Safe, Secure Wi-Fi on the Road
Q: Recently I stayed in a hotel and used the free wireless access. Can any wireless user at another hotel or the parking lot for that matter, gain access to the network or my computer?
— Mary F.
A: Wow Mary, tough question. You couldn't ask me something like what does stand for or what city hosted the ? You leave me no choice but to admit that Information Technology (IT) questions are not my forte. I'm the guy who thought a "hard drive" was a road trip from Seattle to Portland or that a "gigahertz" was a particularly large rental car. Needless to say, I felt it best to defer to the experts on this one. Luckily, you can't swing a coaxial cable around here without lassoing an IT expert. Our in-house security gurus offered the following tips for keeping a secure connection on the road, and ensuring that what is seen is for your eyes only (and not some fedora-wearing corporate spy in the adjacent parking lot or club chair).
- Make sure it's actually the hotel network to which you're connecting. WiFi density is so high in some areas that you have to be cautious. Just because you are in a hotel room, doesn't mean that the hotel network is the only one that can be seen.
- Keep your anti-virus software and patches up-to-date and firewall enabled
- Disable file and printer sharing, likely the easiest way to compromise a remote user.
- Look for WEP (wireless encryption protocol) or WPA (WiFi protected access) when connecting. If you open the tool to view available wireless networks, it will say unsecured if it is not encrypted. Using WEP (encryption) gives you a reasonable amount of protection from someone just reading the signal out of the air.
- Tell your computer to NOT auto connect to wireless access points that are listed as 'unsecure'. A common method of compromise is to establish a fake access point. Users with this feature turned off will automatically associate to your fake access point. You can even provide real internet access, but monitor all of their traffic. Or, if the user automatically associated to you, you can browse their shares without them even realizing.
- When using a hotel network, establish a VPN connection to route your traffic through. The VPN client disables what they call 'split tunneling', which is the ability for your machine to connect to two or more networks at the same time. By establishing a VPN connection, no one else on the hotel network can see your traffic or connect to you.
There you have it Mary, some fine tips from the folks who know. Stay tuned next week when I tackle the really tough questions like business attire and airport parking.
Tom Conway, whose technical prowess ends with enabling his Out-of-Office Assistant, looks forward to your questions, comments and tips below:
(photo courtesy of AirBus)