Story image

Windows 10 Wi-Fi Sense a 'major security flaw', says Xirrus

03 Aug 15

Experts are weighing in regarding the potential security flaw Wi-Fi Sense, a feature in Microsoft’s Windows 10 operating system that was officially released last week. 

As reported by Techday, the Wi-Fi feature enables users to share their Wi-Fi networks with their Outlook, Skype and Facebook contacts using Windows 10 without the need of a password.

Concerns were raised the feature may allow people to hack into other devices connected to the shared network, although Microsoft says this is easily remedied by turning off the ‘network discover’ feature on the network.

However, according to global Wi-Fi company Xirrus, Wi-Fi Sense is a massive security issue and potential deal-breaker for IT departments. 

“Enabling Wi-Fi access to a user’s contact book is a major security flaw,” says Shane Buckley, CEO at Xirrus. 

“Many of us keep contact information of our competitors, former employees and customers in our books. These among many other constituents should not have automatic access to our Wi-Fi networks,” he says.

Buckley says it is vital companies seek clarification on the operation and control of the feature from Microsoft before rolling out the operating system.

Buckley says Wi-Fi is rapidly becoming the de-facto access layer for the internet. ”Customers generally dislike using captive portal systems as a method of authenticated access to networks,” he says.

“Wi-Fi vendors like Xirrus need to eliminate the captive portal and essentially on-board the network onto the device and not the other way around.” 

He adds, “Doing this negates the need to share security keys for sensitive network access.”

Microsoft says a network’s password is stored on a Microsoft server, and is encrypted. Networks are only shared with contacts who use Wi-Fi Sense on their Windows Phone. Wi-Fi Sense doesn't work for people who use a smartphone that's running on a different operating system – so iOS and Android users won’t be to access networks shared via Wi-Fi Sense.

MulteFire announces industrial IoT network specification
The specification aims to deliver robust wireless network capabilities for Industrial IoT and enterprises.
Google Cloud, Palo Alto Networks extend partnership
Google Cloud and Palo Alto Networks have extended their partnership to include more security features and customer support for all major public clouds.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill. 
Schneider Electric's bets for the 2019 data centre industry
From IT and telco merging to the renaissance of liquid cooling, here are the company's top predictions for the year ahead.
China to usurp Europe in becoming AI research world leader
A new study has found China is outpacing Europe and the US in terms of AI research output and growth.
Google says ‘circular economy’ needed for data centres
Google's Sustainability Officer believes major changes are critical in data centres to emulate the cyclical life of nature.
52mil users affected by Google+’s second data breach
Google+ APIs will be shut down within the next 90 days, and the consumer platform will be disabled in April 2019 instead of August 2019 as originally planned.
Ramping up security with next-gen firewalls
The classic firewall lacked the ability to distinguish between different kinds of web traffic.