Wi-Fi networks less private than ever

November 11, 2010 By Liz F. Kay

The local java joint or airport terminal might seem like the perfect location to log onto Facebook or troll Amazon for a deal. But for anyone who has accepted the convenience of unsecured Internet access, here's another reminder to be cautious about what information you share online.

When you use a wireless network - or even many wired ones - your communications are sent to every other computer on the network, said Seth Schoen, senior staff technologist at the Electronic Frontier Foundation, a nonprofit group that defends civil rights in the digital world.

For years, there have been readily available programs known as "packet sniffers" that intercept those communications. Schoen said he's given demonstrations where he's shown intercepted and as well as Google search terms. Until recently, it required a little bit of Internet know-how.

But now a programmer has released a browser modification called Firesheep that makes spying on certain information much, much easier - causing quite a stir in the computer world.

Some sites such as Facebook encrypt your information when you're entering your password to log on - denoted by the padlock at the bottom of the browser. But afterward, it saves a credential on your computer that indicates you're currently logged on and reverts to its unencrypted version.

A nefarious user could then intercept and copy that credential into another browser to impersonate you on that site, Schoen said.

Some sites, such as Amazon, encrypt payment and shipping steps, but not clicks through pages of books or other products. Financial sites usually encrypt your entire session, he said.

Schoen said he believes many popular sites such as Twitter also should be encrypted. "Other things that people do online are also very sensitive and private, and can and ought to be protected in the same way," Schoen said.

Encrypted sites are denoted by the "https" in the URL line of your Web browser. To protect yourself, you could bookmark https links to your favorite websites on your computer and smart phone.

If you use the Firefox browser, you could also install the "HTTPS Everywhere" extension developed by the Electronic Frontier Foundation and the Tor Project, dedicated to improving Web privacy. That automatically directs you to the encrypted version of every site that offers one.

But there are limitations. It doesn't block sites that don't support encryption, but it does disable functions such as Chat and Instant search findings.

Even some areas of sites that support encryption may be vulnerable, he said, but he believes the situation will improve in the long term. "Some of these sites have more engineering work that they have to do in order to protect users," Schoen said.

Mike O'Leary, director of the Center for Applied Information Technology at Towson University, also said consumers should be wary of free Wi-Fi hotspots they don't have a reason to trust.

Those who use Wi-Fi may have noticed at times a network called "Free Public WiFi." This isn't actually a network at all, O'Leary warned. When a computer running Windows XP that hasn't had certain upgrades can't find a network, it offers itself up. It wouldn't give you Internet access, but it could give another user access to your computer.

"If an evildoer wanted to get access to your credentials, an incredibly easy way is for them to put an access point somewhere," O'Leary said.

As this operating system is phased out, consumers will likely see this glitch less and less frequently, he said. But criminals may try to set up rogue access points.

"Regardless of how you're connecting to the Internet, you have to trust all of the intermediary nodes along that path," O'Leary said. "You're placing trust in these organizations."

(c) 2010, The Baltimore Sun.
Distributed by McClatchy-Tribune Information Services.

4.8 /5 (6 votes)  

Rank 4.8 /5 (6 votes)
Relevant PhysicsForums posts

More news stories

Yahoo kills 'Livestand' just 6 months after debut

(AP) -- Yahoo is killing a tablet magazine called Livestand just six months its debut on the iPad.

Technology / Business

created 10 hours ago | popularity not rated yet | comments 1

Computers excel at identifying smiles of frustration (w/ Video)

(Phys.org) -- Researchers at the Massachusetts Institute of Technology (MIT) in the US have trained computers to recognize smiles, and they have turned out to be more adept at recognizing smiles of frustration ...

Technology / Computer Sciences

created 23 hours ago | popularity 4 / 5 (2) | comments 1 | with audio podcast report

Yahoo! ditches digital newsstand for iPads

Yahoo! shuttered its fledgling digital newsstand for iPads on Friday in what it said was the start of a product purge intended to make the floundering Internet pioneer more nimble.

Technology / Internet

created 11 hours ago | popularity not rated yet | comments 0

Facebook IPO debacle raises investor dander

The spate of complaints and investigations over the Facebook stock offering suggests big institutions had an edge over small investors, raising questions about the process.

Technology / Business

created 12 hours ago | popularity not rated yet | comments 0

Apple CEO Cook gives up $75M in stock dividends

(AP) -- Apple CEO Tim Cook is giving up $75 million in dividends on restricted stock that the company is awarding to all of its employees.

Technology / Business

created 16 hours ago | popularity 1.8 / 5 (4) | comments 2


Of mice and mental models: Neuroscientific implications of risk-optimized behavior in the mouse

(Medical Xpress) -- Regardless of an organism’s biological complexity, every encephalized animal continuously makes under-informed behavioral choices that can have serious consequences. Despite its ubiquity, ...

Dragon arrives at space station in historic 1st (Update 2)

The privately bankrolled Dragon capsule made a historic arrival at the International Space Station on Friday, triumphantly captured by astronauts wielding a giant robot arm.

Landmark calculation clears the way to answering how matter is formed

(Phys.org) -- An international collaboration of scientists, including Thomas Blum, associate professor of physics, is reporting in landmark detail the decay process of a subatomic particle called a kaon – ...

High-speed method to aid search for solar energy storage catalysts

Eons ago, nature solved the problem of converting solar energy to fuels by inventing the process of photosynthesis.

It's in the genes: Research pinpoints how plants know when to flower

Scientists believe they've pinpointed the last crucial piece of the 80-year-old puzzle of how plants "know" when to flower.

Researchers solve structure of human protein critical for silencing genes

In a study published in the journal Cell on May 24, Cold Spring Harbor Laboratory (CSHL) scientists describe the three-dimensional atomic structure of a human protein bound to a piece of RNA that "guides" the pr ...