joanie_wexler
Writer

A few outstanding questions for AT&T

Opinion
Apr 20, 20102 mins

* Probing under the hood of network-to-network handoffs

I recently published a statement I received from AT&T in this space about how its auto-authentication mechanism works when the mobile operator hands off traffic — in particular, voice calls — from its 3G network to an AT&T Wi-Fi Hot Spot. The statemen outlined basic process that occurs when the session moves from one network to another.

I recently published a statement I received from AT&T in this space about how its auto-authentication mechanism works when the mobile operator hands off traffic — in particular, voice calls — from its 3G network to an AT&T Wi-Fi Hot Spot. The statement outlined basic process that occurs when the session moves from one network to another.

I asked Lisa Phifer, President of consulting firm Core Competence and a wireless security specialist, if she thought that the explanation enabled us to determine whether the network-to-network handoff should be considered secure. She said she didn’t think the carrier provided quite enough information for us to know. She had a few follow-up questions for AT&T, which I’ve submitted and am still awaiting answers for.

AT&T’s new spring smartphones

Her primary question was about how AT&T’s auto-authentication would distinguish between an AT&T Wi-Fi Hot Spot, an enterprise’s own Wi-Fi network and any old Wi-Fi network and then allow/not allow and manage the hand-off appropriately. Here’s what Lisa said:

“What I do wonder about…is how any associated AT&T Wi-Fi connection management might dovetail (or not) with enterprise Wi-Fi connection management on the same device. Will the phone go probing for the hotspot SSID and any enterprise-configured or home-configured SSID, all at the same time? Presumably voice call handoff won’t occur if the phone doesn’t get associated and authenticated by the real-deal-hotspot SSID, but… does this create cases where the phone might automatically find and associate to another (non-AT&T, potentially unsecured) SSID without the user’s knowledge?

“If that should happen, data traffic might then be sent over (non-AT&T) Wi-Fi instead of 3G. Can’t tell without knowing how the carrier is managing the Wi-Fi connection. But that’s what would trouble me.”

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author