Story image

Windows 10 WiFi Sense: Security risk?

03 Jul 15

The Windows 10 feature WiFi Sense is raising security concerns due to the fact that it automatically shares WiFi passwords with a user’s contacts.

WiFi Sense was first available on for Windows Phone 8.1 users. However, the Windows 10 version opens up potential security risks for WiFi networks.

The feature allows a user to automatically connect to any detected crowdsourced WiFi network, acquires network information and provides ‘additional information’ to networks that require it, and can be used to automatically share their WiFi password with contacts on Facebook, Skype and Outlook.

It requests permission to connect to Outlook, Skype and Facebook to share information and passwords are shared via an encrypted link.

The WiFi passwords are sent via an encrypted link to Microsoft, who stores the data in their own servers and then sends the file over a secure connection to their contacts’ phone - provided they use Wi-Fi Sense and are in range of the Wi-Fi network shared.

Microsoft says WiFi Sense saves users the frustration of sharing passwords with friends and improves security.

On the company’s Windows Phone FAQ page, Microsoft says, “Some WiFi hotspots ask you to accept the terms of use in a web browser, provide additional information or do both before you can connect. WiFi Sense can do these things on your behalf to get you connected quickly.

“You can determine what information does or doesn't get provided and change your settings at any time.”

On exchanging WiFi network access with contacts, Microsoft says,“You can share access to password-protected WiFi networks to give your Facebook friends, contacts or Skype contacts Internet access without seeing each other's WiFi network passwords.

“Your contacts and friends are then automatically connected to the WiFi network you share if they're using WiFi Sense on their Windows Phone.

“Likewise, your phone will automatically connect to WiFi networks they share with you to give you Internet access.”

Providing internet access only ensures contacts don’t gain access to other computers, devices or files stored on the network, according to Microsoft.

One of the concerns with WiFi Sense is that internet encryption standards have experienced multiple bugs in the past year.

Furthermore, the fact that it doesn’t have any granularity beyond the service level means users can’t choose every person they are sharing their WiFi code with.

Microsoft has offered a potential solution: users can now prevent their network from working with WiFi Sense by adding ‘_optout’ to the SSID.

Users can also uncheck a box when they first connect, to disable the Wi-Fi Sense feature and ensure access to password-protected networks aren't shared with contacts.

TCS collaborates with Red Hat to build digital transformation solutions
“By leveraging TCS' technology skills to build more secure, intelligent and responsive solutions, we aim to deliver superior end-user experiences."
Twitter suspects state-sponsored ties to support forum breach
One of Twitter’s support forums was hit by a data breach that may have ties to a state-sponsored attack, however users' personal data was exposed.
How McAfee aims to curb enterprise data loss
McAfee DLP aims to help safeguard intellectual property and ensure compliance by protecting sensitive data.
HPE promotes 'circular economy' for end-of-use tech
HPE is planning to show businesses worldwide that throwing old tech and assets into landfill is not the best option when it comes to end-of-use disposal.
2018 sees 1,500% increase in coinmining malware - report
This issue will only continue to grow as IoT forms the foundation of connected devices and smart city grids.
CSPs ‘not capable enough’ to meet 5G demands of end-users
A new study from Gartner produced some startling findings, including the lack of readiness of communications service providers (CSPs).
Oracle announces a new set of cloud-native managed services
"Developers should have the flexibility to build and deploy their applications anywhere they choose without the threat of cloud vendor lock-in.”
How AT&T aims to help businesses recover faster from a disaster
"Companies need to be able to recover and continue operations ASAP, without pulling resources from other places to get back up and running."