Showing posts with label Wi-Fi. Show all posts
Showing posts with label Wi-Fi. Show all posts

Wednesday, February 21, 2007

Auditing Wi-Fi Areas.

I've always been curious about the kind of security applied in “Hot Spots” or “Wi-Fi Areas”. These are places where you can access the Internet on pre-paid time. I'm not even going to talk about securing the client's activities and data or providing any kind of anonymity. I was really keen on finding what means such providers have deployed to make sure no unauthorized personnel has access (aka people who haven't paid for their time). So today was my lucky day. While waiting for a flight at Athens International Airport I had the chance to test their Wireless Internet Access Service. Apparently they don't use any kind of encryption on their Access Points. That means anyone can connect to it and receive an IP Address through DHCP (Dynamic Host Configuration Protocol). That's good right? These guys want even the least tech savvy user to be their client. As soon as you try to access your first web site (I'm guessing they offer HTTP only), you are redirected (through a transparent proxy) to a login screen and asked for a PIN which can be found on the back of pre-paid cards. When you enter a valid PIN, (I'm guessing) your IP and/or MAC Address are recorded and their firewall let's you out (or your proxy fetches stuff for your or something like that). So, that's how it works.

Let's say I am a bad guy, well not a bad guy – just a guy who doesn't want to pay. I would go and sit next to a guy who is already surfing, sniff the unencrypted air to easily discover the legit user's IP and MAC Addresses. (Of course I could also sniff sensitive information such as his passwords or e-mails but that's another story.) After that would I configure my own wireless card to use the exact same information (hence masquerading my self as the legit user) and I'm in! That's it! I wouldn't even have to try to find holes in their firewall or crack their infrastructure or brute force PINs. Pretty easy huh? Well, it is.

Then I tried to understand it. First of all their administrator has applied no access control mechanisms to the Access Point because that would require a significant trade-off. It would require every user to know how to configure his wireless device to conform with those security systems (e.g. MAC Filtering, Hidden ESSID, WEP, WPA). This could scare away potential customers who just don't get along with computers very well and the CEOs don't want that. So no “frustrating” security measures.

OK so a lot of people can get it for free. We know it and they know it. Although at first it may seem that a bandwidth piggyback is so cool and let's you surf for free, it actually works in their favor. How?

First of all, including the piggybackers, more people will appear using their Wi-Fi Areas. And, as we all know, people tend to imitate other people's behavior. So if you have a wireless-capable device and see other people using such service you will also feel the urge to use it. So there you have, indirect advertisement! Moreover, people able to perform such stunt will be so proud of themselves that will tell their friends about it. And when their friends try to do it for themselves they may fail but they were expecting Internet Access on the spot so it is very likely they will actually pay for the service after all. Extending that, there will be a time the original hacker won't be able to find victims to take advantage of but going online from the airport may already have become a habit to him or somehing he relies on so even he may purchase credits for the service. Also, if you come to think about it, they providers aren't losing that much. Most users (even unauthorized ones) are there to catch a flight so under normal circumstances that won't take more than a couple of hours. It's not like they are stealing bandwidth for days or so.

To sum up, what is advertised and offered, is Internet Access to counteract those long waiting hours or allow one urgent e-mail to be sent or a short chat to be conducted. In other words it addresses the need for communication, something people are always willing to pay (a lot) for. The generics of this, who pays for it, who doesn't, how secure and reliable it is, are not considered (although they should be) important both by the provider and the majority of users so everyone is happy at the end of the day.

Saturday, November 18, 2006

RFID Passports Cracked

It seems that the new uber-secure RFID Passports issued by many European countries after pressure from the U.S. are not that secure after all.

RFID Passports are ordinary-looking passports containing, besides the "human readable" information and authenticity signs, a Radio-Frequency Identification Chip which stores all printed information (and more) and transmits them to wireless readers used at Border Control. The reason for the chip's existence is that it is considered (or at least was) impossible to copy or forge so that even if a malicious person managed to reproduce the actual document he would never make it in producing a valid chip to complete the passport.

So one could ask "what if I buy an RF Reader for $9.99?". Well, authorities are using the 3DES encryption algorithm to encrypt the information on the chip. It is currently considered an above average method, providing 112 bit effective security.

The problem starts with the (known) fact that three public pieces of information are used to build the encryption key: (in the exact order) the passport's serial number + the owner's birth date + the passport's expiry date. So... you don't have to attack the encryption! Just find out (pretty easily) that kind of information and you have yourself the actual encryption/decryption key. Then you can go home, in your garage and clone or modify the chip's contents.

This is very much disturbing since the whole purpose for the new passports was the security provided by that chip but it turns out there are a few wide cracks in it.

[...]

Another problem with these passports is that they transmit in the air and that they are (normally) unique. So... one could identify you by placing an RF Reader inside a dumpster that you walk by every day. And maybe place a bomb inside that would go off if you and only you be in proximity.

Of course, official authorities have issued passports sleeves that act as "RF shields". According to this the chip cannot be read from inside that sleeve and you only take it out just before the police checkpoint. Well, it has been demonstrated that even then, the chip can be read. You just have to be really close to the subject. Doesn't seem like a problem when you are packed up against each other in a crowded area like the subway or a huge waiting line in the airport.


To sum up, current government efforts to control foreigners in their countries seem like panicked maneuvers of a nation under attack. If they feel that way, then somebody should admit it and then maybe we can all go home at toss those e-passports away (maybe shred them and burn them just to be safe).

And for the last time, just leave cryptographers to deal with cryptography issues!

Committee members are excellent at screwing it all up.

Goodnight.

Saturday, September 16, 2006

Wireless Security Revised

There have been talks and talks about Wireless Security but what does the average user know and, more importantly, what does he apply?

Last night I logged in a popular technology forum. It's one of those places where users talks with users and help each other.

A while ago there was a talk (in another forum) I participated in which examined whether forums are the new generation of information or just Unreliable Gossip 2.0. From one point of view, forums allow and promote freedom of speech. Anyone from anywhere may say what he/she has to say. No borders, no boundaries and no censorship. On the other hand, that uncontrollable model of information is susceptible to the "psychology of the group". This means that rumors can easily spread, facts can be twisted and ultimately have dozens or hunders or thousands of people misinformed (I might say deceived) just because "everybody else thinks so". That's the problem right there.

When it comes to critical user-to-user advice, how sure can one be he's getting the right info?

Now, let's get back to the popular technology forum and yet another Thread on Wireless Security. A lot of people in there consider WEP secure, some suggest disabling DHCP and applying a hidden SSID setting and the majority considers MAC Filtering as an effective action. Of course the above will only keep out of a Wi-Fi Network users with the same intellectual level as the ones proposing them. Then again such users don't attack other networks. If they are lucky, when they turn on the computer, it will automatically associate to a network and get an IP through DHCP. Determined attackers on the other hand may penetrate these protective measures in no time.

That's why I consider these tips more dangerous and harmful than any malicious hacker.

The reason is they provide a false blanket of security. Most of these people think "if user1 and user2 suggest them, it's ok". Then, these people, when asked by others to contribute, will replay the same false information as if it was their own, completing an endless loop. Finally a more literate user mentioned WPA/WPA2. That's pretty good unless you use a common dictionary word or name as your Pre-Shared Key.

To sum up, it has been my intention to illustrate the present situation among "user communities" on (wireless) security issues. I would never trust (or at least accept "as-it-is") information from Bob235 or PurpleBeast (the names are fictional), why would you?