Past News - CIOInsight
Home arrow Past News arrow Technology: Wireless
RECENT NEWS

CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    
KNOW IT ALL
By Tony Kontzer
The Cloud Debate: Public Versus Private

What does the legal battle between Salesforce.com and Microsoft really mean for the future of cloud computing?


  Past News


Technology: Wireless

By Gary Bolles


  Table of Contents:
  1. Technology: Wireless
  2. ' Rogue Networks '
  3. ' Staying Secure '
  4. ' Ideal Solutions '
  5. ' Are You Snoop'
  6. ' Fact Sheet '

Is wireless security an oxymoron? It doesn't have to be, with the right company policies and strategy to minimize exposure to hackers—or just plain folks.

Rate This Article:
Add This Article To:

Technology: Wireless


( Page 1 of 6 )

Now, someone can steal your company's most sensitive data by snatching it out of thin air—right from the company parking lot.

Sound more like scare talk than reality? Guess again. On May 1, an anonymous customer of Best Buy Inc. told SecurityFocus Online, a Web site for a security threat management firm, that he was able to break into Best Buy's internal sales data network from his car—which was parked in one of the store's parking lots. He tapped into the network, he said, after installing into his laptop a wireless card that he had just bought in the store.

It's not certain whether any customer credit card numbers or other purchasing information held by Best Buy at its 499 stores across the country has actually fallen into the wrong hands, but the discovery of the company's vulnerability caused a brouhaha at Best Buy headquarters.

The problem? Best Buy, in some of its checkout lanes, uses portable point-of-sale terminals that are tied to its servers by a wireless local area network, or LAN. The LAN relies on the 802.11 wireless networking standard, known as Wi-Fi. But Best Buy did not, apparently, bother to turn on the most fundamental security feature that's built into Wi-Fi, thereby leaving customer credit card data unencrypted and open to snooping. At first, Best Buy pulled its wireless POS systems from its stores. Now, though, they're back in use, says spokeswoman Joy Harris, because the company has bolstered its wireless security procedures.

But Best Buy's vulnerability is hardly unique. Many companies fail to take even the most basic wireless security precautions. Still have doubts? Take a ride with government software consultant Todd Waskelis in Virginia's Dulles corridor, a thruway outside Washington, D.C. that is lined with high-tech firms. Waskelis can slip a wireless card into his laptop, drive down Route 7 and pick up one wireless network after another, including the networks of a major credit clearinghouse. "Instead of hacking from the Internet, people can hack from the road, and probably get to the accounting server," Waskelis says.

But the culprit, say experts, isn't the technology as much as it is poor management. Few companies think about wireless security as a business problem, and fewer still think of wireless security as a critical component of their company's business strategy—a set of choices to be made about what level of wireless risk is acceptable, and how to manage exposure while monitoring the network continuously for new holes and threats.

"The concept of wireless is on many peoples' radar screens, [but] the concept of wireless security is on far fewer of them," says Larry Rogers, a senior member of the technical staff at the CERT Coordination Center at Carnegie Mellon University. CERT trains companies to help secure the Net.



 
 
>>> More Past News Articles          >>> More By Gary Bolles
 


 
FEATURED SPONSORED MESSAGE

    A Center of Greener IT–and Savings

    Check out how IBM's Green Solutions Center is showcasing a number of IT solutions that are helping customers save significant costs when it comes to energy consumption.


FEATURED SPONSORED MESSAGE

    IT Locator

    Your next customer is searching for you. Will you be found? Get listed where customers search for IT experts.

EDITORS' PICKS
 
LATEST STORIES



FEEDBACK
Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • Free 30-day endpoint security trial: VIPRE Enterprise
  • Download eval guide and prepare your apps for multicore.
  • Saugatuck Technology Research: CXO Top Priorities
  • Get expert tips & advice on IBM-Oracle database solutions.
  • Get Control with SonicWALL Application Intelligence
  • Free Trial: All-inclusive Enterprise Phone System
  • Reduce operating expenses with CDW Healthcare solutions.
  • FREE Data Leakage for Dummies Book from Sophos
  • eWEEK Quick LInks