Walk into any coffee shop, hotel lobby, or airport lounge, and you’ll see all manner of professionals hunched over their laptops, sipping lattes and responding to emails. The kind of flexibility that technology offers makes working anytime, anywhere tempting, but it can also be dangerous. This is especially true if your only options are public, free wireless networks.
While it might sound like we’re being paranoid, trust us when we say it’s easier than ever to get caught up in an unexpected security situation while navigating public Wi-Fi. Here’s why.
Most people assume hackers need deep, military-grade coding knowledge to breach a computer, but the truth is that even a teenager with a specific (and cheap) device can compromise a coffee shop’s network.
The type of attack in question is a “Man-in-the-Middle” attack. These specific threats position themselves between your employee’s laptop and the Internet router. All the hacker has to do is rename their rogue hotspot something similar to the real one and inject just enough confusion to get one or two people to connect to it.
Once an employee connects to the network, it’s game over. Every packet of data sent and received passes directly through the hacker’s machine first, giving them access to login credentials, unencrypted emails, client invoices, and more.
Website encryption isn’t enough to keep your data safe, and relying simply on the little padlock icon next to the URL could be a fatal mistake.
Modern cybercriminals can use automated tools to strip away SSL/TLS encryption protocols in real time as data passes through their rogue routers. They can also present fake security certificates that look legitimate to an employee operating on a time crunch. Once the encryption is bypassed, any sensitive data sent through the employee’s web browser is exposed in plain, readable text.
The human element cannot be trusted to spot a subtle, spoofed certificate warning when they are rushing to catch a flight, reach a deadline, or otherwise.
Even MFA isn’t enough to stop a determined hacker, especially if you’re playing on their turf.
When you log into an application, the app will save a session cookie on your browser so you don’t have to re-enter your password and MFA code every five minutes. If an employee accesses these accounts over a compromised public network, a hacker can steal those active session cookies. Once they’ve copied those cookies into their own web browser, the hacker can then bypass the login screen, password requirements, and MFA prompts.
This kind of instant and seemingly authentic access to your cloud environment is a massive problem that can have significant impacts on your business if left unchecked.
The solution to all of these issues is a cocktail of the most advanced enterprise-grade security solutions out there, available from Zinc. We can help you deploy the tools needed to stay safe out there, and we can do it better than anyone else in the area. Learn more by calling us today at (713) 979-2090.
About the author
Zinc has been serving the Texas area since 2017, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.
Comments