All the latest UK technology news, reviews and analysis

Experts warn of Wi-Fi 'evil twin' scam

by Robert Jaques

21 Jan 2005

Be the first to comment

  • Tweet this

Security experts have reignited fears over the potential danger of so-called 'evil twin' Wi-Fi phishing scams.

The well-documented attack methodology centres on hackers fooling wireless network users into logging onto rogue access points set up to emulate legitimate wireless Lan equipment, warned Professor Brian Collins, head of information systems at Cranfield University.

Once hackers have set up these wireless networks next to commercial hotspots, and conned users into logging on, they begin harvesting data from laptops connected to the compromised Wi-Fi network.

"This has been going on for some time," Professor Neil Barrett of Cranfield's computer science department told vnunet.com.

"It's like the Wi-Fi version of rogue diallers but with the added bonus of financial information. It's also akin to phishing in the way that the user is tricked."

But Barrett added that the problem will not affect websites running fully certified systems where both the website host and the user have a software certificate which identifies them to each other. However, he warned that there are relatively few websites that offer this level of service.

David Callisch, director of communications at Wi-Fi firm Aruba, said: "Many hotspots still offer a simple access service that does not currently provide protection against hacking, and this new threat will only add to the woes of mobile computer users.

"The 'evil twin' menace means that users can no longer assume that if they enter a wireless hotspot they are connecting to a bona fide wireless internet connection.

"Enterprises that enable mobile working need to enforce a corporate security policy to ensure that a wireless hotspot does not become an open access point into their corporate network."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

Web Graphic Designer

A leading global provider of critical information to...

Midweight UI Designer

Playstations and table football in the kitchen? Standard...

To send to more than one email address, simply separate each address with a comma.