Wireless warbiking in London, 2012

happygeek 0 Tallied Votes 402 Views Share

The 'Murder Ball' competition is now underway at the London 2012 Summer Paralympics, also known as wheelchair rugby to some. However, you won't find Olympic athletes taking part in the warbiking event that has also been happening in London recently: warbiking is very much a sport for nerds.

warbike The brainchild of security vendors Sophos, Project Warbike itself consisted of one man on a specially adapted bicycle complete with with dynamos and solar panels powering a computer that was scanning for wireless networks. Taking place across a couple of days, Sophos Director of Technology Strategy James Lyne cycled around the streets of London in orrder to create a heat map of wireless network security levels using a GPS device connected to the Heath-Robinson sounding contraption.

In every mile he rode, the warbiker scanned more than a thousand wireless networks and of these one in four was insecure or had 'poor' security that could be easily bypassed. In total, 106,874 individual hotspots were detected across more than 91 miles in Central London. Only 8% used absolutely no encryption, but 19% used 'as hard to crack as a dropped china plate' WEP encryption. Although you might imagine exactly the reverse to be true, analysis of the heat map revealed that it was the residential areas which had the most secure networks and not the business ones. Home users, as a rule, opted for stringer WPA2 level encryption compared to the highest density of unsecured or secured with the pretty pointless WEP encryption was found amongst small business owners.

This is particularly surprising given that just about router these days comes with as easy as it gets, often one-button, secure wireless networking configuration options right out of the box. "Unfortunately many networks are still like a Rolo" commented warbiker James Lyne "hard on the outside but soft and gooey on the inside".

Dani AI

Generated

A short, practical follow-up to ’s warbiking writeup and ’s comment: the exercise is a reminder that weak or misconfigured Wi‑Fi is still common, especially in small or unmanaged deployments. The checklist below focuses on the fixes that cut the most risk now, and on the one-step upgrades worth doing if old kit won’t take them.

  • Use modern encryption. Prefer WPA3 (if supported) or at minimum WPA2 with AES/CCMP; never use WEP or TKIP.
  • Disable Wi‑Fi Protected Setup (WPS) — the PIN method can be brute‑forced.
  • Replace default admin usernames/passwords and pick a long, unique Wi‑Fi passphrase (passphrases >12–16 characters or a few random words).
  • Put guests and IoT on a separate SSID/VLAN with client isolation.
  • Keep router firmware and client devices patched; enable automatic updates where possible.
  • For business environments, move to 802.1X (WPA2/WPA3‑Enterprise) and a RADIUS server rather than shared PSKs.

Practical quick checks: log into the router (common addresses are 192.168.0.1 or 192.168.1.1), open Wireless/WLAN settings, confirm the security mode (switch to WPA3 or WPA2‑AES), disable WPS, change the admin password, and check for firmware updates. If a router does not support modern modes or security patches, replace it — many inexpensive access points now support WPA3.

Background reading and implementation guidance: NIST’s WLAN guidance covers safe configuration and monitoring, the KRACK research explains why timely patches matter, and CISA/US‑CERT have long advised disabling WPS. For plain‑language home advice see national cyber guidance on securing home networks.

Links: NIST SP 800‑153 (WLAN guidelines). (csrc.nist.gov)

WPA3 overview from the Wi‑Fi Alliance press release. (globenewswire.com)

KRACK paper (Vanhoef et al.). (papers.mathyvanhoef.com)

CISA note on WPS PIN brute‑force issues. (cisa.gov)

Northern Ireland Cyber Security Centre: home‑Wi‑Fi tips. (nicybersecuritycentre.gov.uk)

UrbanKhoja 89 Practically a Posting Shark Featured Poster

Interesting read, still amazes me how many are so familiar with networking and domestic routers yet can't fathom the need to protect their new home network.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.