A rogue (AP) access point is a wireless access point that has been installed on a secure network without explicit authorization from a local network administrator, whether added by a well-meaning employee or by a malicious attacker.
To make a point, a firewall supplier installed one of these (a rogue AP) at the recent RSA Conference in San Francisco last month in a successful attempt to demonstrate the dangers of open WiFi hotspots at places like airports and Starbucks cafes.
The attempt was successful because in spite of the tens of thousands of the best security professionals on the planet who were in attendance and should have known better, almost 2,500 of them connected to that network anyway.
This particular rogue AP was of the type that broadcast a few common network names that seemed familiar on first glance. The tendency for us mere mortals is to save the network name and automatically connect to it the next time we are in that hotspot area. Surely, actual security professionals wouldn’t do such a thing, would they?
They sure did. And they did so with a variety of devices; smartphones, laptops, tablets, wearables, etc., each broadcasting their particulars to the network and opening themselves up to commonly used exploits like phishing for login credentials or credit card data using bogus splash pages, or other sensitive data snooping through Man-in-the-middle attacks.
But, there was also a second and more remarkable surprise: The number one application these security experts preferred was peer-to-peer file sharing. Oh dear.
Without repeating all of the now obvious dangers to open WiFi use and examining the many free tools available to WiFi hackers these days, it is sufficient to say that setting up a rogue AP is easy and tricking Wi-Fi devices to connect to it even easier.

The question is what can you do about it?
- Stop the laziness. Don’t choose to “save Wi-Fi network” and “automatically reconnect” when joining random and unverified Wi-Fi networks. Unless, the network is at your home, office or a trusted location, just say no.
- When using any open Wi-Fi hotspot, always check to see if the website is using HTTPS encryption by looking for the “HTTPS” or a padlock icon in or near the nav bar.
- Make sure that traditional devices like laptops have modern endpoint protection installed.
- Never input login credentials, credit card information, or other sensitive data over any WiFi.Period.
And, if you’re a business that wants to offer or is providing WiFi hotspots, you had better have some solid cyber-security infrastructure in place, including regulatory compliance adherence, be mindful that security experts have continually warned that open hotspots are not secure, and most of the data transferred is not encrypted.
While you definitely don’t want to be the security expert who is hacked because she logged onto an open WiFi network out of laziness, you definitely don’t want to be that other guy either.
It happens everywhere now and 90% of it is sourced in human error







