Tuesday, August 3, 2010

Clearwire Must Double Network Reach to Hit 2010 Target

GigaOm notes that Clearwire's 201 target of 120m people covered in 2010 could be hard to reach given its 51m passed numbers today: Stacey Higginbotham writes that Verizon's expected 2010 launch of a 100m-passed LTE 4G network could put a crimp in Clearwire's plans. However, as she notes, Clearwire's 4G pricing and limits (none on most plans) could provide an advantage over AT&T and Verizon, which place relatively tight limits on mobile broadband today.



Clearwire Adds Integrated Mobile Hotspots, New 3G/4G Modem for MacsPixie Lott would like to go psychedelic

Friday, July 30, 2010

Apple Booted Skyhook, Google Location Services in iOS 4

TechCrunch read Apple's letter to a congressman about the kind of data it collects more carefully than most: The letter says Apple dropped Google (which was, I believe, supplying cellular tower triangulation information) and Skyhook Wireless from iOS 4, which powers the iPhone 4 and 2008 and 2009 models of iPhone and iPod touch.

Long-time readers of this site know that Skyhook Wireless has spent many years driving the streets of major cities and aggregating information provided in the form of queries from mobile devices to build a comprehensive and constantly updated Wi-Fi positioning system. While Wi-Fi isn't precise, it's not far off from GPS in urban areas.

As more mobile devices gain full-featured GPS chips and functions, Wi-Fi positioning remains important as a component in Assisted GPS (which allows a GPS to get a fix faster) and in providing an initial rapid location assessment, sometimes in a few seconds.

But location data is incredibly valuable, and owning the data is perhaps worth the price. Apple has apparently, quietly generated its own Wi-Fi and cell tower databases. It has enough mobile devices in the field with GPS receivers that it can use that information to build a comprehensive picture of most cities, I'd imagine. Every time a device queries location and sends a Wi-Fi and cell environmental scan with or without GPS coordinates, that's more data to crunch.

I thought Skyhook Wireless would have a leg up here because of Google's agreement to not scan for Wi-Fi in several countries (or perhaps worldwide) after it's data-collection debacle with Street View. And Apple's not the only fish in the pond. Skyhook has deals with many, many other platforms and providers.



LCD Soundsystem & Hot Chip announce autumn co-headline showsClearwire Adds Integrated Mobile Hotspots, New 3G/4G Modem for Macs

More Detail on Wi-Fi Exploit "Hole196"

More Detail on Wi-Fi Exploit Hole196

At Ars Technica, you can read my long explanation of the group key weakness in WPA/WPA2 Enterprise-protected networks: The information I was given was originally under embargo, but the firm and unrelated researchers released essentially all the data except a video of an exploit in action and some of the mitigation information. Hence, the long Ars Technica piece.

Boiled down, I don't think anyone need worry about Hole196, which describes how an insider with an account on a WPA/WPA2 Enterprise network can send group broadcast packets spoofed to appear as if they originate from the access point for clients attached to that access point.

It's a hole, all right, but it requires so many particular circumstances to be met, that a spy or thief working for a company (or an outsider having gained credentialed access) would most likely have easier methods to get in--or would be detected by other means.

The best lesson I can take away from this hole? Make sure you're running virtual SSIDs if you have that option to separate guests, contractors, and others from employees; or to isolate different kinds of operations within your company.

Because each virtual SSID on an access point is treated nearly as a virtual AP, the group key isn't shared across the access point among different virtual SSID. The BSSID, or AP identifer, is unique for each virtual network on each AP.



Don’t Blame It on the MiFi, After AllThe Cars hint at reunion on Facebook

NetJets Picks Aircell for In-Flight Internet

NetJets Picks Aircell for In-Flight Internet

Internet in the air isn't all about commercial aviation: NetJets, a fractional plane ownership business owned by Warren Buffett's Berkshire Hathaway, will put Aircell's general aviation Internet product (Aircell High Speed Internet) in 250 of its mid-to-large aircraft.

NetJets has a fleet of 800 jets, which are used in increments by "owners," who opt for this rather than the expense of maintaining their own planes. It's hardly a crowd that pinches pennies; dollars, maybe. It's thus a perfect audience for heavy Internet use.



SFO Goes Free

Monday, July 26, 2010

AT&T Expands Hotzone Test to Charlotte, NC

AT&T Expands Hotzone Test to Charlotte, NC

AT&T has added a second location in its outdoor hotzone pilot program: Charlotte, NC's downtown is the second area to get an AT&T hotzone designed to offload network traffic from the company's 3G network and boost performance for customers. The first such hotzone was lit up in Times Square in Manhattan; a third zone is coming to Chicago soon.

The idea of a hotzone makes perfect sense for a firm that's getting criticism for being unable to meet the data needs of subscribers in some cities and neighborhoods. Wi-Fi cells can be quite small, and have much higher capacity than cell channels, while being enormously cheaper to run, partly because there's no opportunity cost related to expensive cellular spectrum licenses.

These AT&T hotzones differ from municipal Wi-Fi efforts started in 2005 and mostly abandoned by 2007. Municipal networks were typically designed to require private investment by firms to provide indoor and outdoor network coverage to 90–95 percent of a city.

AT&T hotzones will cover outdoor areas of high traffic, and work only for customers. There's no specific municipal benefit involved, and AT&T will control its deployments entirely.

It's a smart move. AT&T could likely spend less a tenth as much in high-traffic areas to add Wi-Fi as to beef up cellular. And there's only so much spectrum available, meaning that in many areas there may be no real way to enhance the 3G data side.

This is Wi-Fi as a 3G network heat sink.



Merc Mix It Up with In store live Summer SessionsT-Mobile Expands HSPA+ Markets

AT&T Continues Massive Increases in Wi-Fi Sessions

The telecom behemoth is also gigantic in giving away Wi-Fi to customers: AT&T's quarterly report on Wi-Fi usage finds the firm serving 121m sessions in the first six months of 2010; that compares to 86m sessions in all of 2009. Second quarter 2010 saw 68m sessions used, compared with 15m in the year-ago second quarter. Second quarter was also a 30-percent increase over first quarter.

That's great, but you'll note that the names McDonald's and Starbucks aren't mentioned anywhere in the press release. McDonald's and Starbucks represent about 19,000 of AT&T's "more than 20,000" locations.

In January, McDonald's opened its Wi-Fi network to everyone at no cost; previously, AT&T customers (wired, DSL, fiber, remote business, and laptop 3G) got access at no cost, and so did roaming network partners. One expects that McDonald's drove part (but not all) of the increase.

Likewise, on 1 July 2010, Starbucks shifted from its modestly complicated free two hours' offer, where you needed a Starbucks stored-value card, to unlimited free service for everyone. I expect we'll see a big jolt as a response, because it removes friction for short, casual use, as opposed to longer use in which anyone who figured it out would already have been using Starbucks' Wi-Fi at no cost.

You can't disregard other factors, however. AT&T continues to add wireless, laptop 3G, and fiber customers (although I believe DSL and landline markets are static or shrinking). Those users gain free service on subscribing. And existing users rely more on using free service as available.

The couple of million iPads that AT&T sold as part of the 3m+ worldwide totally likely are part of that jump in usage. A single iPad user could consume dozens of sessions a day, either on the AT&T free locations (with a Wi-Fi only unit or a 3G iPad without an active 3G subscription), or across AT&T's network with a 3G iPad and an active 3G data plan. (The active data plan gives you access to hotels, airports, and other otherwise for-fee locations, and some roaming locations on reciprocal networks.)

Finally, AT&T switch a few weeks ago from unlimited service plans to cheaper, limited plans for new customers or those that opt to switch away from unlimited will likely mean bargain hunters like yours truly will work harder to find free Wi-Fi instead of consuming expensive 3G juice.



Merc Mix It Up with In store live Summer SessionsStarbucks Goes All-In: Free, Unlimited Wi-Fi Starting July 1st

Saturday, July 24, 2010

Researcher Hints 802.1X WPA2 Flaw

Researcher Hints 802.1X WPA2 Flaw

AirTight Networks' researcher Md Sohail Ahmad will present a WPA2/802.1X weakness at DEFCON18 next week: The press release from AirTight doesn't give away too many details, but I believe this an 802.1X problem because it requires an authenticated user on a network that has unique master key material for multiple users. Hence, 802.1X, where WPA2 is used to secure the connection, and a user login causes a master key to be generated.

My suspicion is that there's a weakness in broadcast key implementation, since that's a natural place. That's confirmed by the name the researcher has given the weakness: "Hole 196," which the press release says refers to page 196 of the revised IEEE 802.11-2007 specification.

The note at the bottom, in a section on Robust Security Network Association (RSNA) used for the 4-way handshake for authentication dealing with the group temporal key (used to protect broadcast and multicast data), reads:

"NOTE—Pairwise key support with TKIP or CCMP allows a receiving STA to detect MAC address spoofing and data forgery. The RSNA architecture binds the transmit and receive addresses to the pairwise key. If an attacker creates an MPDU with the spoofed TA, then the decapsulation procedure at the receiver will generate an error. GTKs do not have this property."

This could be a serious exploit for corporations, government, and academic institutions that use 802.1X, and rely on the intra-network security of having one user unable to sniff the traffic of any other user. This is not a generic WPA2 or AES-CCMP key extraction exploit; I'm not sure any key recovery is involved at all.



Class-Action Suit against Google Has Gaping Hole