Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Latest News
    • Mobile

    Aggregated Mobile Access Services Address Hot-Spot Security

    Written by

    Carol Ellison
    Published February 10, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Evil Twin, the phishing scheme that threatens users of Wi-Fi hot spots, has been well-known in the industry for as long as two years, according to the chairman of the Wi-Fi Alliances public access committee.

      Evil Twins target is the Universal Authentication Method, or UAM, the basic browser-based authentication presentation screen you see at most commercial hot spots.

      The good news for users is that by the time Evil Twin hit the headlines last month, the industry had come up with schemes for addressing that category of attacks, known as man-in-the-middle.

      /zimages/4/28571.gifClick here for tips on how to avoid Evil Twin.

      The bad news is that those strategies, pegged to the WPA (Wi-Fi Protected Access) and WPA2 security standards, are not in place everywhere. The problems result from legacy equipment that has not been upgraded to WPA and from the fact that the staff at most hot spots, such as coffee shops, airport lounges and hotels, are not permitted to distribute secure login keys and support users if theres a question.

      “Once devices have the WPA client embedded in them,” said Greg Hayes, chairman of the Alliances public access committee and director of mobility marketing at InfoNet, “it drastically reduces the local support burden on the venues because the procedure for getting authentication and getting services becomes a baseline industry standard.

      In October the Alliance published a technical whitepaper that detailed how WPA could be implemented in hot spots and offered a migration path to WPA for organizations using legacy equipment. “So its not a forklift upgrade,” Hayes said. Ultimately, he added, the goal is “that end users will enjoy the same levels of secure mobile access when they travel” as they have when they work wirelessly within their offices.

      Many corporate and campus environments that provide guest access to visitors have already taken these steps, Hayes noted. But problems still exist at hot spots provided as a courtesy by restaurants, coffee shops, and other public venues where there is no good way of distributing credentials or providing support to Wi-Fi users.

      Hayes cited Connexion by Boeings new in-flight Wi-Fi service as an example. “Imagine an airline flight attendant being asked to troubleshoot the network connection with an end user. Obviously, thats not going to happen,” he said. “The burden is really on us [as service providers] to provide seamless roaming and, more and more, to automate the process and make it transparent to the user.”

      Traditionally, the authentication, encryption and accounting schemes that offer security and consolidated billing across networks came to enterprise users in the form of aggregated service offerings through such providers as Boingo Wireless Inc., Infonet Services Corp., iPass Inc. and Fiberlink Communications Corp. Boingo also provides service to end users, and iPass, which is largely focused on the enterprise, resells its service to users through its various partners.

      These services use client-side software, installed on the mobile devices, to provide authentication, encryption and consolidated billing services. Users have the same login experience whether theyre at an airport lounge, hotel or coffee shop, and they receive a single bill for services as long as the provider servicing the location is a member of the aggregated network.

      With their enterprise focus, Infonet, iPass and Fiberlink each provided added security services that allow IT managers to push their security to remote users logging in over any type of connection, whether its Wi-Fi, wired broadband, or dial-up.

      Next page: How the aggregators work.

      Page 2


      : How the aggregators work”>

      Infonet and FiberLink have added features to Boingos client that both companies license.

      “There are a number of ways where the UAM can be replicated or scammed. Evil Twin is the newest iteration of it,” said Christian Gunning, director of product management at Boingo. When a user logs in, Boingo validates that the access point is a member of its network. If its not, the user gets a failed authentication notice.

      “The first thing we do is validate the certificate of that access point to certify that who we think were talking to is actually who were talking to,” said Howard Pressman, manager of wireless solutions at Fiberlink.

      iPass Secure Connect automatically launches a personal firewall. Its iSEEL encrypts logon credentials through authentication when VPN encryption is launched. Chris Churilo, director of product marketing at iPass, said if phishers are looking for credit card information, “theyll be a little bit disappointed the only thing they could actually do is get onto the Internet.”

      /zimages/4/28571.gifClick here to read more about the iPass mobile security platform.

      Last year, the Wi-Fi Alliance endorsed the Wireless ISP Roaming specification to define a roaming model that aims to pull service providers more directly into the mix and bring WPA authentication security technologies into public hot spots as they, and their customer users, upgrade equipment.

      “If we make the assumption going forward that more and more users will have WPA-enabled clients on their devices, the easier the roaming challenge becomes because you have a standardized protocol for securing and transmitting the information among parties,” Hayes said.

      Already, he said, were seeing “a kind of a horse race among providers over the number of hot spots in their networks.” And thats good news to users who find Wi-Fi connectivity increasingly available to them no matter what provider they subscribe to.

      /zimages/4/28571.gifCheck out eWEEK.coms for the latest news, reviews and analysis on mobile and wireless computing.

      Carol Ellison
      Carol Ellison
      Carol Ellison is editor of eWEEK.com's Mobile & Wireless Topic Center. She has authored whitepapers on wireless computing (two on network security–,Securing Wi-Fi Wireless Networks with Today's Technologies, Wi-Fi Protected Access: Strong, Standards-based Interoperable Security for Today's Wi-Fi Networks, and Wi-Fi Public Access: Enabling the future with public wireless networks.Ms. Ellison served in senior and executive editorial positions for Ziff Davis Media and CMP Media. As an executive editor at Ziff Davis Media, she launched the networking track of The IT Insider Series, a newsletter/conference/Web site offering targeted to chief information officers and corporate directors of information technology. As senior editor at CMP Media's VARBusiness, she launched the Web site, VARBusiness University, an online professional resource center for value-added resellers of information technology.Ms. Ellison has chaired numerous industry panels and has been quoted as a networking and educational technology expert in The New York Times, Newsday, The Los Angeles Times and The Wall Street Journal, National Public Radio's All Things Considered, CNN Headline News, WNBC and CNN/FN, as well as local and regional Comcast and Cablevision reports. Her articles have appeared in most major hi-tech publications and numerous newspapers and magazines, including The Washington Post and The Christian Science Monitor.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.