Tuesday | 14 October, 2008
CIO
When Wireless Works
Ben Worthen 05 February, 2003 13:18:28

Related Stories
  • +

    Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44

    Adobe to launch Web site offering users free hosted services for document creation, sharing and storage
    Adobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage.
Additional Resources
Executive Guides
Whitepapers

Newsletter Subscription

Sign up for our CIO newsletters!
Weekly coverage of the issues that impact corporate and government information
RSS Feeds

Caution: No Wires Attached

They're here, they're insecure, and they're gaining a foothold in your enterprise

By Daintry Duffy

A lot has been written about the security flaws of wireless networks, and you've probably heard the tales of the enterprising hacker who can sit on a park bench in the heart of the financial district and tap into dozens of wireless networks. But for CIOs the challenges of wireless are only getting larger as the holes in security go unpatched, and employees either demand greater wireless connectivity or surreptitiously achieve it on their own.

"Wireless is robustly insecure," says Bruce Schneier, author, cryptographer and CTO of Counterpane Internet Security, a security-management service provider. "The only way to look at wireless is to assume that it's completely insecure."

Bob Degen is the former supervisor of the financial crimes unit for the US. Currently he is senior vice president for corporate security of First Data (the parent company of Western Union), where he has seen proof of wobbly wireless security. A high-placed executive at the company bought himself a WLAN and, despite Degen's numerous warnings about the security problems, was bound and determined to use it. After a business trip to Paris, he came to Degen and apologised for having ignored his warnings. The executive sheepishly went on to explain that he had been on his WLAN in the hotel, had turned it off, but was puzzled when a light indicated that he was still connected to the network. It turned out that a guy two rooms down had been on a WLAN as well and the lines had got crossed. Each had become connected to the other company's LAN, and the light was on because the other guy was still on First Data's network.

The standard security protocol for wireless is WEP (wired equivalent privacy), and since its release in 1997 a number of flaws have been found that allow anyone with the right tools to break the encryption. Even the example of the hacker on the park bench is out of date. By using increasingly powerful receivers and transmitters, it's now possible to break into a wireless network from as far as 10 miles away. According to one vendor, a telecom customer that realised its exposure even went so far as to put special windows into its new facility to block transmitters and protect internal wireless communications. It had to evaluate up to six window systems before it found one it couldn't transmit across. But for most companies, security-driven window replacement is an unattainable and expensive luxury.

This is not the only problem that wireless presents. Like Degen's executive who was determined to use his wireless LAN out of the office, employees can easily set up their own WLAN access points within the company walls. WLANs use wireless network cards and small boxes - the size of a CD drive - as network access points. They can easily be tucked in a drawer or under a desk. Whether they are set up by an employee who wants to e-mail during meetings or by a hacker looking to establish 24/7 access to your network, it is virtually impossible for CIOs to find them.

While security experts such as Schneier contend that wireless will never be secure, others see hope. "Well-implemented end-to-end cryptography or a virtual private network offers strong protection against certain kinds of attacks," says Hernan. While he cautions that there are other kinds of attacks for which these solutions may not work, he believes that "most organisations would be well served to use end-to-end security or a VPN as part of a strategy for securing a wireless network". The biggest problem with wireless security systems is that many companies aren't bothering to use them. An informal 2001 Gartner survey found that more than 60 per cent of companies operating wireless networks didn't even have WEP - the most basic security that comes packaged with a wireless LAN - turned on.

But one thing that CIOs need to educate their executives about is that while it is possible to conceal specific content, the fact that person X is having a conversation with person Y can't be hidden. At times, the very fact that communication is taking place at all can become a security breach. For example, a flurry of text messages between execs at two rival banks could signal that a long-rumoured merger is in the works.

Although CIOs can control company-sponsored wireless installations, the greater vulnerability may come from employees, like Degen's executive, who go out and set themselves up on wireless. While it is a must to create and enforce strong policies, Degen also advocates a touch of humiliation as an effective deterrent. "I didn't get to where I was because I'm such a persuasive guy," he says. "We have a saying in my group that 'adversity is my friend'. When something bad happens, jump on it, make a big example out of it, don't hide it." When a bank or government group comes in and gives First Data a bad security audit, Degen believes in making it public within the organisation to increase the pressure on business units and employees that might be tempted to ignore a security mandate. "Look at what's at risk," he says. "Take advantage of bad things and parlay them into as much as you can get."

Many CIOs or CSOs might be horrified at the idea of tarnishing their own reputation within the company by exposing security flaws, but Degen plays the strong security mandate he's been given for all its worth. When it was recently discovered that a facilities executive was flouting the company's security policy by letting his employees use a loading dock door instead of the employee card-reader turnstiles, Degen organised a sting operation. He asked an employee from the company's Tulsa office (a stranger at the company's Colorado headquarters) to piggyback on facilities employees going in and out through the dock doors. Time after time employees let him in, even though nobody knew who he was. Degen wrote up a ticket for every violation.

"I'm going to take all 30 of these tickets and throw them on [the facilities executive's] desk," he says. "Then I'm going to hold a remedial security class for all his people, and it's going to be long and gruesome."

Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00

    The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.
    There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little.
  • +

    PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00

    Compliance strategies for PCI's new application security requirements
    While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Email Archiving 101—Customer Case Study

Join Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.