Story image

Windows 10 WiFi Sense: Security risk?

03 Jul 15

The Windows 10 feature WiFi Sense is raising security concerns due to the fact that it automatically shares WiFi passwords with a user’s contacts.

WiFi Sense was first available on for Windows Phone 8.1 users. However, the Windows 10 version opens up potential security risks for WiFi networks.

The feature allows a user to automatically connect to any detected crowdsourced WiFi network, acquires network information and provides ‘additional information’ to networks that require it, and can be used to automatically share their WiFi password with contacts on Facebook, Skype and Outlook.

It requests permission to connect to Outlook, Skype and Facebook to share information and passwords are shared via an encrypted link.

The WiFi passwords are sent via an encrypted link to Microsoft, who stores the data in their own servers and then sends the file over a secure connection to their contacts’ phone - provided they use Wi-Fi Sense and are in range of the Wi-Fi network shared.

Microsoft says WiFi Sense saves users the frustration of sharing passwords with friends and improves security.

On the company’s Windows Phone FAQ page, Microsoft says, “Some WiFi hotspots ask you to accept the terms of use in a web browser, provide additional information or do both before you can connect. WiFi Sense can do these things on your behalf to get you connected quickly.

“You can determine what information does or doesn't get provided and change your settings at any time.”

On exchanging WiFi network access with contacts, Microsoft says,“You can share access to password-protected WiFi networks to give your Facebook friends, Outlook.com contacts or Skype contacts Internet access without seeing each other's WiFi network passwords.

“Your contacts and friends are then automatically connected to the WiFi network you share if they're using WiFi Sense on their Windows Phone.

“Likewise, your phone will automatically connect to WiFi networks they share with you to give you Internet access.”

Providing internet access only ensures contacts don’t gain access to other computers, devices or files stored on the network, according to Microsoft.

One of the concerns with WiFi Sense is that internet encryption standards have experienced multiple bugs in the past year.

Furthermore, the fact that it doesn’t have any granularity beyond the service level means users can’t choose every person they are sharing their WiFi code with.

Microsoft has offered a potential solution: users can now prevent their network from working with WiFi Sense by adding ‘_optout’ to the SSID.

Users can also uncheck a box when they first connect, to disable the Wi-Fi Sense feature and ensure access to password-protected networks aren't shared with contacts.

52mil users affected by Google+’s second data breach
Google+ APIs will be shut down within the next 90 days, and the consumer platform will be disabled in April 2019 instead of August 2019 as originally planned.
Ramping up security with next-gen firewalls
The classic firewall lacked the ability to distinguish between different kinds of web traffic.
Platform9 aims to allow enterprises to run Kubernetes instantly
Snapfish, HPE, and Juniper use Platform9’s hybrid cloud solution to deliver a modern cloud infrastructure-as-a-service experience.
DigiPlex’s data centre heat reuse system wins award
Its solution to reuse heat to warm thousands of local homes took out the accolade at the recent 2018 Energy Awards.
STT GDC to build hyperscale data centre in Singapore
ST Telemedia Global Data Centres (STT GDC) today unveiled ambitious plans for expansion with its largest data centre in Singapore to date.
Opinion: A data centre manager's Christmas wish list
In this time of merriment and cheer there is one thing everyone is not-so-secretly waiting for: Presents.
Golden opportunities for enterprise e-waste reduction
E-waste is a hot topic in tech circles, and Park Place's EMEA MD believes there could be huge opportunities if data centres and enterprises improve their practices.
How Schneider Electric aims to simplify IT management
With IT Expert, Schneider Electric aims to ensure secure, vendor agnostic, wherever-you-go monitoring and visibility of all IoT-enabled physical infrastructure assets.