Compromised WiFi Threat
Microsoft has warned users of its cloud services that attackers apparently supported by Russian intelligence have targeted vulnerable wireless networks likely to be used by travelers. Impacts include harvesting credentials and otherwise gaining improper access to cloud accounts.
Curtin discussed the attack and defenses with 10TV's Kevin Landers.
The attack is complex, fundamentally compromising a real public WiFi system to provide incorrect address information to cause users to be sent not to the real web site they request—in this case, a Microsoft site—but a lookalike created and managed by the attackers.
Curtin recommends several defensive actions.
- If part of an organization, ensure that you follow the organization's directives for security and privacy.
- Use a Virtual Private Network (VPN) that specifically includes all Domain Name Service (DNS) requests and responses.
- If using Windows, disable Web Proxy Auto-Discovery (WAPD).
- When making a secured connection to a web site, click that shield or lock on the browser next to the address to see not only "Connection Secure," but that any site that looks like Microsoft's says verified by Microsoft Corporation.
- Users can avoid risk of compromised public WiFi systems by using their own mobile phones' hotspots.
Of course, sometimes just going without Internet access for a while can be good for reasons beyond the risk of attack.
About Interhack
Columbus-based Interhack is a cybersecurity and computer expert firm established in 2000. The firm can be found online at web.interhack.com.
