Defeating the Evil Twin

Opinion
Feb 2, 20053 mins

* The Evil Twin reawakens

The British press recently got hold of a wireless threat that’s been around for years and reintroduced it to the paranoid public. Now called the “Evil Twin,” the threat is also known as “Wi-Fi phishing,” “AP phishing” and “AP spoofing.”

The Evil Twin has reared its head infrequently so don’t stay up nights fretting about it. Just be aware of a couple measures you can take to protect your traveling business users against it.

This particular threat involves someone misdirecting wireless connections to an access point (AP) that masquerades as a legitimate one by using the same service set identifier (SSID), or network name. Usually, the goal is to steal user credentials or other information.

The perpetrator might pluck the desired information out of the air or attach the Evil Twin to a server that displays a phony Web page resembling a Web site a user is trying to reach; say, that of a particular Wi-Fi hot spot provider. If the user fills out a form at the phony page, of course, the hacker can use that info later.

Hot spots, in particular, are Internet-access anomalies for business travelers. Hot spot providers, of course, want to encourage usage to get revenue, so their networks are open. “Open” and “secure” are generally at odds with one another.

So it’s a good idea for corporate IT to have a policy in place for how users should tread in these areas.

For example, you might mandate that when users connect to the Internet using corporate laptops, they do so only via a corporate IP VPN connection. If you’re willing to allow direct Internet connections that bypass a corporate VPN (or if you don’t run a VPN), you might want to only allow wireless use in hot spots operated by providers that you can verify monitor for Evil Twins using tools from companies such as AirDefense or AirMagnet.

“It’s incumbent on the hot spot provider to take action to protect its users,” asserts Rich Mironov, AirMagnet’s vice president of marketing.

Some hot spot providers, such as T-Mobile, are rumored to be offering such protection – yet, for some reason, it’s pretty cloak-and-dagger about who’s actually performing the monitoring functions to keep you safe.

Finally, you may wish to run special client scanning systems that put that monitoring control in your own hands. AirDefense offers a client product – AirDefense Personal for enterprise users and AirDefense Personal Lite, announced last week for consumers – that automatically identify a phony AP based on a number of variables, such as information in a beacon frame, says Richard Rushing, AirDefense chief security officer.

The “Lite” version, available for free at https://www.airdefense.net/products/adpersonal/trial.php4, sends 13 different popup alarms when certain connections kick in (such as a wireless association with an Evil Twin or an ad hoc network or a Bluetooth connection firing up) and explains to the user how to shut them down, if desired. The enterprise version can be set up by the IT department to automatically shut down the wireless network interface card if these or other situations present themselves.