site Search:


 
   
story category
Novatel MiFi Has Some Security Issues
Hacks give attacker ownership of device, access to GPS data
by Karl Bode Monday 18-Jan-2010 tags: wireless · hardware · security
Novatel's MiFi portable 3G to Wi-Fi router has become very popular among carriers, many of which are now selling rebranded version of the devices to their 3G customers (both Sprint and Verizon sell the unit as the MiFi 2200). According to Security researcher Adam Baldwin however, the device's security leaves a little something to be desired. A number of attacks can provide an attacker not only with control of the unit, but access to the GPS location of the MiFi device without the user becoming immediately aware. The attack can be executed without authentication and even if the GPS has been disabled by the administrator.

view: topics flat text 
Post a:

ycool

join:2001-12-04
Miami, FL

big bird is watching...

i better watch out, i got one of these from Sprint.

As I suspected, the government is watching us...

R4M0N
Brazilian Soccer Ownz Joo

join:2000-10-04
Glen Allen, VA

Re: big bird is watching...




equus
Funny, It Worked The Last Time
Premium
join:2000-10-02
Milpitas, CA

Re: big bird is watching...

Those eyes of that cat are really sad looking.........he seems to say>>>> I had nothing to do with this........really....all I wanted was to locate that stupid bird using my masters MiFi and the GPS........and he puts this tin-foil on me.......--
I thaw a puttytat,I did,I did.
iansltx

join:2007-02-19
Golden, CO
kudos:2

Overdrive?

If the Overdrive has this issue that's bad. If it doesn't it's good. I'll keep on recommending CradlePoints though.

r81984
Fair and Balanced
Premium
join:2001-11-14
Katy, TX
Reviews:
·AT&T U-Verse
·AT&T DSL Service
·row44

Meh.

I guess since no one offers unlimited bandwidth anymore this can be a big problem if you stay in one area for a while that does not have free wifi and someone downloads a lot of data using your mifi like on a greyhound bus, airplane terminal, or train. If they got access and maxed out your connection then you would notice right away as you would not be able to do anything.

Accessing the GPS does not matter since they have to be very close to you anyways.

Even though this flaw is pathetic and they need to fix it quickly it does not seem to be that big of a deal.
--
Republicans: less fiscally conservative than that other party.
jbelisle

join:2009-12-09
Lubbock, TX

Adam Baldwin (Security Researcher)

I love the 'security researcher' prefix (one of the reasons why Karl rocks), but it makes me laugh to think of the other Adam Baldwin making this observation public.

Maybe because I could totally see him do it, in character as Jayne Cobb or John Casey.

»en.wikipedia.org/wiki/Adam_Baldwin

Monday, 04-Jun 22:15:23 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.