Big Data. Big Decisions
InformationWeek
Special Coverage Series

Commentary

Kurt Marko

Kurt Marko

Contributing Editor

Securing Public Hotspots--Protect Yourself And Your Users

Encrypting Wi-Fi is critical to keeping it a reliable and safe method of access.

Wi-Fi, not wired Ethernet, is now the network access method of choice for most users, having become so cheap and pervasive, it's even available on $50 text message gadgets aimed at grade-schoolers (which are easily hacked into a Linux-booting, BackTrack-worthy, penetration-testing appliance; see more below). Yet what Wi-Fi offers in convenience, it lacks (in spades) in security, at least in a public setting. In fact, the exposure on an open, unencrypted network is worse than you think--about like taking a swim in a smelly, tepid cesspool. Here's why.

Most IT pros are familiar with Firesheep, the Firefox extension that snoops unencrypted networks (usually open Wi-Fi, but it also Ethernet), filters packets looking for common sites (Facebook is a favorite target), and captures their session cookies, allowing instant impersonation of the victim. But far more nefarious man-in-the-middle Wi-Fi attacks are relatively easy to set up and can not only capture data but transparently redirect the victim to bogus sites, opening the door to all kinds of fun exploits, whether it's making use of old, unpatched browsers to install a keylogger or cloning a banking site and hoping the rube on the other end doesn't notice the missing padlock symbol in the address bar.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

The more sophisticated of these types of attacks use a Wi-Fi honeypot, like the deceptively cute Pineapple (essentially a Fon access point running an OpenWrt package), which impersonates any SSID a client might be looking for, such as one the system has previously accessed and has configured to automatically reconnect to, essentially sucking in the Wi-Fi traffic from every client within range. In other words, when accessing unencrypted Wi-Fi APs, it's virtually impossible to know if you're being compromised.

Of course, WPA2 solves these vulnerabilities (although, even here, it's possible to exploit the WPA handshake and crack weak preshared keys), but because secure key management is a hassle, few public hotspots use it.

What's a poor road warrior to do? The best defense is to immediately establish a VPN tunnel, whether to your corporate network (make sure you're not split-tunneling and that all traffic is routed through the corporate WAN) or to a public provider, of which there are many (WiTopia is my favorite), upon making a Wi-Fi connection. Better yet would be for hotspot providers to start using encryption … if only there were an easier way. Thanks to Aerohive, there is.

Aerohive, one of those small, innovative, "we try harder" wireless LAN software and equipment vendors, developed what it calls Private PSKs (PDF) (preshared WPA2 key) two years ago, but the implementation was hampered by the need to individually set up and administer users--not a feasible situation for public networks. It has remedied this in the recent 4.0 release of the HiveOS/HiveManager software with an option for "secure guest self-registration" for PPSKs. While the software is still aimed at enterprises, Matthew Gast, Aerohive's director of product management, says it's also useful for public networks. Here's how it works.

Unlike traditional WPA-Personal (what most people use at home) keys, Private PSKs are unique, time-limited keys created for individual users on the same SSID. Since PPSK credentials are unique, a key from one user can't be used to derive keys for others. Furthermore, uniqueness allows network administrators to set each user's access policies, including virtual LAN, firewall policy, and quality of service.

The latest Aerohive software allows the keys to be delivered via a captive Web portal of the type many public hotspots already employ to get user acknowledgement of terms of service. This means that when people access an Aerohive-powered public hotspot and open their browsers, they are presented with their own, very random WPA2 keys. Getting onto the public Internet requires setting up a WPA2 connection using these private keys. While allowing a user to self-register is fine in many situations where a user's "right" to access a network isn't restricted, such as at coffee shops or airports, in some situations, such as at hotels or conference rooms, WLAN providers might want to verify a user's identity. Here, the Aerohive software allows preassigning a user ID (for example, the customer's last name concatenated with the room number), which that person must correctly enter in the Web portal before getting a private key.

Encrypting Wi-Fi is critical to keeping it a reliable, safe access method, and public hotspots remain the Wi-Fi architecture's Achilles' heel. A simple yet secure means of extending WPA2 security to situations where the user population is unknown and constantly changing is the next step in the evolution of public hotspots. While Aerohive has come up with an innovative and effective system, the industry really needs to develop a standard that can be deployed across WLAN platforms so that open, unencrypted Wi-Fi can become a thing of the past.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.