- More porn sneaks onto the iPhone
- 'Swatting' case shows need to ban caller-ID spoofing
- Why the iPhone can't be "killed"
- Nortel enterprise chief wants to bring back Bay
- US sets final emergency responder wireless pilot
There's bad news for some retailers at this week’s National Retail Federation trade show in New York City, where WLAN security company AirDefense disclosed the findings of its four-day scan of local retailers’ wireless nets.
Watch a video on what AirDefense did in New York City.
Security for retail wireless nets is still bad, though improving, AirDefense found after scanning nearly 800 stores in the five NYC boroughs between Thursday, Jan. 10 and Sunday, Jan. 13.
About one third of the stores had no security at all, not even the minimal encryption provided by the flawed Wired Equivalent Privacy (WEP) protocol. Another third had weak encryption, such as WEP or the pre-shared key mode of the Wi-Fi Protected Access (WPA PSK) specification, which was originally intended as basic security for home or SOHO WLANs.
The final third showed a quantum improvement, according to AirDefense Chief Security Officer Richard Rushing: the more advanced WPA2 specification, with 802.1X authentication brought down to every device, including handhelds, on the WLAN, and AES encryption, the strongest commercially available today. “These are the first retail stores we’ve seen with bulletproof [wireless] security,” Rushing says.
Rushing has surveyed large retailers in sections of Manhattan in the past. The new scan was focused on smaller stores, 771 in all, in malls and shopping centers throughout the five boroughs. Rushing walked around with his notebook PC running the AirDefense monitoring and analysis software, simply observing the WLAN traffic in each store. No attempt was made to connect to any of the nets or launch penetration attacks.
In many of the sites, where the only network may be a DSL broadband router, Rushing also frequently found unprotected rogue access points deployed. He speculates that many of them are brought into stores so employees can run applications, make VoIP calls or get Internet access when not dealing with customers. But apparently, these unprotected devices are unknown to the store owners or managers, creating gaping net security holes. (Learn more about WLAN security in our Wireless LAN Security Buyer’s Guide.)
Another noticeable problem with the first two groups was that radio signals -- and thus access to the unprotected access points and unencrypted traffic -- spilled well beyond the walls of the store. Attackers could set up shop outside, snoop on the WLAN traffic, and collect MAC addresses and other data that could be used to hack deeper into the store’s net, servers and data.
Comments (2)
Stunning...By EJ on January 16, 2008, 9:05 amThat in the face of the TJX fiasco, companies still don't get it. Apparently it'll take a few more multi-hundred million dollar settlements before principals sit...
Reply | Read entire comment
RE: Wireless LAN scan finds big security holes in NYC retailers' wireless netsBy Anonymous on January 16, 2008, 8:56 amThe best thing corporate retailiers/business can do is buy and enterprise solution that allows central managment to these branch sites for encryption. Something...
Reply | Read entire comment
View all comments