Search
Search internet.com
News Reviews Insights Tutorials WiMax VoIP HotSpots Forums Events Products Glossary About






Subscribe Now!
Wi-Fi Planet.com's Daily Newsletter



More Free Newsletters


Wi-Fi Glossary
Find a Wi-Fi Term

Wi-Fi® is a registered certification mark of the Wi-Fi Alliance




internet.commerce
Be a Commerce Partner
















internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

>> Wi-Fi Planet Marketplace

RELATED ARTICLES
Wi-Fi Planet Guide to WPA
DIA Deploys Free Wi-Fi
How to Choose the Best WRT54G Router for You
Meraki Frees the ‘Net in San Francisco
Trend Micro Internet Security 2008


80211Planet.com Tutorials


Wi-Fi Planet Guide to Hotspot Safety
By Lisa Phifer

January 8, 2008

Step 3: Secure your hotspot login 

To avoid accidental associations with strangers, configure your Wi-Fi connection to connect only to Preferred Networks, in manual (not automatic) mode. This ensures that you retain complete control over your wireless connectivity when visiting hotspots (below).

fig3a.jpg

 

The only foolproof way to ensure that you connect to a legitimate hotspot AP is to verify the server’s certificate. In hotspots with WPA-Enterprise (e.g., T-Mobile, iBAHN), configure your laptop to validate the server’s certificate during 802.1x (below).

fig3b.jpg

 

In hotspots where 802.1x is not available, see if you can use a secure roaming client (e.g., iPass, Boingo) that transparently authenticates both you and the hotspot to an off-site roam server (below).

fig3c.jpg

 

Think twice about using unfamiliar paid hotspots that do not support either option. Man-in-the-middle attacks are very difficult to avoid there, since you don’t even know what the server's identity should be. If you decide that the risk is worth it, then avoid entering credit card numbers unless the hotspot login page is SSL-encrypted and the server’s certificate is valid and signed by a trusted root authority. If anything looks suspicious (as below), go somewhere else.

fig3d.jpg

 

Step 4: Encrypt your data

In hotspots that offer WPA-Enterprise (below), connect to the encrypted network’s SSID (e.g., tmobile1x, stsn_wpa), being careful to the open network (e.g., tmobile, stsn). With WPA, all packets sent by your laptop will be encrypted—including LAN broadcasts. However, when they reach the hotspot AP, packets will be decrypted and routed onto the Internet.

fig4a.jpg

Encrypt data with WPA.

 

In hotspots without WPA, use higher-layer encryption. If you don’t have your own VPN, you can use a consumer VPN service like JiWire Hotspot Helper, Witopia personalVPN, or HotspotVPN. For example, download and install AnchorFree, an OpenVPN client that tunnels your traffic to a free VPN gateway out on the Internet (below). These services decrypt packets at the provider's VPN gateway before relaying them to the destination in the clear.

fig4b.jpg

Encrypt data with a VPN.

To protect packets all the way to their destination, without your own VPN, use applications that can encrypt their own messages, like SSL-protected websites and mail clients (below). Doing so hides those messages from third parties, but leaves other applications exposed. For better coverage, protect everything with WPA or VPN, adding SSL for sensitive applications.

fig4c.jpg

Encrypt e-mail with SSL.

  

Step 5: Watch your step

Many hotspot connection managers, personal firewalls, and Internet security programs can log network activity. Use those logs to confirm or deny your suspicions whenever an incident occurs. If you spend a lot of time at unfamiliar hotspots, consider installing a host Wireless IPS program like Shmoo Group HSDK or AirDefense Personal (below). After all, what you can't see CAN hurt you—especially if you're careless.  fig5a.jpg

Like any traveler in unfamiliar territory, the single most important thing that you can do is to exercise caution and err on the side of safety. If a hotspot feels "phishy" don't stay connected. If your firewall warns you about suspicious activity, don't click "ok" and continue. By combining basic security measures with sound judgment, you can use hotspots safely.

Lisa Phifer owns Core Competence, a consulting firm focused on business use of emerging network and security technologies. She has been involved in the design, implementation, assessment, and testing of NetSec products and services for over 25 years.

  Go to page: Prev  1  2  

RELATED ARTICLES
Wi-Fi Planet Guide to WPA
DIA Deploys Free Wi-Fi
How to Choose the Best WRT54G Router for You
Meraki Frees the ‘Net in San Francisco
Trend Micro Internet Security 2008

Tools: Email this Article View Printable Version
Tutorials Archives | 7 day summary

Add wi-fiplanet.com to your favorites
Add wi-fiplanet.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed








JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
Avaya Article: Call Control XML - Powerful, Standards-Based Call Control
Tripwire Whitepaper: Seven Practical Steps to Mitigate Virtualization Security Risks
Internet.com eBook: The Pros and Cons of Outsourcing
Go Parallel Article: Scalable Parallelism with Intel(R) Threading Building Blocks
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Go Parallel Article: Getting Started with TBB on Windows
HP eBook: Storage Networking , Part 1
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Go Parallel Video: Intel(R) Threading Building Blocks: A New Method for Threading in C++
HP Video: Is Your Data Center Ready for a Real World Disaster?
Microsoft Partner Portal Video: Microsoft Gold Certified Partners Build Successful Practices
HP On Demand Webcast: Virtualization in Action
Go Parallel Video: Performance and Threading Tools for Game Developers
Rackspace Hosting Center: Customer Videos
Intel vPro Developer Virtual Bootcamp
HP Disaster-Proof Solutions eSeminar
HP On Demand Webcast: Discover the Benefits of Virtualization
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Microsoft Download: Silverlight 2 Software Development Kit Beta 2
30-Day Trial: SPAMfighter Exchange Module
Red Gate Download: SQL Toolbelt
Iron Speed Designer Application Generator
Microsoft Download: Silverlight 2 Beta 2 Runtime
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
IBM IT Innovation Article: Green Servers Provide a Competitive Advantage
Microsoft Article: Expression Web 2 for PHP Developers--Simplify Your PHP Applications
Featured Algorithm: Intel Threading Building Blocks - parallel_reduce
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES