Free hotel wifi is a hacker’s dream | Eurasia Diary -

18 October, Friday

Free hotel wifi is a hacker’s dream

Hotel systems are so leaky it’s worth investing in your own virtual private network

Science & Tech A- A A+

You’ve just arrived at the hotel after a delayed flight and a half-hour wrangle with the car-hire firm. And then you remember that you’ve forgotten to pay last month’s credit card bill, and there’ll be an interest charge if you wait until you’re back at base. But – hey! – you can do it online and help is at hand. The receptionist is welcoming and helpful. They have wifi and it’s free. Relieved, you ask for the password. “Oh, you don’t need one,” he replies. “Just type in your room number and click the box.”

Phew! Problem solved. Er, not necessarily. At this point the human race divides into two groups. Call them sheep and goats. Sheep are sweet, trusting folks who like to think well of their fellow humans. Surely that helpful receptionist would not knowingly offer a dangerous service. Also, they find digital technology baffling and intimidating. And they cannot imagine why anything they do online might be of interest to anyone.

Goats, on the other hand, have nasty, suspicious minds. They believe that many of their fellow humans may be up to something. They believe that, in this networked world, only the paranoid survive. So when they see an open, free wifi network they smell a rat. And they would never, ever send confidential information via such a channel.

Sadly, in this particular context, the goats are wiser than the sheep. They know that hotel chains have become a coveted target of hackers. Many of the industry’s biggest operators have reported data breaches in recent years, including big names such as Hilton, InterContinental, Marriott and Hyatt. Most of these attacks, according to Bloomberg, are focused on the property management systems (PMS) used by hotel chains to take reservations, issue room keys and store credit card data.

The Bloomberg report, written by Patrick Clark, was based on the exploits of a team of “white hat” hackers, employed to test the security of a particular system. After plugging the internet cable from a bedroom’s smart TV into a laptop they got into the hotel’s PMS, which led to the chain owner’s corporate system. In doing so they gained access to credit card information for several years’ worth of transactions in dozens of hotels. And if they had been crooks the team could have sold the information on the black market, where a Visa card with a high credit limit can fetch up to $20.

Why are hotels such tempting targets? Partly because their systems are easy to penetrate, technically. “Hospitality companies,” writes Clark, “long saw technology as antithetical to the human touch that represented good service. The industry’s admirable habit of promoting from the bottom up means it’s not uncommon to find IT executives who started their careers toting luggage. Former bellboys might understand how a hotel works better than a software engineer, but that doesn’t mean they understand network architecture.”

In the meantime, what can travelling holidaymakers do to protect themselves? The short answer is to invest in – and install – virtual private network (VPN) software on any device that travels with you. A VPN functions as an encrypted tunnel to a special server located somewhere on the internet. If you connect to the Observer through a VPN, for example, then the VPN server connects to the paper on your behalf. And because all the traffic is encrypted it’s gobbledegook to any snooper, which means that you can safely use hotel (and cafe) wifi networks wherever you go.

Read more:

The Guardian

Report a mistake by marking it and pressing Ctrl+Enter

EurasiaDiary © Must be hyperlinked when used.

Follow us:
Twitter: @Eurasia_Eng
Facebook: EurasiaEng