Feeds

UK retail Wi-Fi security still patchy

War walk on the wild side

Remote control for virtualized desktops

Wi-Fi security in UK retail environments is improving, but shops remain vulnerable to the sorts of attacks carried out as part of the infamous TJX credit card heist.

The cybercrooks, who lifted more than 21 million credit card records, leapfrogged onto the retailer's credit card database after first breaking into the wireless network of a regional store, a subsequent investigation ahead of upcoming US trials revealed. The incident ought to have acted as a wake-up call to retailers worldwide, but progress has been a little slow.

A Wi-Fi war walk, passively detecting Wi-Fi networks in a popular shopping areas around Oxford Circus last week, revealed numerous problems.

Data was collected over a one hour period on 16 December using security scanning tools from Motorola AirDefense. No networks or devices were actively compromised during the exercise

In all, over 300 Access Points (APs) and 400 wireless clients were passively detected during the exercise. Almost three in four (71 per cent) of APs were set up for 802.11g access. Nearly one in four (21 per cent) of networks detected were running the older 802.11a protocol. These older networks are used to support mobile scanners, making them popular in retail environments.

A quarter of the networks (25 per cent) detected were set-up without any encryption while a further 21 per cent were protected only by easily breakable WEP encryption. Although some of the networks with no crypto were likely to be related to hotspot services available in cafe’s and other outlets for consumer access, there still were many identifiable business Wi-Fi networks using no encryption at all.

Motorola AirDefense found that a further 18 per cent of networks were using TKIP encryption, a modified version of WEP that rotates keys with every packet for extra security. However recent attacks have also revealed flaws in the TKIP protocol. Only 20 per cent of the Wi-Fi networks identified during the exercise were using the recommended AES/CCMP encryption.

Only 3 per cent of the stations were using AES/CCMP encryption and only 6 per cent of the networks discovered were using enterprise class IEEE 802.1X authentication. All others had either no authentication for users or relied on a shared key.

Diane Johnson, Motorola AirDefense manager EMEA, noted other common problems identified during the test, including naming a Wi-Fi network with the same name as a store, making it easier for crooks to identify potential targets. Cybercrooks want to use access to retail branches as stepping stones towards corporate networks that contain a much greater cache of goodies. Running flat networks with no VPNs makes it easier to map corporate networks and attack database systems, the sort of attack carried out by the TJX hackers.

For all the problems identified during the exercise, Johnson said that the security of UK retail networks had improved from the last time it carried out a similar exercise in London back in September. Furthermore, it was generally better than those of similar environments elsewhere in Europe. She attributed the improvements over recent months to changes made so that retailers could achieve compliance with the credit card industry's PCI DSS standard for merchants.

Motorola's exercise also highlighted potential dangers for businessmen and Christmas shoppers taking advantage of West End hotspots to catch up with some surfing.

More than 25 per cent of stations detected were probing for open hotspots, with 10 per cent probing for "free public Wi-Fi". Machines configured in this way could easily become subject to an Evil Twin-style attacks using a fake hotspot or ad hoc network. ®

Remote control for virtualized desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
prev story

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.