« Notes from Amsterdam | Main | .local under Linux »

Hotspot insecurities: Credit card data at risk.

Mainstrem media talk about evil twins, the security monkey points to stories of hotspot billing systems being so widely open that users can easily reconfigure hotspots to free-of-charge mode. Hotspots are insecure, it seems.

But what does "insecure" or "secure" mean when you talk about a wireless hotspot?

When thinking about the security or insecurity of a hotspot, one has to distinguish between two aspects.

On the one hand, there are the general risks that come from unencrypted wireless connectivity. These are well-known, and can be controlled by using VPN or actual end-to-end security technologies. These risks are relatively boring.

The more interesting attack avenues are created by hotspot operators' bad use of security technology when it comes to their payment systems: How often have you seen warnings about unknown CAs, about self-signed certificates, about non-matching host names, or about the unreachability of a revocation list when trying to securely connect to a commercial hotspot? In all these cases, hotspot operators undermine the security technology that is meant to protect your credit card information or your hotspot user name and password information. In all these cases, hotspot operators give their users a choice between securing their data or using the service.

TrackBack

TrackBack URL for this entry:
http://log.does-not-exist.org/mt/mt-tb.cgi/1394

About

This page contains a single entry from the blog posted on February 11, 2005 2:25 PM.

The previous post in this blog was Notes from Amsterdam.

The next post in this blog is .local under Linux.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.35