Feeds

Eircom wireless security flaw revealed

250,000 routers vulnerable to piggybacking

Internet Security Threat Report 2014

A serious security flaw has been uncovered in certain models of wireless broadband routers supplied to up to 250,000 of Eircom's residential and business customers.

The flaw allows the security encryption of an Eircom wireless network to be bypassed by outsiders, who can then "piggyback" on a customer's internet connection. In some cases, any files or data shared on the user's wireless network can also be accessed.

The Wired Equivalent Privacy (WEP) security protocol used by the Eircom-supplied Netopia 3300 and 2247 series routers requires a 16-digit network key to access the network, which is generated from the serial number of the router as well as some text which is converted to numerical values.

However, the eight-digit number used to identify each user's wireless network is also derived from the serial number. This identifier can be seen by anyone with a wireless-enabled computer in a radius of about 30 metres.

This particular security flaw aside, WEP itself has been criticised as being too vulnerable to attack from hackers. Conor Flynn, technical director of IT security firm RITS told ENN: "WPA2 (Wi-Fi Protected Access) is the only protocol that should be considered by any service provider. WEP is a predictable and easily-broken protocol. There are software tools online that will crack any WEP key in the space of two minutes."

Eircom's director of communications Paul Bradley defended the protocol, however, saying "WEP is an industry standard protocol used by telecoms providers around the world."

He went on to tell ENN that Eircom was working with its modem suppliers to offer more advanced security protocols, such as WPA2 and WPS (Wi-Fi Protected Setup). "We're looking at ways to offer these protocols to new customers and allow existing customers to retrofit them as well," he said.

A statement from Eircom confirmed that it was currently testing WPS-enabled devices with a view to offering them to customers sometime next year.

The current problem was first brought to light by a user of the Irish discussion forum boards.ie and soon after it was exposed programs began appearing online that automatically generated the network key when the network name was keyed in.

As of Tuesday morning, Eircom was offering instructions to customers on how to change their default WEP key via its website broadbandsupport.eircom.net. The company said it would also be contacting affected customers directly.

© 2007 ENN

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Same old iPad? NO. The new 'soft SIMs' are BIG NEWS
AppleSIM 'ware to allow quick switch of carriers
Arab States make play for greater government control of the internet
Nerds told to get lost in last-minute power grab bid at UN meeting
Brits: Google, can you scrape 60k pages from web, pleeease
Hey, c'mon Choc Factory, it's our 'right to be forgotten'
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.