Connect with us

Published

on

Over the years, travelers have repeatedly been warned to avoid public Wi-Fi in places like airports and coffee shops. Airport Wi-Fi, in particular, is known to be a hacker honeypot, due to what is typically relatively lax security. But even though many people know they should stay away from free Wi-Fi, it proves as irresistible to travelers as it is to hackers, who are now updating an old cybercrime tactic to take advantage.

An arrest in Australia over the summer set off alarm bells in the United States that cybercriminals are finding new ways to profit from what are called “evil twin” attacks. Also classified within a type of cybercrime called “Man in the Middle” attacks, evil twinning occurs when a hacker or hacking group sets up a fake Wi-Fi network, most often in public settings where many users can be expected to connect.

In this instance, an Australian man was charged with conducting a Wi-Fi attack on domestic flights and airports in Perth, Melbourne, and Adelaide. He allegedly set up a fake Wi-Fi network to steal email or social media credentials.

“As the general population becomes more accustomed to free Wi-Fi everywhere, you can expect evil twinning attacks to become more common,” said Matt Radolec, vice president of incident response and cloud operations at data security firm Varonis, adding that no one reads the terms and conditions or checks the URLs on free Wi-Fi.

“It’s almost a game to see how fast you can click “accept” and then ‘sign in’ or ‘connect.’ This is the ploy, especially when visiting a new location; a user might not even know what a legitimate site should look like when presented with a fake site,” Radolec said.

Today’s ‘evil twins’ can more easily hide

One of the dangers of today’s twinning attacks is that the technology is much easier to disguise. An evil twin can be a tiny device and can be tucked behind a display in a coffee shop, and the small device can have a significant impact.

“A device like this can serve up a compelling copy of a valid login page, which could invite unwary device users to enter their username and password, which would then be collected for future exploitation,” said Cincinnati-based IT consultant Brian Alcorn. 

The site doesn’t even have to actually log you in. “Once you’ve entered your information, the deed is done,” Alcorn said, adding that a harried, weary traveler probably would just think the airport Wi-Fi is having issues and not give it another thought.  

People who are not careful with passwords, such as use of pet’s names or favorite sports teams as their password for everything, are even more vulnerable to an evil twin attack. Alcorn says for individuals who reuse username and password combinations online, once the credentials are obtained they can be fed into AI, where its power can quickly give cybercriminals the key.

“You are susceptible to exploitation by someone with less than $500 in equipment and less skill than you might imagine,” Alcorn said. “The attacker just has to be motivated with basic IT skills.”

How to avoid becoming a victim of this cybercrime

When in public places, experts say it’s best to use alternatives to public WiFi networks.

“My favorite way to avoid evil twin attacks is to use your phone’s mobile hotspot if possible,” said Brian Callahan, Director of the Rensselaer Cybersecurity Collaboratory at Rensselaer Polytechnic Institute.

Users would be able to spot an attack if through a phone relying on its mobile data and sharing it via a mobile hotspot.

“You will know the name of that network since you made it, and you can put a strong password that only you know on it to connect,” Callahan said.

If a hotspot isn’t an option, a VPN can also provide some protection, Callahan said, as traffic should be encrypted to and from the VPN.

“So even if someone else can see the data, they can’t do anything about it,” he said.

Airport, airline internet security issues

At many airports, the responsibility for WiFi is outsourced and the airport itself has little if any involvement in safeguarding it. At Dallas Fort Worth International Airport, for example, Boingo is the Wi-Fi provider.

“The airport’s IT team does not have access to their systems, nor can we see usage and dashboards,” For said an airport spokesman. “The network is isolated from DAL’s systems as it is a separate standalone system with no direct connection to any of the City of Dallas’ networks or systems internally.” 

A spokeswoman for Boingo, which provides service to approximately 60 airports in North America, said it can identify rogue Wi-Fi access points through its network management. “The best way passengers can be protected is by using Passpoint, which uses encryption to automatically connect users to authenticated Wi-Fi for a safe online experience,” she said, adding that Boingo has offered Passpoint since 2012 to enhance Wi-Fi security and eliminate the risk of connecting to malicious hotspots.

Alcorn says evil twin attacks are “definitely” occurring with regularity in the United States, it’s just rare for someone to get caught because they are such stealth attacks.  And sometimes hackers use these attacks as a learning model. “Many evil twin attacks may be experimental by individuals with novice-to-intermediate skills just to see if they can do it and get away with it, even if they don’t use the collected information right away,” he said.

The surprise in Australia wasn’t the evil twinning attack itself, but the arrest.

“This incident isn’t unique, but it is unusual that the suspect was arrested,” said Aaron Walton, threat analyst at Expel, a managed services security company. “Generally, airlines are not equipped and prepared to handle or mediate hacking accusations. The typical lack of arrests and punitive action should motivate travelers to exercise caution with their own data, knowing what a tempting and usually unguarded -target it is — especially at the airport.”

In the Australian case, according to Australian Federal Police, dozens of people had their credentials stolen.

According to a press release from the AFP, “When people tried to connect their devices to the free WiFi networks, they were taken to a fake webpage requiring them to sign in using their email or social media logins. Those details were then allegedly saved to the man’s devices.”  

Once those credentials were harvested, they could be used to extract more information from the victims, including bank account information.

For hackers to be successful, they don’t have to dupe everyone. If they can persuade only a handful of people – statistically easy to do when thousands of harried and hurried people are milling around an airport – they will succeed.

“We expect WI-Fi to be everywhere. When you go to a hotel, or an airport, or a coffee shop, or even just out and about, we expect there to be Wi-Fi and often freely available WI-FI,” Callahan said. “After all, what’s yet another network name in the long list when you’re at an airport? An attacker doesn’t need everyone to connect to their evil twin, only some people who go on to put credentials into websites that can be stolen.”

The next time you’re at the airport, the only way to be 100% sure you’re safe is to bring your own Wi-Fi.

Continue Reading

Technology

Former Trump advisor Dina Powell McCormick leaves Meta board after eight-month stint

Published

on

By

Former Trump advisor Dina Powell McCormick leaves Meta board after eight-month stint

Dado Ruvic | Reuters

Dina Powell McCormick, who was a member of President Donald Trump’s first administration, has resigned from Meta’s board of directors.

Powell McCormick, who previously spent 16 years working at Goldman Sachs, notified Meta of her resignation on Friday, according to a filing with the SEC. The filing did not disclose why McCormick was stepping down from Meta’s board, but said her resignation was effective immediately.

Meta does not plan on replacing her board role, according to a person familiar with the matter who asked not to be named due to confidentiality. Powell McCormick is considering a potential strategic advisory role with Meta, but nothing has been decided, the person said.

Powell McCormick joined Meta’s board in April along with Stripe co-founder and CEO Patrick Collison. Meta CEO Mark Zuckerberg said in a statement at the time that the two executives “bring a lot of experience supporting businesses and entrepreneurs to our board.”

Powell McCormick served as a deputy national security advisor to President Trump during his first stint in office and was also an assistant secretary of state during President George W. Bush’s administration.

She is married to Sen. Dave McCormick, R-Pa, who took office in January.

Powell McCormick is the vice chair, president and head of global client services at BDT & MSD Partners, which formed in 2023 after the merchant bank BDT combined with Michael Dell’s investment firm MSD.

With her departure, Meta now has 14 board members, including UFC CEO Dana White, Broadcom CEO Hock Tan and former Enron executive John Arnold.

WATCH: TikTok signs joint venture to create TikTok USDS Joint Venture.

TikTok signs joint venture to create TikTok USDS Joint Venture

Continue Reading

Technology

Musk’s $56 billion Tesla pay package must be restored as court rules cancellation was too extreme

Published

on

By

Musk's  billion Tesla pay package must be restored as court rules cancellation was too extreme

Elon Musk's 2018 Tesla pay package must be restored, Delaware Supreme Court rules

Elon Musk‘s 2018 CEO pay package from Tesla, worth some $56 billion when it vested, must be restored, the Delaware Supreme Court ruled Friday.

“We reverse the Court of Chancery’s rescission remedy and award $1 in nominal damages,” the judges wrote in their opinion.

In the decision, the Delaware Supreme Court judges said a lower court’s decision to cancel Musk’s 2018 pay plan was too extreme a remedy and that the lower court did not give Tesla a chance to say what a fair compensation ought to be.

The decision on the appeal in this case, known as Tornetta v. Musk, likely ends the yearslong fight over Musk’s record-setting compensation.

Musk’s net worth is currently estimated at around $679.4 billion, according to the Forbes Real Time Billionaires List.

Dorothy Lund, a professor at Columbia Law School, told CNBC that while the Friday opinion may restore the 2018 pay plan for Musk, it leaves the rest of the lower court’s decision unaddressed and intact.

“The court had previously decided that Musk was a controlling shareholder of Tesla and that the Tesla board and he arranged an unfair pay plan for him,” she said. “None of that was reversed in this decision.”

“We are proud to have participated in the historic verdict below, calling to account the Tesla board and its largest stockholder for their breaches of fiduciary duty,” lawyers representing plaintiff Richard J. Tornetta said in an e-mailed statement.

Tesla did not immediately respond to requests for comment.

The Delaware Supreme Court issued the order per curiam with no single judge taking credit for writing the opinion and no dissent noted.

Read more CNBC tech news

Musk’s 2018 CEO pay package from Tesla, comprised of 12 milestone-based tranches of stock, was unprecedented at the time it was proposed. After it was granted, the pay plan made Musk the wealthiest individual in the world.

Tesla shareholder Tornetta sued Tesla, filing a derivative action in 2018, accusing Musk and the company’s board of a breach of their fiduciary duties.

Delaware’s business-specialized Court of Chancery decided in January 2024 that the pay plan was improperly granted and ordered it to be rescinded.

In her decision, Chancellor Kathaleen McCormick also found that Musk “controlled Tesla,” and that the process leading to the board’s approval of his 2018 pay plan was “deeply flawed.”

Among other things, she found the Tesla board did not disclose all the material information they should have to investors before asking them to vote on and approve the plan.

After the earlier Tornetta ruling, Musk moved Tesla’s site of incorporation out of Delaware, bashed McCormick by name in posts on his social network X, formerly Twitter, where he has tens of millions of followers, and called for other entrepreneurs to reincorporate outside of the state.

Tesla also attempted to “ratify” the 2018 CEO pay plan by holding a second vote with shareholders in 2024.

In November, Tesla shareholders voted to approve an even larger CEO compensation plan for Musk.

The 2025 pay plan consists of 12 tranches of shares to be granted to the CEO if Tesla hits certain milestones over the next decade and is worth about $1 trillion in total. The new plan could also increase Musk’s voting power over the company from around 13% today to around 25%.

Shareholders had also approved a plan to replace Musk’s 2018 CEO pay if the Tornetta decision was upheld on appeal. That plan is now nullified.

As CNBC previously reported, a law firm that currently represents Tesla in this appeal penned a bill to overhaul corporate law in Delaware earlier this year. The bill was passed by the Delaware legislature in March, and if it had applied retroactively, it could have affected the outcome of this case.

Read the Delaware Supreme Court’s ruling here.

Ron & Michael Baron on Elon Musk, Tesla and the next big, currently-overlooked opportunities in the market

Continue Reading

Technology

Cramer says Boeing is a buy here — plus, Wells Fargo and bank stocks keep rolling

Published

on

By

Cramer says Boeing is a buy here — plus, Wells Fargo and bank stocks keep rolling

Continue Reading

Trending