-minute period in the station, three people agreed to the terms and conditions and tried to log on and provide credit card details. To avoid breaching the law, Laurie rejected all these approaches.



View the original article here

READ MORE » Wi-Fi security flaw puts credit cards at risk