Login Login

print Feed

About Thomas Herold

Thomas Herold, Acentic’s HSIA expert, has over 10 years of experience in the IT industry building secure networks and engineering software. Joining Acentic 5 years ago he was nailed to his workplace proving his geeky self but soon discovered his passion for customer services and Acentic's product range evolution. He enjoys feeding customer feedback into Acentic’s products making hoteliers' wishes become a reality.

Tuesday, September 21, 2010

Vulnerable Gateways in Hotels

by Thomas Herold

Free access to the internet, but safe for your data or your computer? Not at all.

Recently one of Acentic’s employees was traveling and seeking to get some good internet connectivity at his hotel. When he was finally connected he sent me an email with the subject: "This email is sent courtesy of our “xxx competitor.”  He had actually discovered that he was able to send emails through a competitor’s gateway without paying for the service. 

So we did a little investigation on this and it seemed that the competitor's gateway was only blocking from surfing the web and a couple of other standard services, but wasn't able to lock him out of Acentic’s own email service. Now we're not using anything unusual - it's a server from a company that probably has millions of installations in the world. In fact he was also able to connect to Acentic’s VPN service, which accidentally runs on the same protocol as our e-mail service, and with this active he was able to use the Internet to its fullest without paying a single cent.
 
Now obviously we weren't the only ones that have discovered this "loophole". A German journalist actually wrote an article about six months after our employee discovered it. In the article the author described exactly what our employee was experiencing. After this report showed up in the German Linux Magazine the provider hurried to close this loophole.
 
The reporter had analyzed the problem in detail and detected that the gateway was not really using a controlled firewall but rather detecting certain "known" applications on the network and redirecting them if the client hadn't paid. Everything that was unknown to the gateway (or rather that the developer hadn't thought of), would just pass through. Who knows how much revenue this provider has lost in the six months that have gone by - probably hundreds of thousands. Attention to security is as key as return on investment is. As providers of an essential service to guests, many of which send and receive confidential information, we take particular care to avoid such loopholes through extensive testing prior to release. Who knows what other holes the provider may have left open. To think that you're sitting there with no "real" firewall doesn't give you a very good feeling about using hotel high speed internet.
 
On Acentic Horizon, our high speed internet access solution, this is not a problem because we are using a far more advanced architecture that utilizes a controlled firewall - so loopholes are a thing of the past. It's either you've paid or you haven't with no way of bypassing this. And a good firewall, that even includes intrusion detection functionality with the added benefit of a truly enterprise class Wi-Fi installation, will give our customers the peace of mind they need.

Add comment


(Will show your Gravatar icon)

  Country flag

biuquote
  • Comment
  • Preview
Loading