Beware of using Wireless@SG

innosia

Banned
Joined
May 5, 2009
Messages
446
Reaction score
0
Today somebody changes my yahoo password. And I only uses this password using my personal/office computer which is secured by antivirus.

This happens today when I am surfing internet using my tablet using Wireless@SG as internet connection. Then my password is changed by someone else.

Either my tablet or Wireless@SG is compromised. I believe only this two is the possibility, I remove out my tablet possibility as because I haven't heard about android tablet keylogger ever happens.

As because wireless@SG uses WEP encryption, which I suspect easily compromised and data in the network can be eardrops easily including my yahoo password.

Any expert please help me?
 

ky_nich

Member
Joined
Jan 4, 2007
Messages
151
Reaction score
2
A wireless network is not a secure channel to begin with. However, based on your description, the compromise could also have taken place on your personal/office computers since it is secured by only an anti-virus software.

If traffic on your personal/office networks are not encrypted, someone could also have been sniffing your confidential data. There is also a possibility that your computers have been planted with trojans and/or malware.

To mitigate such risks, you should enable SSL encryption for all your confidential transactions on the internet. I'm not sure whether Yahoo! offers the SSL encryption option, if not, you may wish to consider changing your email service provider (E.g. Gmail)?

In addition, you could also consider:
1. Installing Firewalls on your computers;
2. Update your computer patches;
3. Changing your passwords on a periodic basis (E.g. every 90 days); and
4. Use a strong password (E.g. Minimum of 8 characters, a mix of alphanumeric characters, as well as upper and lower case characters).
 

dskw

Supremacy Member
Joined
Oct 7, 2003
Messages
7,800
Reaction score
0
Either my tablet or Wireless@SG is compromised. I believe only this two is the possibility, I remove out my tablet possibility as because I haven't heard about android tablet keylogger ever happens.

that's not a very good assumption to make. =:p have you been installing apks from untrusted sources, for example?

also, to add on to ky_nich's recommendation, gmail and i believe hotmail, allows for 2FA. you could activate that for greater peace of mind :)
 

Qubicfactor

Supremacy Member
Joined
Mar 26, 2003
Messages
7,678
Reaction score
680
As because wireless@SG uses WEP encryption, which I suspect easily compromised and data in the network can be eardrops easily including my yahoo password.

What WEP? Wireless@SG is OPEN :s22:

Actually you have to beware of all unencrypted networks, since someone can just run something like firesheep and steal your session cookie. Doesnt take much to perform an attack nowadays.

Using a 3G dongle is a safer bet than using free wifi. Else, try to get Wireless@SGx running.
 

happily1986

Senior Member
Joined
Nov 27, 2007
Messages
1,193
Reaction score
110
TS nxt time use HTTPS la... then use VPN.

why people wanna hack ur yahoo? :s13::s13:

you can try this btw

https://crypto.stanford.edu/forcehttps/

nowadays simi sai online also rely on verification emails. if someone can hijack your email = possibility for him or her to hijack account in e.g. shopping websites which store your credit card details = max out credit card = ho seh.

if this happen to you, i will see whether you will still :s13:
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
Today somebody changes my yahoo password. And I only uses this password using my personal/office computer which is secured by antivirus.

This happens today when I am surfing internet using my tablet using Wireless@SG as internet connection. Then my password is changed by someone else.

Either my tablet or Wireless@SG is compromised. I believe only this two is the possibility, I remove out my tablet possibility as because I haven't heard about android tablet keylogger ever happens.

As because wireless@SG uses WEP encryption, which I suspect easily compromised and data in the network can be eardrops easily including my yahoo password.

Any expert please help me?

The only REAL SECURITY is usage of SSL with proper certificate checking on properly implemented sites

Anything else like using Wireless@SGx or VPN is delusional.

WEP is a broken security and not to be trusted. WPA/WPA2 which can be defeated by monitoring the traffic for the 4 EAPOL packets on initial connection made by client and subject to decryption. So Wireless@SGx is not as safe as you think it is. The devil is in the details and hackers are working on details.

Using SSL is not sufficient for proper security either. Too much half-baked knowledge about security to think when you see an SSL connection is good enough. You can be hoax into a split SSL tunnel as such

client <---- SSL ----> HACKED <---- SSL ----> REAL SITE

Your browser should complain if the above happens, but a mobile client may not because the responsibility of floating up the error message is by the mobile client. The SSL socket when using proper certificate checking by domain will helps to lower the risk, provided the local DNS server is not compromised. However this is the minimal and acceptable security level for most end-users.

VPN are not secure based on the way how it is introduced to consumers. It did not provide end-to-end security, partial protection is NO PROTECTION. Simply to speak, wearing a broken condom is as good as not wearing one.

Even where proper SSL is implemented, poorly executed website will still be compromised. It is commonly found in a lot of websites where the login form is non-SSL protected, during during submission. This is a security hole where the form can be modified before you even get into a SSL session, which means you could have easily been hoaxed into submitting your userid and password to a phishing site.

Partial SSL protection implemented in websites also allow for cookies to be exposed and hence browser hijacking can be done to extract personal information stored in the site without even having a SSL connection. Badly implemented site might even allow password to be changed without the need for the original password, or even visible to hackers via forget password change. I have come across foolish implementor sending password via email to end-user.

Hacking can happen across services. One can start a forget password process. While the password is not sent to the hacker's email. It can be extracted via the wireless network since POP3 and IMAP are not necessarily SSL protected and can be sniffed in a shared network if the end-user start up a local email client working in the background. So the email is sent to the victim, and if it is concurrently sniffed by the hacker, it can then be retrieved and quickly access the website and lock out the victim if done fast enough.

Let be even more innovative. What makes you think when you are connecting to Wireless@SG, or starbucks network, these are real hotspots offer by the intended originator ? Even if there are 2 Wireless@SG network in the area, your devices will attempt to connect to the stronger ones even after initial connection to the real one. For all you know, your hacker is just sitting next to you monitoring your traffic.

If you are foolish enough to use your password in unprotected sites like HWZ and same as the one you use for yahoo, you are screw just as bad.

Passwords I used are like this "IP6JAsOKsF@vQgb{XT'k0dteB6OT6(aU" and they are different across all my services. If you decided to use such kind of complicated passwords without a password manager, how many can you remember ? If you are using simple passwords like this "johhmybaby2012", then I'm pretty sure the chance you reuse the password in another site is high, or just a few tweaks like "mybabyjohn2012", "johnmybaby2013", etc...

The approaches are endless and subject to the creativity of the hackers.
 
Last edited:

Shion

Senior Mentor
Joined
Oct 24, 2008
Messages
375,546
Reaction score
121,990
I heard some of those "Wireless@SG" are not the real ones
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
I heard some of those "Wireless@SG" are not the real ones

Not surprising. There is no authentication mechanism for these Wifi hotspots. Even if there is, how many non IT savvy end-users can actually differentiate the real from the fake?

The fact is it is so easy to monitor the wireless network without even the network operator or end-users knowledge. A lot of such espionages are operating without your knowledge. Always practice proper security. And be aware of them, don't let ur guard down
 

weap0nx

Master Member
Joined
Sep 13, 2000
Messages
4,400
Reaction score
4
Once you use Wireless@SG, regardless of WHETHER OR NOT it is the authentic one:

If you login to any site which does not use SSL, your username and password is sent in the clear and usually such form inputs have fields conveniently named "username" and "password" which means it doesn't take a novice tinkerer, let alone a hacker, to automatically sift through millions of packets from all Wireless@SG users in the vicinity to locate one http exchange with form inputs labelled "password".

So use it and you are almost certainly gonna get into trouble some day.

With respect to david's post I think it's a little exaggerated, it's all possibilities but not as dangerous as it sounds.

WPA2 can be trusted if you use a hard to crack password, if you didn't then actually WPA2 is no different from other security protocols, it may be brute forced if certain conditions are met. Your post seemed to have downplayed "subject to decryption", that is actually the hardest part.

Man in the middle attacks are quite uncommon these days all modern browsers including mobile ones put up their warnings very prominently and prevent users from conveniently ignoring them. If someone does do that, they are an idiot.

Badly implemented sites are also becoming very uncommon because of the availability of high quality open-source web building frameworks, small time developments no longer spin their own shoddy security. Personally I've seen less sites displaying those vulnerabilities that you have mentioned.

Except for VPN which actually to me stands for virtual PRIVATE NETWORK which means that it's something exclusive to you, like an office VPN, a home VPN. If set up correctly they are secure. If we were talking about VPN providers to watch and receive restricted content, then there is no security in them but it was never and has never been advertised for that purpose in the first place. :)

Just my two cents worth and I'm not an expert, sorry if I'm mistaken
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
With respect to david's post I think it's a little exaggerated, it's all possibilities but not as dangerous as it sounds.

Please don't downplay the risk unless you have sufficient information to show otherwise. The risk are there. From the standpoint of security, just because it is not widely advertise doesn't mean it is not happening. 10 thieves getting caught doesn't mean there are only 10 thieves in the world, am I right ?

How dangerous something is depends on what it matters to you. If you consider your privacy and confidentiality as worthless, obviously any lost in those assets would seems harmless to you. How can one feels pain until something is being stolen from them ? Since you feel what I have mentioned is not as dangerous, can you be more specific which is not as dangerous, or perhaps you just *feel* they are not ? Just saying, you don't need 1000 snowden type of calibre security experts to steal 1 million records, just a couple will do.

Badly implemented sites are also becoming very uncommon because of the availability of high quality open-source web building frameworks, small time developments no longer spin their own shoddy security. Personally I've seen less sites displaying those vulnerabilities that you have mentioned.

I beg to differ with regards to this statement. Good opensource libraries does not mean that a website has to be properly implemented. Don't believe ? Let me show you a few that I have discovered http://www.shapeways.com, http://www.starhub.com, http://www.toggle.sg/en/signin

Tell me that the authentication system has been properly implemented. If you can't see the flaw in the implementation, then it means you have more to learn about proper implementation of secured authentication.

Just because there are high quality libraries around, does not in any way imply or result in developers implementing security properly. Only properly educated developers with respect to best security practices helps to ensure websites are properly implemented with the necessary security features in place to protect the confidentiality and privacy of the end-users.
 
Last edited:

Shion

Senior Mentor
Joined
Oct 24, 2008
Messages
375,546
Reaction score
121,990
@david,

Thanks for your insight. Anyway, is Wireless@SGx "safer" in any aspects?
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
@david,

Thanks for your insight. Anyway, is Wireless@SGx "safer" in any aspects?

Safer than an unencrypted wireless network, but not safe enough for any authentication purpose or transmission of private and confidential information.

The only way I will *recommend* that you submit any confidential information over the network is the END-TO-END security implementation of HTTPS or other SSL for most web oriented purpose.

Wireless@SGx only provide encrypted wireless network from your device to the service gateway, outside in the Internet, there is no protection or whatsoever.
 

Shion

Senior Mentor
Joined
Oct 24, 2008
Messages
375,546
Reaction score
121,990
Thanks david

I can never seen to login to Wireless@sg. Blessing in disguise I guess. :s13:

Yes, it is like impossible to login. Worst still, sometimes you see multiple Wireless@SG whereby some are fake ones :eek:
 

xkiller213

Senior Member
Joined
Oct 21, 2012
Messages
647
Reaction score
0
Using SSL is not sufficient for proper security either. Too much half-baked knowledge about security to think when you see an SSL connection is good enough. You can be hoax into a split SSL tunnel as such

client <---- SSL ----> HACKED <---- SSL ----> REAL SITE

Your browser should complain if the above happens, but a mobile client may not because the responsibility of floating up the error message is by the mobile client. The SSL socket when using proper certificate checking by domain will helps to lower the risk, provided the local DNS server is not compromised. However this is the minimal and acceptable security level for most end-users.
Of course, unless you are using a Lenovo laptop, or have any of the below software installed...
CartCrunch Israel LTD
WiredTools LTD
Say Media Group LTD
Over the Rainbow Tech
System Alerts
ArcadeGiant
Objectify Media Inc
Catalytix Web Services
OptimizerMonitor
SSL-busting code that threatened Lenovo users found in a dozen more apps | Ars Technica
 

localITguy

Suspended
Joined
Dec 13, 2013
Messages
17,788
Reaction score
1,674
its a free service. you should always use a VPN when using a public wireless network.

it provides an extra layer.
unless you are doing somthing that is not sensitive stuff ( email) which in my book is not. unless its a crop account or the content of the emails is.

i am sorry hear this. hope you get things sorted
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
its a free service. you should always use a VPN when using a public wireless network.

it provides an extra layer.
unless you are doing somthing that is not sensitive stuff ( email) which in my book is not. unless its a crop account or the content of the emails is.

i am sorry hear this. hope you get things sorted

And this layer is not going to protect you from anyone whom is really hacking you once you get out of the other end-point of the VPN right ? Where is the security ? If you want to advice someone on security, you will want to make sure it's end-to-end. If not, you are just giving them a good feeling, and good feeling doesn't protect them from getting their data stolen. VPN in the way you have described is quite incorrect. Not that it doesn't solve anything, but it leaves more gapping hole when interpreted that you can have HTTP across VPN and it's considered safe ?
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top