http://www.asiamedia.ucla.edu/article-southasia.asp?parentid=95536

INDIA: Experts apprehensive about Wi-Fi service misuse
Hacking of US national Ken Haywood's Wi-Fi network exposes the
system's security vulnerability, says cyber experts

The Times of India
Saturday, August 2, 2008

By Kumar Manish

When US national Ken Haywood's Wi-Fi service was hacked into to send
email warnings to media houses just before the serial blasts in
Ahmedabad on July 26, it showed the vulnerability of the system.

And, with a high percentage of Wi-Fi users in the city -- mostly
corporate houses, educational institutes, coffee shops and government
buildings -- experts are apprehensive about its misuse and questioning
the security measures.

Cyber expert Sunny Vaghela, who did a security check at different
locations in the city, feels Wi-Fi services could well be vulnerable.

"The Wi-Fi network at the city police headquarters and at places like
Ahmedabad Municipal Corporation and malls on SG Highway with Wi-Fi
connetivity can be easily hacked into without anyone noticing. One can
send hate or terror mails through this service. The security-less
Wi-Fi is just like unlocking your door and inviting thieves to steal,"
says Vaghela.

"To make the service user-friendly , service providers compromise on
security aspects, making it easier for misuse without the knowledge of
Wi-Fi users," adds Vaghela.

In Mumbai, the Brihanmumbai Municipal Corporation (BMC) is reviewing
its plan to make the city Wi-Fi-enabled after revelations that the
Ahmedabad terror email was sent by hacking into the Internet Protocol
address of Haywood, living in Navi Mumbai.

Police believe that the hackers misused the Wi-Fi of the American. The
civic body is also having second thoughts about Wi-Fi plans for its
central disaster management cell at a cost of Rs 85 lakh. The Rs
50-crore Wi-Fi project for the city would have enabled anyone with a
PC or a laptop to access the internet without having to plug in. "But
given the possibility of misuse of Wi-Fi , we want to review our
proposal and build in security provisions," said a senior BMC
official. "Recently, we carried out a survey on Wi-Fi users in
Ahmedabad. Surprisingly, almost 90 per cent of users have not changed
their default password of wireless router necessary for Wi-Fi
services. This makes it easy for hackers to get into the system
without anyone tracing them. These default passwords are easily
available on the internet," says CEO of Icenet, Chirag Mehta, who has
done extensive work on Wi-Fi and its security aspect.

Pointing out serious flaws in Wi-Fi facilities , Sujal Nanavaty,
director of a city-based software company said, "Professional hackers
have alternative methods which are easily available on the web to hack
into any system."

WI-FI & SECURITY

Wireless technology eliminates cabling, switches, adapters, plugs, connectors

A WiFi-enabled device (PC, game console, mobile phone, MP3 player or
PDA) can connect to the net when within the 'hotspot' of a wireless
network

Encryption helps obscure info to make it unreadable without special
knowledge, key files and passwords. The Wi-Fi encryption standard,
Wired Equivalent Privacy (WEP), is easily breakable even when
configured. Wi-Fi Protected Access (WPA, WPA2) aims to solve this
problem

Wi-Fi access points default to an 'open', or encryption-free, mode.
Novices benefit from zero-configuration , but this provides open
access. To turn security on requires configuration

Wi-Fi networks that are open (unencrypted) can be hacked, unless
another security method is used. Early in Wi-Fi use, open access was
encouraged to cultivate a wireless community. Later, whitelists of
users were created

Wardriving is recreational mapping of others' open points

WEP encryption can protect against casual snooping, but freely
available tools can recover WEP encryption keys. WPA and WPA2
encryption standards do not have any of the serious weaknesses of WEP
encryption

With wired networking it is necessary to get past a firewall, security
guard and locked doors. With wireless it is only necessary to get
reception

Piggybacking is using open (unencrypted) Wi-Fi networks as a free service

Date Posted: 8/2/2008

Reply via email to