Wireless connections can be a haven for hackers

As communities push to turn themselves into massive wireless hotspots, unsuspecting Internet users are stumbling directly onto hacker turf, giving computer thieves nearly effortless access to their laptops and private information, authorities and high-tech security experts say.

It’s an invasion with a twist: People who think they are signing on to the Internet through a wireless hotspot might actually be connecting to a look-alike network, created by a malicious user who can steal sensitive information, said Geoff Bickers, a special agent for the FBI’s Los Angeles cyber squad.

It is not clear how many people have been victimized, and few suspects have been charged with Wi-Fi hacking. But Bickers said that over the past couple of years, these hacking techniques have become increasingly common and are often undetectable. The risk is especially high at cafes, hotels and airports, busy places with heavy turnover of laptop users, authorities said.

“Wireless is a convenience, that’s why people use it,” Bickers said. “There’s an axiom in the computer world that convenience is the enemy of security. People don’t use wireless because they want to be secure. They use wireless because it’s easy.”

For Mark Loveless, it was just a letter that separated security from scam.

Logging on to his hotel’s free wireless Internet in San Francisco last month, Loveless had two networks to choose between on his laptop screen – same name, one beginning with a lowercase letter, one with a capital. He chose the latter and, as he had done earlier that day, connected. But this time, a screen popped up asking for his log-in and password.

Loveless, a 46-year-old security analyst from Texas, immediately disconnected. A former hacker, he knew an attack when he saw one, he said.

Most Internet users do not.

“There’s literally probably millions of laptops in the U.S. that are configured to join networks named Linksys or D-Link when they are available,” said Corey O’Donnell, vice president of marketing for Authentium, a security company that provides security software. “So if I’m a hacker, it’s as easy as setting up a network with one of those names and waiting for the fish to come.”

Linksys and D-Link are two of the many commercial brands of wireless routers, products that allow a user to connect to the Internet using radio frequency.

As the field of wireless connectivity expands, so too does a hacker’s playground. More than 300 municipalities across the United States are planning or already operating Wi-Fi service. Google and Earthlink are working to bring wireless access to all of San Francisco.

Corporate networks are sometimes the most vulnerable, as employers push for a more mobile work force without always educating its users on the security risks of wireless Internet. “Once they’ve got a toehold in a network, it’s pretty much game over,” Bickers said.

Many workers rely on corporate firewalls in the office and an automatic default network setting that links them to their corporate networks. Outside the office, the firewall is no longer in place. That means the computer is unprotected.

Most laptops are configured to search for open wireless points and common wireless names, whether or not the user is trying to get online. That leaves people open to hacking.

In two new attacks, called “evil twin” and “man in the middle,” hackers create Wi-Fi access points titled whatever they like, such as “Free Airport Wireless” or an established, commercial name.

In the “evil twin” attack, the user turns on a laptop, which might automatically be trying to connect behind the scenes. When it does connect, it is connecting to a fake access point, or “evil twin,” and the hacker gets into personal files, steals passwords or plants a virus.

The attacker can become a “man in the middle” when he funnels the user’s Internet connection through this false access point to a true wireless connection. The unsuspecting Wi-Fi surfer then might proceed to enter credit card information, access e-mail or reveal other sensitive data. Meanwhile, the session appears ordinary to the user.

Talk to us

More in Herald Business Journal

Members of Gravitics' team and U.S. Rep. Rick Larsen stand in front of a mockup of a space module interior on Thursday, August 17, 2023 at Gravitics' Marysville facility. Left to right: Mark Tiner, government affairs representative; Jiral Shah, business development; U.S. Rep. Rick Larsen; Mike DeRosa, marketing; Scott Macklin, lead engineer. (Gravitics.)
Marysville startup prepares for space — the financial frontier

Gravitics is building space station module prototypes to one day house space travelers and researchers.

Orca Mobility designer Mike Lowell, left, and CEO Bill Messing at their office on Wednesday, Aug. 16, 2023 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Could a Granite Falls startup’s three-wheeler revolutionize delivery?

Orca Mobility’s battery-powered, three-wheel truck is built on a motorcycle frame. Now, they aim to make it self-driving.

Catherine Robinweiler leads the class during a lab session at Edmonds College on April 29, 2021. (Kevin Clark / The Herald)
Grant aids apprenticeship program in Mukilteo and elsewhere

A $5.6 million U.S. Department of Labor grant will boost apprenticeships for special education teachers and nurses.

Peoples Bank is placing piggy banks with $30 around Washington starting Aug. 1.
(Peoples Bank)
Peoples Bank grant program seeks proposals from nonprofits

Peoples Bank offers up to $35,000 in Impact Grants aimed at helping communities. Applications due Sept. 15.

Workers build the first all-electric commuter plane, the Eviation Alice, at Eviation's plant on Wednesday, Sept. 8, 2021 in Arlington, Washington.  (Andy Bronson / The Herald)
Arlington’s Eviation selects Seattle firm to configure production plane

TLG Aerospace chosen to configure Eviation Aircraft’s all-electric commuter plane for mass production.

Jim Simpson leans on Blue Ray III, one of his designs, in his shop on Friday, August 25, 2023, in Clinton, Washington. (Ryan Berry / The Herald)
Whidbey Island master mechanic building dream car from “Speed Racer”

Jim Simpson, 68, of Clinton, is using his knowledge of sports cars to assemble his own Mach Five.

An Amazon worker transfers and organizes items at the new PAE2 Amazon Fulfillment Center on Thursday, Sept. 14, 2023, in Arlington, Washington. (Ryan Berry / The Herald)
Amazon cuts ribbon on colossal $355M fulfillment center in Arlington

At 2.8 million square feet, the facility is the largest of its kind in Washington. It can hold 40 million “units” of inventory.

A computer rendering of the North Creek Commerce Center industrial park in development at 18712 Bothell-Everett Highway. (Kidder Mathews)
Developer breaks ground on new Bothell industrial park

The North Creek Commerce Center on Bothell Everett Highway will provide warehouse and office space in three buildings.

Dan Bates / The Herald
Funko president, Brian Mariotti is excited about the growth that has led his company to need a 62,000 square foot facility in Lynnwood.
Photo Taken: 102312
Former Funko CEO resigns from the Everett company

Brian Mariotti resigned Sept. 1, six weeks after announcing he was taking a six-month sabbatical from the company.

Cash is used for a purchase at Molly Moon's Ice Cream in Edmonds, Washington on Wednesday, Aug. 30, 2023. (Annie Barker / The Herald)
Paper or plastic? Snohomish County may require businesses to take cash

County Council member Nate Nehring proposed an ordinance to ban cashless sales under $200. He hopes cities will follow suit.

A crowd begins to form before a large reception for the opening of Fisherman Jack’s at the Port of Everett on Wednesday, August 30, 2023, in Everett, Washington. (Ryan Berry / The Herald)
Seafood with a view: Fisherman Jack’s opens at Port of Everett

“The port is booming!” The new restaurant is the first to open on “restaurant row” at the port’s Waterfront Place.

Tanner Mock begins unwrapping new furniture that has been delivered on Thursday, Aug. 24, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
In Everett, new look, new name for mainstay Behar’s Furniture

Conlin’s Furniture, based in South Dakota, bought the huge store and celebrates with a grand opening this week.