Subscribe

WiFi an easy target for hackers

Michelle Avenant
By Michelle Avenant, portals journalist.
Johannesburg, 08 May 2015

WiFi often presents significant security risks.

So said Dominic White, CTO of SensePost, in an open interview via Twitter with ITWeb yesterday.

WiFi password protection is often flawed, says Dominic White of SensePost.
WiFi password protection is often flawed, says Dominic White of SensePost.

White will facilitate a WiFi hacking workshop at the ITWeb Security Summit 2015 later this month.

WiFi essentially does not provide a physical layer of security, and password protection is often flawed, White elaborated.

"The most general root cause [of these problems] is 'mistakes made in initial implementation that can't be fixed'," he said.

"The immediate concern is to figure out how this affects your organisation. There are lots of variables," he continued, advising that each organisation be aware of its own unique risks and develop solutions that best suit its context.

Insecure WiFi can compromise the security of cloud data, White warned, adding the large amount of data stored in a cloud taunts man-in-the-middle attackers with a particularly bountiful reward.

Where the general public is concerned, White noted that the burgeoning Internet of things embodies sobering security hazards, as many smart household appliances are not equipped with the same defence mechanisms as devices such as smartphones, tablets or computers, some of which are as simple as having a keyboard suitable for entering WPA passwords.

White also warned that although WiFi access in general needs to broaden and improve, city-wide WiFi projects present an easy target for hackers. For hacking victims, it is not always easy to distinguish between a malicious and a harmless connection, he added.

On the bright side, White said the insecure coffee-shop WiFi so many users capitalise off is trustworthy "for the most part", as hackers need to be on the same network as their victims, making hacking small localised networks a difficult activity to scale.

Share