Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Coffee shop WiFi for dummies
Scott Granneman, 2006-02-09

The average user has no idea of the risks associated with public WiFi hotspots. Here are some very simple tips for them to keep their network access secure.

Comments Mode:
WiFi for dummies 2006-02-09
Greg
One thing to note - Using Firefox (or others) instead of Internet Explorer is not enough. All software has bugs, and Firefox itself has had a number of serious vulnerabilities announced in the past few months. The nice thing about Firefox is how fast they generally patch bugs when they're found.
...

[ more ]  [ reply ]
WiFi for dummies 2006-02-09
Mike Heffner
Scott,

Great article (as usual), but (isn't there always one of those? :-), Yahoo! Mail now submits your password over SSL. Of course, once you're in, it's good ol' HTTP for you!

Mike
...

[ more ]  [ reply ]
WiFi for dummies 2006-02-09
Anonymous
title should have been "Marketing for coffee shop business"...

[ more ]  [ reply ]
WiFi for dummies 2006-02-09
Anonymous
Actually, all of this is usefull at all times.

Never ASSUME your network is secure just because you are in the office.

Always encrypt....

[ more ]  [ reply ]
WiFi for dummies 2006-02-09
Anonymous
Good article, but I think you could mention about the needs of a firewall to protect the user from malicious attacks when attached in a coffee shop....

[ more ]  [ reply ]
WiFi for dummies 2006-02-10
Phil from NY
Great tips, Scott!

Anyone looking for some more advice should check out the "Open Wireless Access Points" episode of the "Security Now!" podcast:
http://www.grc.com/SecurityNow.htm#10

And when you want to get *really* secure when connecting to a public wireless network, by setting up a secure...

[ more ]  [ reply ]
WiFi for dummies 2006-02-10
Sid (2 replies)
OK, WEP is better than nothing. But no the other hand, it's so heavily crippled it cannot be seriously called a security feature.

Considering that, is it still pertinent to mention WEP usage ? Would not it be far more wise to tell people not to use WEP anymore and move to WPA which usage on dummi...

[ more ]  [ reply ]
Re: WiFi for dummies 2006-02-11
stacy (1 replies)
WEP is better than nothing in the same sense that if your roof gets blown off, a tarp is better than nothing; but it is still not a solution to the problem.

A couple points about public hotspots:
1) The usage of encryption at the wireless level is the choice of the wireless provider, not you. So...

[ more ]  [ reply ]
Re: Re: WiFi for dummies 2006-02-15
Sid
I really don't see the point in your comparison. I would have said that WEP is a tarp with no roof...

My point is, and it's especially applying to public accesses, that WEP is bringing close to nothing in terms of security. It does not bring confidentiality, nor between users, nor against eavesdr...

[ more ]  [ reply ]
Re: WiFi for dummies 2006-02-13
Anonymous
WEP isn't better than nothing. It is nothing, at least from the perspective of the user of a public hotspot. WEP provides no protection against one machine on that WLAN from reaching another. Thus, it is exactly the same protection as nothing.

The article would have achieved more good if it pu...

[ more ]  [ reply ]
WiFi for dummies 2006-02-10
Maxim
A small correction: Gmail DOES use https for reading/sending emails - just type https://mail.google.com/mail/ or assure that "continue" parameter in URL start with https....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-10
Edgard Tanieda
Don't be paranoic USING IE YOU'LL BE HACKED, FIREFOX is the same crap ... Long Live Gopher Time!...

[ more ]  [ reply ]
Coffee shop WiFi for dummies - Gaim part 2006-02-12
Jean-Philippe
Sure Gaim is a nice IM, especially for the multi-connectivity part of it.
If you save your password keep in mind that they are in plain text in the accounts.xml file on the PC running Gaim.
http://gaim.sourceforge.net/plaintextpasswords.php...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-12
Jim Driscoll
Scott
Great article for US dummies,I had no idea of the risk,Your article opened My eyes !
Also the follow up comments were very helpfull as
well.
Jim Driscoll...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-12
Paul
Great article. Anything that helps minimize security threats is a plus.

Wanted to mention in the new IE7, setting similar security for GMAIL is possible by simply customizing the GMAIL button in the Google toolbar. It's not necessary to have FireFox to use apply this setting....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-13
j (1 replies)
Also, never assume that by using your corporate VPN that ALL of your traffic will be encrypted. That is the best way to set it up but many companies still only encrypt business traffic and not web traffic (including personal e-mail). Double check with your IT folk, if they say that they encrypt ev...

[ more ]  [ reply ]
Re: Coffee shop WiFi for dummies 2006-02-15
Anonymous (1 replies)
j
even without split tunneling wouldn't the return traffic come back unencrypted? I think so.
j...

[ more ]  [ reply ]
Re: Re: Coffee shop WiFi for dummies 2006-02-16
j
Nope, all traffic coming and going goes though the VPN when split-tunneling is disabled. Basically it takes over your default route as opposed to just putting in a few routes....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-13
Anonymous
Another thing to note about WiFi encryption- if ALL of the customers are to use WEP/WPA, then one would reasonably assume they might all have the same WEP/WPA encryption key. If so, then using WEP/WPA is completely totally pointless as everyone will still see everyone's traffic....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-13
Paul R. from Rome, NY
All security features are part of a SYSTEM that includes the USER. SSL is no exception. Just because you're using a SSL-protected web site (and you have the comforting little padlock in the corner of you browser), doesn't mean that someone at the coffee shop hasn't poisoned the ARP tables and issu...

[ more ]  [ reply ]
Use a VPN for God's Sake 2006-02-13
Anonymous
Seriously, most of these people are going to have a high speed connection at home. Set up a VPN on your system at home, then have your laptop connect to and route all the traffic through that VPN. Sure, it's a little slower because of company upload caps that are usually in place, and because you're...

[ more ]  [ reply ]
Gmail does support https... 2006-02-14
Anonymous
You just have to go to https://gmail.google.com rather than http.
...

[ more ]  [ reply ]
RE: Coffee shop - Just say NO to Google! 2006-02-15
Anonymous (1 replies)
Interesting article however, given the latest news surrounding Google's policies on privacy and information security, I would NOT recommend using Google for anything.

For more information take a look at these sites:

http://www.gmail-is-too-creepy.com/

http://www.scroogle.org/
...

[ more ]  [ reply ]
Vindictive whackos just say NO to Google! 2006-02-17
Roger (1 replies)
"...given the latest news surrounding Google's policies on privacy and information security..."

You mean the news about how every other company hit with the US Federal subpoenass buckled without so much as a whimper, while Google is fighting them tooth and nail to protect your privacy?

"For mo...

[ more ]  [ reply ]
Re: Vindictive whackos just say NO to Google! 2006-05-07
Anonymous
Really ? Lawyers can subpoena your private key ? I was supposed there is something in laws about you are allowed to not witness against yourself or against close family ......

[ more ]  [ reply ]
Coffee shop WiFi for dummies - VPN won't always help 2006-02-15
Anonymous
Most VPN's I know of will only encrypt traffic destined for the corporate lan.
For instance, if I log onto my gmail or bank account the vpn is smart enough to know that the destination is not on the corporate lan and send it out unencrypted over the public network.
On the other hand if I log in t...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-02-15
Lizard
What about your shared drives? You may want a note about serving up your entire laptop's data to anyone in a 500 foot radius when you do attach without a key. Personal firewalls, blocking "Microsoft Networking" are a must - regardless of the network you are jacking into....

[ more ]  [ reply ]
What about something like www.publicvpn.com ??? 2006-02-15
Anonymous (1 replies)
What about something like www.publicvpn.com ???...

[ more ]  [ reply ]
Re: What about something like www.publicvpn.com ??? 2006-02-16
stacy
Talk about an oxymoron; a PUBLIC virtual PRIVATE network. How about just using some hacker repellant?
http://www.ranum.com/security/computer_security/marketing/ha
cker-repellant-small.jpg

Seriously, if your only concern is eavesdropping by people within a few hundred feet of the hotspot, then thi...

[ more ]  [ reply ]
Gmail via SSL 2006-02-15
Ricky
Just use https://mail.google.com

But if Google submits your information you are still not secure, especially if Google does not encrypt all stored messages using key that their employees don't know......

[ more ]  [ reply ]
Recommending gaim? HAH 2006-02-17
infamous41md (1 replies)
You have the nerve to criticize IE and Skype for their security records, but yet at the same time you actually recommend GAIM? The code in GAIM is some of the shoddiest I have ever audited, and that's saying a lot. Oh the 0day. Perhaps you should leave commenting on the relative security of progr...

[ more ]  [ reply ]
Re: Recommending gaim? HAH 2006-02-19
Roger (1 replies)
Umm, that's interesting, but at least you *have* given Gaim a code audit, unlike IE and Skype which are closed source. And that's reflected in the vulnerability disclosures: since getting up to version 1 around 16 months ago, Gaim has had 13 vulnerabilities published, of which nearly all were non-cr...

[ more ]  [ reply ]
Re: Re: Recommending gaim? HAH 2006-02-20
infamous41md (1 replies)
I alone reported I think 5 vulns to the developers, several of which could be exploited.Sometime right around when I reported those someone else reported 12, plus there have been numerous other reports since then. I'm not sure where your numbers are coming from, but they're slightly off. The devel...

[ more ]  [ reply ]
Re: Re: Re: Recommending gaim? HAH 2006-02-23
Roger (1 replies)
> I'm not sure where your numbers are coming from, but they're slightly off.

Got 'em straight from Bugtraq.

> My bigger point is not that gaim sucks, which it does, but it's that "security columnists" should keep their mouth shut

How would that help anyone?...

[ more ]  [ reply ]
Re: Re: Re: Re: Recommending gaim? HAH 2006-02-24
infamous41md (1 replies)
The bugs I reported probably were never bugtraq'd.

> My bigger point is not that gaim sucks, which it does, but it's that "security columnists" should keep their mouth shut

>How would that help anyone?...

You didn't include my whole quote, but I take it that was sarcasm? In case it wasn'...

[ more ]  [ reply ]
Re: Re: Re: Re: Re: Recommending gaim? HAH 2006-03-01
Anonymous (1 replies)
Well You mister Auditer... If You did Audit the code it would be safer now. Unless You did not do Your job right?

And the comment about not talking is the freedom of speach. Deny that right at Your peril....

[ more ]  [ reply ]
Re: Re: Re: Re: Re: Re: Recommending gaim? HAH 2006-03-03
infamous41md
Safer? Hardly. Maybe just less of a choice of attack vectors to choose from. As I said I reported 5 or 6 vulns in gaim to the developers long ago. http://gaim.sourceforge.net/security/index.php. That was just the tip of the iceberg. More recent vulns I've kept b/c as I said the developers are ...

[ more ]  [ reply ]
Get a real ISP provider 2006-02-17
In Secure
My provider (www.kattare.com - I'm in no way associated with them other than a customer) allows secure IMAP, POP, SMTP, including the IMPORTANT option of sending to a different port (not 25, which as is implied in the article, might be blocked by the coffee-shop's ISP). In my case, I check "Send ma...

[ more ]  [ reply ]
Wrong! Yahoo logins are SSL'd by default 2006-02-19
Anonymous
Uh, check again. Yahoo as been encrypting Yahoo Mail logins....

[ more ]  [ reply ]
You forgot one of the most important... 2006-02-26
Anonymous (1 replies)
If the WiFi isn't free, or if you have to establish some unique identity to use it, beware of rogue gateways. Any of the other laptops could be putting out a stronger signal and be presenting a fake login page. If you're sitting far from the real transmitter, it can be a problem. And since you do...

[ more ]  [ reply ]
personalVPN 2006-03-08
Anonymous
Quickest way around all thse issues is to use a service like WiTopia's personalVPN. It's based on openVPN (very powerful) and builds an encrypted SSL tunnel from wherever you are to the Internet. http://www.witopia.net Only $39.99 a year and works with Mac or PC. ...

[ more ]  [ reply ]
Miranda 2006-08-31
Lo Yuk Fai
Very informative, good job.

Besides GAIM, there's also Miranda, which has some encryption plug-ins and work with many IM networks, albeit only for Windows....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-09-14
Anonymous
I am opening a coffee shop in a month and trying to decide whether or not to get Wifi for the customers. I know somewhat about computers but I am no expert, Can some one tell me the best Wifi to get and what risk are involved. I have read the threaded discussions here but I am at a lost which is the...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-10-04
oreste
This article was very helpful, for users of email and IM, and also for computer people like me who are not security experts. However, I use Mozilla Thunderbird for email at work, a secure environment, and recently had to plug in GNU OpenPGP to send a secure email to someone in another company. Thi...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2006-12-25
Anonymous
Good Article! Anchorfree offers a free VPN service for all hotpot users known a hotspot shield. I would recommend that anyone who regularly uses HotSpots, consider this security measure. The reality is that HotSPots will always leave users vulnerable. If this concerns you, stay away from Hotspots ...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2007-01-24
Charlene - Prescott, AZ
Hey - thanks for the tips. I have been studying Computer Systems and Applications at the local community college for the last two years and have learned absolutely nothing! It is so nice to hear from a knowledgeable person. ...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2007-02-25
Anonymous
SMTP Problem; cannot send emails or how to send emails from Outlook when using a free WIFI hotspot?

Check this article out:
www.carevolution.nl/wififindsmtp.htm...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2007-05-21
Anonymous
A great Web site for finding free WiFi enabled Internet coffee shops is at http://www.openwifispots.com/category_free_wifi_wireless_hot
spot_Coffeeshops_7.aspx....

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2007-11-22
Coffee Guy
Great article - I forwarded it on to a few road warriors who are just waiting to be hacked...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2008-01-08
Anonymous
say what you want to.. I don't know how to CONNECT or even how to tell my laptop it connect on wifi.. Can u help me with that???????...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2009-03-23
pewterbot9
Customize Google extension does not work for latest version of Firefox. :(...

[ more ]  [ reply ]
Coffee shop WiFi for dummies 2009-06-23
Ken
Hello,
I've been tasked with making my friend's coffeehouse WIFI network secure. I can go WEP or WPA. The plan is to change the password every 2-3 hours during the working hours of the coffeehouse. The password would be printed on the customer's receipt. Not bullet proof I suppose, but we're tr...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus