OK, so I use a nice VPN solution that works through every public WiFi I’ve ever encountered. Great – no problem (which one you ask? My Astaro Security Gateway… but its implementing OpenVPN which is open source so anyone could set their own up withour the UTM). So I’m not too concerned about running my Virtual Desktop (Windows XP Pro, virtualized onto VMware Server 2.0) because the connection from my laptop to the Virtual Desktop is encrypted. So when using non-encrypted public WiFi, the traffic that others can see freely is encrypted.
Enter the All Ways On Wireless at the Ronald Reagan International Trade Center in Washington, DC. Its a pay-for public WiFi, I’m not against paying for it. Its actually running quite nicely and the regular, non-VPN enabled all-day pass works just fine with my VPN (another reason I like OpenVPN). However, when I went to purchase my day of access, it led me to a non-encrypted web page to type in my credit card details. Seeing as the radio frequency traffic between my laptop and the wireless access point is not encrypted and completely open to anyone that knows how to look, I essentially broadcast my credit card details out for that potential someone to steal.
Be wary of public wifi access spots that make you enter credit card details without leading you to a secure web page (that’s when you see https:// in the address bar, or that little padlock in the status bar of your browser). I don’t think my details are now in the hands of some nefarious identity theif, but its a lot more possible now that I’ve given them out over unencrypted radio transfer. Someone taking this information wouldn’t even be recorded as a data breach in the All Ways On Wireless financial system – since essentially they didn’t hack into their database they just listened to the freely broadcast, unencrypted traffic.
When will companies start taking security of information more seriously? I tried to go to their website (www.allwayson.net) but strangely enough, you can’t even get to their website from their own public wifi gateway. I wonder if its even up anymore, or if it changed and noone set up any forwarding address.