Story image

Windows 10 WiFi Sense: Security risk?

03 Jul 15

The Windows 10 feature WiFi Sense is raising security concerns due to the fact that it automatically shares WiFi passwords with a user’s contacts.

WiFi Sense was first available on for Windows Phone 8.1 users. However, the Windows 10 version opens up potential security risks for WiFi networks.

The feature allows a user to automatically connect to any detected crowdsourced WiFi network, acquires network information and provides ‘additional information’ to networks that require it, and can be used to automatically share their WiFi password with contacts on Facebook, Skype and Outlook.

It requests permission to connect to Outlook, Skype and Facebook to share information and passwords are shared via an encrypted link.

The WiFi passwords are sent via an encrypted link to Microsoft, who stores the data in their own servers and then sends the file over a secure connection to their contacts’ phone - provided they use Wi-Fi Sense and are in range of the Wi-Fi network shared.

Microsoft says WiFi Sense saves users the frustration of sharing passwords with friends and improves security.

On the company’s Windows Phone FAQ page, Microsoft says, “Some WiFi hotspots ask you to accept the terms of use in a web browser, provide additional information or do both before you can connect. WiFi Sense can do these things on your behalf to get you connected quickly.

“You can determine what information does or doesn't get provided and change your settings at any time.”

On exchanging WiFi network access with contacts, Microsoft says,“You can share access to password-protected WiFi networks to give your Facebook friends, contacts or Skype contacts Internet access without seeing each other's WiFi network passwords.

“Your contacts and friends are then automatically connected to the WiFi network you share if they're using WiFi Sense on their Windows Phone.

“Likewise, your phone will automatically connect to WiFi networks they share with you to give you Internet access.”

Providing internet access only ensures contacts don’t gain access to other computers, devices or files stored on the network, according to Microsoft.

One of the concerns with WiFi Sense is that internet encryption standards have experienced multiple bugs in the past year.

Furthermore, the fact that it doesn’t have any granularity beyond the service level means users can’t choose every person they are sharing their WiFi code with.

Microsoft has offered a potential solution: users can now prevent their network from working with WiFi Sense by adding ‘_optout’ to the SSID.

Users can also uncheck a box when they first connect, to disable the Wi-Fi Sense feature and ensure access to password-protected networks aren't shared with contacts.

Lenovo DCG moves Knight into A/NZ general manager role
Knight will now relocate to Sydney where he will be tasked with managing and growing the company’s data centre business across A/NZ.
The key to financial institutions’ path to digital dominance
By 2020, about 1.7 megabytes a second of new information will be created for every human being on the planet.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
Record revenues from servers selling like hot cakes
The relentless demand for data has resulted in another robust quarter for the global server market with impressive growth.
Opinion: Critical data centre operations is just like F1
Schneider's David Gentry believes critical data centre operations share many parallels to a formula 1 race car team.
MulteFire announces industrial IoT network specification
The specification aims to deliver robust wireless network capabilities for Industrial IoT and enterprises.
Google Cloud, Palo Alto Networks extend partnership
Google Cloud and Palo Alto Networks have extended their partnership to include more security features and customer support for all major public clouds.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill.