http://www.asiamedia.ucla.edu/article-southasia.asp?parentid=95536
INDIA: Experts apprehensive about Wi-Fi service misuse Hacking of US national Ken Haywood's Wi-Fi network exposes the system's security vulnerability, says cyber experts The Times of India Saturday, August 2, 2008 By Kumar Manish When US national Ken Haywood's Wi-Fi service was hacked into to send email warnings to media houses just before the serial blasts in Ahmedabad on July 26, it showed the vulnerability of the system. And, with a high percentage of Wi-Fi users in the city -- mostly corporate houses, educational institutes, coffee shops and government buildings -- experts are apprehensive about its misuse and questioning the security measures. Cyber expert Sunny Vaghela, who did a security check at different locations in the city, feels Wi-Fi services could well be vulnerable. "The Wi-Fi network at the city police headquarters and at places like Ahmedabad Municipal Corporation and malls on SG Highway with Wi-Fi connetivity can be easily hacked into without anyone noticing. One can send hate or terror mails through this service. The security-less Wi-Fi is just like unlocking your door and inviting thieves to steal," says Vaghela. "To make the service user-friendly , service providers compromise on security aspects, making it easier for misuse without the knowledge of Wi-Fi users," adds Vaghela. In Mumbai, the Brihanmumbai Municipal Corporation (BMC) is reviewing its plan to make the city Wi-Fi-enabled after revelations that the Ahmedabad terror email was sent by hacking into the Internet Protocol address of Haywood, living in Navi Mumbai. Police believe that the hackers misused the Wi-Fi of the American. The civic body is also having second thoughts about Wi-Fi plans for its central disaster management cell at a cost of Rs 85 lakh. The Rs 50-crore Wi-Fi project for the city would have enabled anyone with a PC or a laptop to access the internet without having to plug in. "But given the possibility of misuse of Wi-Fi , we want to review our proposal and build in security provisions," said a senior BMC official. "Recently, we carried out a survey on Wi-Fi users in Ahmedabad. Surprisingly, almost 90 per cent of users have not changed their default password of wireless router necessary for Wi-Fi services. This makes it easy for hackers to get into the system without anyone tracing them. These default passwords are easily available on the internet," says CEO of Icenet, Chirag Mehta, who has done extensive work on Wi-Fi and its security aspect. Pointing out serious flaws in Wi-Fi facilities , Sujal Nanavaty, director of a city-based software company said, "Professional hackers have alternative methods which are easily available on the web to hack into any system." WI-FI & SECURITY Wireless technology eliminates cabling, switches, adapters, plugs, connectors A WiFi-enabled device (PC, game console, mobile phone, MP3 player or PDA) can connect to the net when within the 'hotspot' of a wireless network Encryption helps obscure info to make it unreadable without special knowledge, key files and passwords. The Wi-Fi encryption standard, Wired Equivalent Privacy (WEP), is easily breakable even when configured. Wi-Fi Protected Access (WPA, WPA2) aims to solve this problem Wi-Fi access points default to an 'open', or encryption-free, mode. Novices benefit from zero-configuration , but this provides open access. To turn security on requires configuration Wi-Fi networks that are open (unencrypted) can be hacked, unless another security method is used. Early in Wi-Fi use, open access was encouraged to cultivate a wireless community. Later, whitelists of users were created Wardriving is recreational mapping of others' open points WEP encryption can protect against casual snooping, but freely available tools can recover WEP encryption keys. WPA and WPA2 encryption standards do not have any of the serious weaknesses of WEP encryption With wired networking it is necessary to get past a firewall, security guard and locked doors. With wireless it is only necessary to get reception Piggybacking is using open (unencrypted) Wi-Fi networks as a free service Date Posted: 8/2/2008
