Feeds

WLAN security still dismal – survey

London Calling

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

The security of London's wireless networks remains pitifully slack.

The second annual survey of WLAN security revealed the number of wireless networks deployed in businesses across London has grown 300 per cent in the past year.

However the increased popularity of wireless networks hasn't been matched by realisation of the importance of extending proper security policies to WLANs.

The RSA- commissioned survey suggests that London businesses are becoming even more vulnerable to malicious hacking because of slack WLAN security. Possible risks include:

  • Computer eavesdropping on company secrets
  • Network disruption
  • Launching denial of service attacks using the cover of the unsuspecting company,

With a hand-held scanner, researchers were able to pick up information from company wireless networks by simply driving around the streets of London. The research identified that 63 per cent of the networks surveyed were left on default configuration, which clearly identifying the company owning the data and where it was coming from.

The overall security picture has barely changed from last year when, using the same methodology, researchers found 67 percent of London companies surveyed left their wireless networks poorly secured against potential attack.

Tim Pickard, strategic marketing director, RSA Security says: "We have seen a proliferation of the use of wireless networks around London, but the steps taken to secure these networks are still woefully inadequate."

"The research shows that many organisations are now at least encrypting their company data by securing wireless networks with virtual private networks but the problem has shifted to other areas."

Among the problems highlighted by the survey are:

  • Failure to effectively encrypt data travelling across wireless networks.
  • Equipment left in default configurations.
  • Insufficiently secured wireless network access points, potentially allowing crackers to set up rogue access points to capture company information.
  • Failure to secure data on wireless enabled laptops.

Independent security consultant Phil Cracknell, who wrote the report, comments: "Researchers stuck to the strict letter of the law in carrying out this survey and did not access any specific data but others clearly may not.



"Hackers could easily use this access to conduct cyber crime or to launch hacking attacks on other companies with complete anonymity."®

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.