Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Friday, July 10, 2009

Traveling this summer? Do not be fooled by "fake" WI-FI hotspots

The newest trend in Internet fraud is "vacation hacking," a sinister sort of tourist trap.

Cybercriminals are targeting travelers by creating phony Wi-Fi hot spots in airports, in hotels, and even aboard airliners.

Vacationers on their way to fun in the sun, or already there, think they're using designated Wi-Fi access points. But instead, they're signing on to fraudulent networks and hand-delivering everything on their laptops to the crooks.

"More and more people are traveling with Wi-Fi devices like smartphones and laptops," says Marian Merritt, Internet safety advocate at the computer-security giant Symantec. "Airports and airlines and hotels are responding. They're setting up free Wi-Fi networks to lure in customers. Now they're luring in hackers as well."

In 2008, Silicon Valley-based AirTight Networks, a wireless security company, sent a team of "white-hat" hackers — good guys who try to thwart "black hat" hackers — around the world on an international airport study.

They checked the Wi-Fi networks at 27 airports — 20 in the U.S., five in Asia and two in Europe — and the results were not good.

At John F. Kennedy International Airport in New York, the baggage-handling system was being run on an insecure network. At other airports, ticketing systems were similarly exposed.
And everywhere they looked, they found fake Wi-Fi hot spots set up by hackers phishing for suckers — and there were plenty of suckers to be had.

"We found a lot of people using insecure Wi-Fi," says AirTight investigator Rick Farina, "and people engaged in all sort of dangerous activity — checking their e-mail, doing their banking, buying stock. These are not the kinds of thing you want to be doing on public Wi-Fi."

A lot of the problem may be that people let their guard down when they're on vacation.
"Much of the time, people just log in to the first robust network they see," says AirTight spokeswoman Della Lowe. "When we did our airport study, we found only 3 percent of the people were using secure networks."

And according to their study, even the "secure" networks weren't all too safe.

Eighty percent of the private Wi-Fi networks at airports surveyed by Airtight were secured by the aging Wired Equivalent Privacy (WEP) protocol, which was cracked back in 2001.
Almost as many — 77 percent — of the networks they surveyed were actually private, peer-to-peer networks, meaning they weren't official hotspots. Instead, they were running off someone else's computer.

In response to the rise in vacation hacking, some companies are beginning to tighten up security.
When AirTight's Farina alerted American Airlines to vulnerabilities in its system earlier this year, the airline took action.

"I can't tell you what they did," says Farina, "but their Wi-Fi is safer."

JetBlue also says it has taken appropriate steps. "Phishing is a risk that exists anywhere there are wireless services available, which is pretty much everywhere these days," says JetBlue spokesman Bryan Baldwin.

"At our Terminal 5 at JFK, where we offer free Wi-Fi, we have measures in place to minimize risks for our customers," he said. "We'd prefer not to go into detail about the specifics of those measures, because the details could be used by clever hackers against the defenses."

A spokesman for the Marriott hotel chain would give only a terse statement:
"When it comes to online security, Marriott has worked diligently to protect our guests."

One thing all security experts agree on: When it comes to hackers, the best defense is a good offense.
To this end, the folks at Symantec have created a list of five simple tips for thwarting most attacks.

1. Pay attention to your surroundings. Just because you're on vacation doesn't mean you're not in public. Don't look at important documents when sitting in a waiting area for a plane or a train — wait until you're alone and in private for that.

2. Beware of "Evil Twins." Some Wi-Fi networks look legitimate but are actually dummy networks created by criminals. Even if they contain the name of your airport, airline or hotel, they will directly link your computer to the hacker's. If you always use the official access keys provided by the establishment, then you should be safe.

3. Always assume Wi-Fi connections are being eavesdropped on. Never enter sensitive data — Social Security numbers, bank account information, etc. — when browsing the Web via a Wi-Fi network.

4. Set all Bluetooth devices to "hidden," not to "discoverable." Better yet, if you don't use Bluetooth, just shut off the function altogether.

5. Keep your security software current and active. Mobile PCs are just as vulnerable to viruses, worms and Trojan horses as are desktops, so make sure you have the latest protection installed."In short," says Merritt, "if you don't feel confident in the system security, then just don't use it."

original post: http://www.foxnews.com/story/0,2933,531380,00.html

Tuesday, October 21, 2008

Updated CompTIA Security+ Exam

from Comptia.org press release

Oakbrook Terrace, Ill., October 13, 2008 The Computing Technology Industry Association (CompTIA), the leading provider of vendor-neutral certifications for the world's technology workforce, announced today the updated CompTIA Security+ certification exam is scheduled for worldwide availability on Tuesday, October 14, 2008.

The 2008 Edition of the CompTIA Security+ exam places greater emphasis on knowing how to address specific security issues, rather than simply being able to recognize these issues. The new exam covers six major objectives, or topics: Systems Security, Network Infrastructure, Access Control, Assessments and Audits, Cryptography, and Organizational Security.

"CompTIA Security + serves as a solid foundation as it demonstrates a deeper understanding than some of the other computer security certifications available today," said Sam Brothers, senior digital forensics analyst, U.S. Customs. "Coming from a very technical environment, CompTIA Security + certification enables us to identify more desirable candidates and plays a role in our decision making process."

Organizations across a wide range of industries including professional services, agriculture and food, information technology, telecommunications, government, and the United States military use CompTIA Security + as a skills benchmark for IT staff members who manage systems and network security.

In addition, government security requirements such as U.S. Department of Defense Directive 8570 mandate that department employees or contractors engaged in work related to information security are required to be certified. The directive specifies CompTIA Security+ as a choice for Information Assurance Technician Level II and Information Assurance Manager I.

A 2008 CompTIA survey of more than 2,000 individuals with responsibilities for information security found that more organizations are requiring security certifications, such as CompTIA Security+, for their IT staff because certified staff is better able to identify potential security risks proactively, and to respond more quickly when security breaches do occur.

The CompTIA Security+ (2008 Edition) exam will be available at Prometric or Pearson VUE testing centers worldwide. The new exam will initially be in English, with other languages to follow. For more information on CompTIA Security+, visit http://certification.comptia.org/security/default.aspx.

About CompTIA
The Computing Technology Industry Association (CompTIA) is the voice of the world's information technology (IT) industry. Its members are the companies at the forefront of innovation; and the professionals responsible for maximizing the benefits organizations receive from their investments in technology. CompTIA is dedicated to advancing industry growth through its educational programs, market research, networking events, professional certifications, and public policy advocacy. For more information, please visit www.comptia.org.

Contact:Kara KershManager, Media RelationsCompTIA630-678-8464
KKersh@comptia.org
www.comptia.org