• On TechRepublic: 10 cool USB flash drive tricks
December 13, 2006 4:23 PM PST

Microsoft quietly tackles known Wi-Fi flaw

by Robert Vamosi
  • Font size
  • Print
  • Post a comment

Earlier this year, security researchers publicized a known flaw with how Microsoft Windows XP SP2 implemented its wireless networking: Windows XP SP2 would automatically scan for wireless networks upon power-up, going through a list of known, previously associated networks.

On the one hand, this makes connecting to your home or office wireless networks a cinch. However, it also means that if you didn't change the default name broadcast on your Linksys router, every time you powered up your laptop in a new space (such as an Internet caf?? or an airport waiting area), a criminal might be sitting nearby broadcasting with a rogue access point with the name "Linksys," in the hopes that you'll connect.

Once connected, the criminal could then act as a man in the middle, relaying your requests to the Internet via the criminal's PC (and perhaps recording strings of valuable data, such as your credit card info or bank login).

Microsoft has quietly posted an update found here. The update prevents a Windows wireless client on a laptop from advertising its preferred wireless network list to the world at large.

But the update appears to leave open the larger problem, which is having your laptop connect to a criminal rogue access point with the same default name as one of your preferred home networks. At least with the patch, the criminal can't see your preferred network list.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right