Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Focus on Apple
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 11:50AM
Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 03:11PM
Howard Oakley (h oakley btconnect com) (4 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 12:23PM
Radoslav Dejanoviæ (radoslav dejanovic opsus hr) (1 replies)
On Thursday 10 August 2006 17:11, Howard Oakley wrote:
> > This IS really bad for companies, for they can throw away their
> > security measures if all it takes to get the data is a vulnerable
> > computer reachable from the car parked outside the well guarded
> > building.
>
> How many corporates actually use wireless networking inside their
> firewalls etc.?

A LOT!

Speaking from my experience, of course.
There are mostly two cases in play:

a) the company decides they do need wifi access for any reason;

b) some manager discovers that there's a way to avoid plugging ethernet
cable into the notebook every time (s)he returns to office.

Point b is troublesome one. If a company decides they want to use wireless,
they would probably have done it correctly, either by having their IT
department plan and deploy, or by outsourcing this to some IT company.

If a boss, however, decides that (s)he wants a wireless connection, it
might just end up being patched by an inexperienced IT employee. Boss
doesn't care about any technobabble, and rarely want to listen about all
steps that should be done to securely implement wifi. If a boss wants
something, boss gets that.

There's third possibility, that someone in the company just decided to buy
a wifi card and use it on internal network (for "b" reasons).

> Unless they have very remote locations, I'd certainly never advise them
> to.

Neither do I, but it is hard to convince people that while this seems a
cool technology, it might be a pretty big security risk and should be
avoided if possible. I talk to the people - and they tell me that having
wired connections is sooo "pase", and they're cool company that has to use
cool technology.
But I do have more success with my ICT-oriented clients, at least they can
understand what I'm trying to tell them. :-)

--
Radoslav Dejanoviæ
Operacijski sustavi d.o.o.
http://www.opsus.hr

[ reply ]
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 03:22PM
Roy Atkinson (roy atkinson jax org) (2 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 06:51PM
Chris Pepper (pepper reppep com) (1 replies)
RE: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 08:10PM
Todd Woodward (todd_woodward symantec com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 09:31PM
Sam Pierson (samuel pierson gmail com) (2 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 10:05PM
Howard Oakley (h oakley btconnect com)
RE: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 09:50PM
Todd Woodward (todd_woodward symantec com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 12 2006 09:12PM
Bill Weiss houdini+focus-apple (at) clanspum (dot) net [email concealed] (houdini+focus-apple clanspum net) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 14 2006 07:04AM
fwa266m mac com (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 14 2006 01:36PM
David Maynor (dmaynor gmail com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 14 2006 01:59PM
Massimo Marino (fwa266m mac com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 14 2006 03:08PM
David Maynor (dmaynor gmail com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 15 2006 08:51AM
Nicolas RUFF (nicolas ruff gmail com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 15 2006 01:01PM
David Maynor (dmaynor gmail com) (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 20 2006 07:21AM
Nicolas RUFF (nicolas ruff gmail com)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 11 2006 05:36PM
Sam Pierson (samuel pierson gmail com)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 06:42PM
Paul Schmehl (pauls utdallas edu)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 05:38PM
Michael Edwards (medwards digital-legal com) (1 replies)
How to persuade someone to switch off wireless Aug 11 2006 12:11PM
Radoslav Dejanoviæ (radoslav dejanovic opsus hr)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 04:42PM
mfossi securityfocus com (1 replies)
Re: Hijacking a Macbook in 60 Seconds or Less Aug 10 2006 05:55PM
Howard Oakley (h oakley btconnect com)







 

Privacy Statement
Copyright 2008, SecurityFocus