- Recommend:
- 0 Comments
Mapping Wireless Nets: Security Risk?
FBI warns 'warchalking' practice could expose business data to hackers--or terrorists.
At some point, the quest for ubiquitous computing turns into a security nightmare.
That's the concern of some federal law enforcement officials who in July warned companies throughout the Pittsburgh area of what can best be described as a systematic effort to mark and map unsecured Wi-Fi 802.11b wireless access points throughout many of the nation's major metropolitan areas.
Bill Shore, a special agent with the FBI's Pittsburgh field office, sent an e-mail to private-sector members of the local FBI Infragard chapter, warning them of a process known as "warchalking"--the physical marking of a building or facility to denote an open wireless access point.
Infragard chapters are local partnerships between the FBI and businesses in particular geographic areas focused on cybersecurity information sharing. There are 56 such chapters in the United States.
Shore likened warchalking to hobos marking public places that are willing to provide a hot meal, or the way spies mark dead-drop locations to exchange packages. Although the markings can be used for legitimate purposes, such as denoting a free public access point, officials fear that markings are being made on corporate buildings--enabling hackers, and possibly even terrorists, to more easily locate vulnerable wireless LANs.
The threat posed by warchalking, however, goes far beyond what might be considered isolated incidents of scanning for the presence of wireless networks.
"In Pittsburgh, the individuals are essentially attempting to map the entire city to identify the wireless access points," Shore said. Although he said there have been no reports of buildings in Pittsburgh being physically marked as they have in other parts of the country, Web sites have popped up that provide interactive digital maps denoting the precise locations of dozens of Wi-Fi access points in cities such as Pittsburgh, Philadelphia, Boston, and Berkeley, California, as well as regions of northeast Texas and various college campuses.
Spreading the Word
For example, Zhrodague Wireless Maps allows war drivers--those who go around looking for wireless networks--to submit output from their war-driving adventures and then creates digital street-level maps that show the location and signal strength of 802.11b access points. In some cases, satellite photos are used.
The site, which advertises itself as a service that puts "Wi-Fi on the map," includes more than 28,000 entries from war-driving results in Boston alone. It also provides maps for locals as far-flung as Germany and Okinawa, Japan.
Another Web site, Warchalking, includes a message board where computing enthusiasts often post messages about their warchalking plans. One user bragged about his warchalking excursion in Santa Monica, California, where he marked the "corrugated metal wall of an art gallery."
Shore acknowledged the threat such markings and Web sites pose to ongoing criminal and counterintelligence investigations, especially antiterrorism investigations. The ability of criminals and terrorists to spot these markings while simply walking down the street and then use vulnerable corporate wireless networks for anonymous Internet access "poses a real problem" for law enforcement, he said.
But William Harrod, director of the Investigative Response Division at TruSecure and a 14-year veteran of the FBI, downplayed the security significance of warchalking, saying that terrorists or serious criminals are unlikely to rely on it for identifying access points.
Harrod, who served at the FBI as a supervisory forensic computer specialist and a Rapid Start team leader, also downplayed the utility of having online interactive maps for terrorist activities. "It's not terribly hard to find access and gain that access," he said.

For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Lock Down Your Wi-Fi or the FBI Might Come Knocking
- G-Tech G-Connect Provides Wireless Portable Storage and Network Access Point
- Quick Poll: How Do You Share Wi-Fi Access?
- Solving Tech Mysteries: 3G vs. Wi-Fi, Write Access Denied
- What's the Difference Between 3G and Wi-Fi?
- Poll Results: Most Companies Secure Their Wi-Fi
- Google Offers Opt-Out for Wi-Fi Location Database
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.























