Feeds

UK retail Wi-Fi security still patchy

War walk on the wild side

Security for virtualized datacentres

Wi-Fi security in UK retail environments is improving, but shops remain vulnerable to the sorts of attacks carried out as part of the infamous TJX credit card heist.

The cybercrooks, who lifted more than 21 million credit card records, leapfrogged onto the retailer's credit card database after first breaking into the wireless network of a regional store, a subsequent investigation ahead of upcoming US trials revealed. The incident ought to have acted as a wake-up call to retailers worldwide, but progress has been a little slow.

A Wi-Fi war walk, passively detecting Wi-Fi networks in a popular shopping areas around Oxford Circus last week, revealed numerous problems.

Data was collected over a one hour period on 16 December using security scanning tools from Motorola AirDefense. No networks or devices were actively compromised during the exercise

In all, over 300 Access Points (APs) and 400 wireless clients were passively detected during the exercise. Almost three in four (71 per cent) of APs were set up for 802.11g access. Nearly one in four (21 per cent) of networks detected were running the older 802.11a protocol. These older networks are used to support mobile scanners, making them popular in retail environments.

A quarter of the networks (25 per cent) detected were set-up without any encryption while a further 21 per cent were protected only by easily breakable WEP encryption. Although some of the networks with no crypto were likely to be related to hotspot services available in cafe’s and other outlets for consumer access, there still were many identifiable business Wi-Fi networks using no encryption at all.

Motorola AirDefense found that a further 18 per cent of networks were using TKIP encryption, a modified version of WEP that rotates keys with every packet for extra security. However recent attacks have also revealed flaws in the TKIP protocol. Only 20 per cent of the Wi-Fi networks identified during the exercise were using the recommended AES/CCMP encryption.

Only 3 per cent of the stations were using AES/CCMP encryption and only 6 per cent of the networks discovered were using enterprise class IEEE 802.1X authentication. All others had either no authentication for users or relied on a shared key.

Diane Johnson, Motorola AirDefense manager EMEA, noted other common problems identified during the test, including naming a Wi-Fi network with the same name as a store, making it easier for crooks to identify potential targets. Cybercrooks want to use access to retail branches as stepping stones towards corporate networks that contain a much greater cache of goodies. Running flat networks with no VPNs makes it easier to map corporate networks and attack database systems, the sort of attack carried out by the TJX hackers.

For all the problems identified during the exercise, Johnson said that the security of UK retail networks had improved from the last time it carried out a similar exercise in London back in September. Furthermore, it was generally better than those of similar environments elsewhere in Europe. She attributed the improvements over recent months to changes made so that retailers could achieve compliance with the credit card industry's PCI DSS standard for merchants.

Motorola's exercise also highlighted potential dangers for businessmen and Christmas shoppers taking advantage of West End hotspots to catch up with some surfing.

More than 25 per cent of stations detected were probing for open hotspots, with 10 per cent probing for "free public Wi-Fi". Machines configured in this way could easily become subject to an Evil Twin-style attacks using a fake hotspot or ad hoc network. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.