Abstract

Walk into any coffee shop, hotel lobby, or airport lounge, and you’ll see all manner of professionals hunched over their laptops, sipping lattes and responding to emails. The kind of flexibility that technology offers makes working anytime, anywhere tempting, but it can also be dangerous. This is especially true if your only options are public, free wireless networks.

While it might sound like we’re being paranoid, trust us when we say it’s easier than ever to get caught up in an unexpected security situation while navigating public Wi-Fi. Here’s why.

Man-in-the-Middle Attacks Require Zero Technical Skill

Most people assume hackers need deep, military-grade coding knowledge to breach a computer, but the truth is that even a teenager with a specific (and cheap) device can compromise a coffee shop’s network.

The type of attack in question is a “Man-in-the-Middle” attack. These specific threats position themselves between your employee’s laptop and the Internet router. All the hacker has to do is rename their rogue hotspot something similar to the real one and inject just enough confusion to get one or two people to connect to it.

Once an employee connects to the network, it’s game over. Every packet of data sent and received passes directly through the hacker’s machine first, giving them access to login credentials, unencrypted emails, client invoices, and more.

Encryption Protocols Only Get You So Far

Website encryption isn’t enough to keep your data safe, and relying simply on the little padlock icon next to the URL could be a fatal mistake.

Modern cybercriminals can use automated tools to strip away SSL/TLS encryption protocols in real time as data passes through their rogue routers. They can also present fake security certificates that look legitimate to an employee operating on a time crunch. Once the encryption is bypassed, any sensitive data sent through the employee’s web browser is exposed in plain, readable text.

The human element cannot be trusted to spot a subtle, spoofed certificate warning when they are rushing to catch a flight, reach a deadline, or otherwise.

Session Hijacking Can Bypass Your Multi-Factor Authentication

Even MFA isn’t enough to stop a determined hacker, especially if you’re playing on their turf.

When you log into an application, the app will save a session cookie on your browser so you don’t have to re-enter your password and MFA code every five minutes. If an employee accesses these accounts over a compromised public network, a hacker can steal those active session cookies. Once they’ve copied those cookies into their own web browser, the hacker can then bypass the login screen, password requirements, and MFA prompts.

This kind of instant and seemingly authentic access to your cloud environment is a massive problem that can have significant impacts on your business if left unchecked.

The solution to all of these issues is a cocktail of the most advanced enterprise-grade security solutions out there, available from NetMGM. We can help you deploy the tools needed to stay safe out there, and we can do it better than anyone else in the area. Learn more by calling us today at 888-748-2525.

ABOUT THE AUTHOR

3 Reasons to Avoid Public Wi-Fi Across Your Company

Rafiq Masri

With over 25 years of experience in Information Technology, Rafiq is one of the most accomplished, versatile and certified engineer in the field. He has spent the past 2 ½ decades administering and supporting a wide range of clients and has helped position Network Management, Inc. as a leader in the IT Managed Services space.

Rafiq has built a reputation for designing, building and supporting top notch IT infrastructures to match the business objectives and goals of his clients.

Embracing the core values of integrity, innovation, and reliability, Rafiq has a very loyal client base with some customer relationships dating back 20+ years.

Rafiq holds a bachelor’s degree in Mechanical Engineering from the University of Michigan and has completed graduate programs in Software Engineering and Business at Harvard and George Mason University. Rafiq is a former founder and CEO of Automation, Inc. in Ann Arbor, Michigan as well as a valued speaker on entrepreneurship and technology at industry events such as ExpoTech and others.