<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetStumbler</title>
	<atom:link href="http://www.netstumbler.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netstumbler.com</link>
	<description>The award-winning wireless networking tool and the best source for your daily Wi-Fi, WiMAX, 3G and VoIP news.</description>
	<lastBuildDate>Mon, 07 May 2012 16:45:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Is Marius Milner the unnamed google engineer?</title>
		<link>http://www.netstumbler.com/2012/05/07/is-marius-milner-the-unnamed-google-engineer/</link>
		<comments>http://www.netstumbler.com/2012/05/07/is-marius-milner-the-unnamed-google-engineer/#comments</comments>
		<pubDate>Mon, 07 May 2012 16:45:57 +0000</pubDate>
		<dc:creator>Brad Slavin</dc:creator>
				<category><![CDATA[Wardriving]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/?p=3073</guid>
		<description><![CDATA[Although sited in a number of articles about Marius Milner being the alleged Google engineer who was behind the WiFi mapping.   http://www.crn.com.au http://blog.seattlepi.com http://www.bloomberg.com FCC report on Google Street View Wi-Fi data collection We at Netstumbler.com have no comment at this time.]]></description>
			<content:encoded><![CDATA[<p>Although sited in a number of articles about Marius Milner being the alleged Google engineer who was behind the WiFi mapping.   </p>
<p><a href="http://www.crn.com.au/News/299072,netstumbler-creator-behind-google-wi-fi-snoop.aspx" rel="nofollow">http://www.crn.com.au</a></p>
<p><a href="http://blog.seattlepi.com/techblog/2012/05/01/report-google%E2%80%99s-wi-fi-sniffing-street-view-code-came-from-netstumbler%E2%80%99s-creator/" rel="nofollow">http://blog.seattlepi.com</a></p>
<p><a href="http://www.bloomberg.com/news/2012-05-04/google-s-wargaming-engineer-doe-at-privacy-probe-center.html" rel="nofollow">http://www.bloomberg.com</a></p>
<p><a style="margin: 12px auto 6px auto; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none; display: block; text-decoration: underline;" title="View FCC report on Google Street View Wi-Fi data collection on Scribd" href="http://www.scribd.com/doc/91952307">FCC report on Google Street View Wi-Fi data collection</a><iframe id="doc_31829" src="http://www.scribd.com/embeds/91952307/content?start_page=1&amp;view_mode=list" frameborder="0" scrolling="no" width="100%" height="600" data-auto-height="true" data-aspect-ratio=""></iframe></p>
<p>We at Netstumbler.com have no comment at this time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2012/05/07/is-marius-milner-the-unnamed-google-engineer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Easy Is it to Write Malware for Android?</title>
		<link>http://www.netstumbler.com/2012/01/16/how-easy-is-it-to-write-malware-for-android/</link>
		<comments>http://www.netstumbler.com/2012/01/16/how-easy-is-it-to-write-malware-for-android/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 20:26:51 +0000</pubDate>
		<dc:creator>Georgia Weidman</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/?p=3062</guid>
		<description><![CDATA[The Android platform is currently the top selling mobile platform in the U.S., and in quarter four of 2010 smartphones began to outsell PC platforms worldwide.  Android was even recently picked up as the choice platform for the U.S. Department of Defense. With the ubiquitousness of Android growing, naturally it and other smartphone platforms will [...]]]></description>
			<content:encoded><![CDATA[<p>The Android platform is currently the <a href="http://www.fiercemobilecontent.com/story/npd-apples-ios-closes-android-q4-sales-surge/2012-01-10">top selling mobile platform in the U.S.</a>, and in quarter four of 2010 <a href="http://www.idc.com/about/viewpressrelease.jsp?containerId=prUS22689111">smartphones began to outsell PC</a> platforms worldwide.  Android was even recently picked up as the <a href="http://www.federalnewsradio.com/?nid=394&amp;sid=2694787">choice platform for the U.S. Department of Defense</a>. With the ubiquitousness of Android growing, naturally it and other smartphone platforms will become prime targets for malware authors. Be it for fun or for profit, stealing your information, sending you spam, and other malicious activity, has been a widespread problem in the computing world for years. It is only natural that as smartphones know even more about their users than traditional PC platforms, and have access to additional features such as text messaging and GPS data, that they will be become juicy targets for high tech criminals.</p>
<p>This past year has seen new developments in Android malware both in the wild and by researchers intent on raising awareness and improving the state of security. The Droid Dream attack against Android in early 2011 made headlines for being the first known malware infection inside of the official Android market.  The malware was packaged with seemingly legitimate applications, but once installed, the apps turned Android phones into drones in a mobile botnet. This attack had been foreshadowed by security researchers when Jon Oberheide uploaded a <a href="http://jon.oberheide.org/files/summercon10-androidhax-jonoberheide.pdf">proof of concept app</a> to the Android market disguised as an inside look at the upcoming Twilight movie.  Though malware analysists and network security experts have been combating botnets for years, smartphones open new avenues of both attack and control, that experts simply don&#8217;t have as much experience analyzing. For example security researchers have created <a href="http://georgiaweidman.com/wordpress/?cat=10">proof of concept smartphone botnet </a>scenarios that use text messaging (SMS) for command and control mechanisms.</p>
<p><span id="more-3062"></span></p>
<p>Putting aside the continually growing sophistication of smartphone based attacks, how easy is it actually to attack Android phones? How much work would be involved to learn how to write an Android app, develop an app that performs malicious activity, and get that app up on the Android market? Is this something that a beginner could feasibly accomplish, or is Android malware solely the realm of hard core criminals with the skills, time, and money to develop cutting edge attack techniques?</p>
<p>I started off by learning a little bit about coding in Android. I have some coding background including in Java, the language from which the Android software development kit was derived. My only previous experience developing for smartphones was writing base operating system level proof of concept malware in C. I had never written a mobile app before. <a href="http://developer.android.com/resources/browser.html?tag=tutorial">Android Developer offers beginning tutorials</a>, which I worked through to get started.  Android prides itself on being easy for developers to pick up and dive into, and that was my experience as well.</p>
<p>My next goal was to write an app that performs malicious activity. Specifically I wanted to steal the smartphones personal identifier (IMEI) and send a text message without giving any indication to the user. As it turns out the Android API has built in capabilities to perform both of those tasks. The only caveat is the user has to be informed at install time that I want access to these clearly potentially dangerous capabilities.  Whenever a user installs an Android app, they are presented with a list of potentially dangerous capabilities the app requests.  An example install screen is shown below:</p>
<p style="text-align: center;"><img class="size-medium wp-image-3063 aligncenter" title="android_installer_georgia" src="http://cdn.netstumbler.com/wp-content/uploads/android_installer_georgia-247x300.png" alt="" width="247" height="300" /></p>
<p>I then wondered if malware writers need to somehow bypass this permission model  in some way so the dangerous permissions don&#8217;t show up at install. Would having a list of dangerous permissions that would allow an app to steal data and run up fraudulent charges raise a red flag to  average Android users  and deter them from installing an app? I did a search for popular Android apps to take a look at the permissions they request. The general consensus seems to be that the top downloaded Android app of all time is from an obscure company called Facebook. The complete list of permissions the Facebook for Android app requests upon install includes: sending SMS, reading the IMEI, the smartphone&#8217;s GPS information, accessing accounts stored on the phone including their credentials, among a long list of others that can be found <a href="https://market.android.com/details?id=com.facebook.katana">here</a>. As a sometimes proud member of Facebook since it was for college kids only, I often access Facebook from my computer. Facebook seems to work just fine without sending SMS, knowing my location, or having access to my Gmail password.  It appears that being warned about potentially dangerous permissions does nothing to deter users from installing apps to their Androids. To be fair, the Facebook app comes from a legitimate and well known company. Users have less reason to be wary of Facebook than they would the sort of apps seen in the DroidDream attack. That being said, as we saw in the recent detection of spyware in the <a href="http://www.washingtonpost.com/business/economy/feds-probing-carrier-iq/2011/12/14/gIQA9nCEuO_story.html">CarrierIQ service</a>  installed by default on many smartphone platforms, any service or app can be a potential malware source, even if the developer doesn&#8217;t intend for it to be malicious.</p>
<p>Now that I knew I could just use the Android API&#8217;s permission model to make my malicious app, I went about writing it. I thought I would have to search through the Android Development manager to find out the correct code for what I wanted to do. As it turned out, a quick Google search for &#8220;Send SMS Android App&#8221; or &#8220;Access IMEI Android App&#8221; revealed several other curious developers asking for and providing the code snippets I needed.  For example the code to send an SMS transparently to the user is only a two lines long:</p>
<p><code>SmsManager sm = SmsManager.getDefault();<br />
sm.sendTextMessage(number, null, message, null, null);<code></code></code></p>
<p>where number is the phone number to send the SMS to, and message is the message to send.  By requesting the right permissions I was able to quickly and easily build an app that accessed private data and sent it to another phone through SMS. The SMS does not appear in the user&#8217;s sent folder, so users receive no indication that the message has been sent.</p>
<p>My demo app in action video:</p>
<p><iframe src="http://player.vimeo.com/video/35039316?byline=0&amp;portrait=0" frameborder="0" width="400" height="225"></iframe></p>
<p>My last task was to see about getting my proof of concept app to the Android market. Using a Gmail account that didn&#8217;t link back to my real name I was able to sign up, and I used someone else&#8217;s credit card (with permission) to sign up. This leads me to believe it is possible for a malware author to leave no trace of her true identity on an app. I didn&#8217;t actually publish my app to the market, but other researchers have already proven that a malicious app is automatically published to the Android market upon upload.</p>
<p>My conclusions are that for anyone with any development experience it is easy to pick up the Android programming language. Thus any malware authors with experience on PC platforms will be able to make the switch to Android without any trouble. Also, the Android permission system is not working to keep users safe. The average, security unaware user will often simply install an app regardless of permissions. Using the API to call malicious functionality was straightforward given the correct permissions.  Finally, uploading a malicious app to the Android market is trivial.<br />
Read more about <a href="http://about.me/georgiaw">Georgia Weidman</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2012/01/16/how-easy-is-it-to-write-malware-for-android/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So you want to be a Security Consultant?</title>
		<link>http://www.netstumbler.com/2011/12/21/so-you-want-to-be-a-security-consultant/</link>
		<comments>http://www.netstumbler.com/2011/12/21/so-you-want-to-be-a-security-consultant/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 20:23:35 +0000</pubDate>
		<dc:creator>Brad Slavin</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/?p=3050</guid>
		<description><![CDATA[This is my first guest blogging opportunity on Netstumbler.com and I wanted to discuss what I believe is missing in most of the student/consultants I encounter. I would recommend these things for anyone preparing to be a consultant in IT security. So, the first and most important thing to learn in my opinion is TCP/IP. [...]]]></description>
			<content:encoded><![CDATA[<p>This is my first guest blogging opportunity on Netstumbler.com and I wanted to discuss what I believe is missing in most of the student/consultants I encounter. I would recommend these things for anyone preparing to be a consultant in IT security.</p>
<p>So, the <strong>first and most important thing to learn</strong> in my opinion is <a href="http://en.wikipedia.org/wiki/TCP/IP_model">TCP/IP</a>. You need to know it as well as you do the alphabet. The majority of people I meet in the University world and out in industry do not have a detailed and thorough knowledge of TCP/IP. For a security consultant it is best that you can look at the packets and know exactly what is taking place at the lowest level the wire. Elite hackers know TCP/IP as well as they can write their name. To be able to secure the environment and the enterprise it is imperative you know it like they do.</p>
<p>Take wireless for example, many people will start playing with <a href="http://www.wireshark.org">Wireshark</a> to observe the traffic over the wireless card, as most of you can attest to when you first use Wireshark with a wireless card you start a capture, and you see NOTHING, because you are at the application layer, and do not have a good understanding of the lower layers, and also do not understand that you need to be in monitor mode to capture traffic for the most part, and you are connected to the network, and cannot sniff the wireless traffic, so as you read the alert message that tells you to check the selection for promiscuous mode, and then you deselect it, and what do you see?  You see the 802.3 Ethernet traffic and not the 802.11 traffic you were expecting. Taking it one step further you need an understanding of the PHY layer before you start looking at a tools that analyze it for you.<br />
<span id="more-3050"></span><br />
The <strong>second most important thing is to learn</strong> Linux and Unix. Also, do not stop at Linux, download one of the Unix virtual machines and play with it until you get proficient at it.</p>
<p>A note on<strong> certifications</strong>, <em>they are good for getting you an interview, but once you get that interview you have to convince the people there that you know what you are doing.</em> There is <strong>no certification that can replace hands-on experience and knowledge</strong>, you can get that on your own by using virtual machines and building and running your own test labs. <em>The concern over certifications is most are based on rote memorization, it is the same problem we have in academic circles (more on that in a moment). </em></p>
<p>The problem with this is when you study and cram for a certification exam you memorize something take a test, and then you get certified, but what does this really mean? In my view it means you studied and took a test, and  be honest, some of these classes cram all of the information into your brain in 4-5 days, and if the class does not provide a study guide, or something similar to practice the types of questions you  may encounter you would not see 90% and above exam success rates touted by so many sites. Now, we shall discuss academic thinking, most of the “academics” without industry experience do not understand what I have been talking about either. I was on a <em>team that developed a Master of Science in Information Security</em>, and I was the only non-academic on the team, the entire group was made up of all PhDs but me, and as we discussed the curriculum I focused on teaching the students protocol analysis &#8230;  that is packets! Well this shocked pretty much all of the team, but I argued my point in many of the meetings, and finally swayed enough support where we had packet and protocol analysis as part of the curriculum</p>
<p>The <strong>most important thing I look for when hiring someone</strong> when I was running the Network Operations Center (NOC) is <strong>desire and initiative to learn</strong>. I would interview people with a list of certification as long as their arm, and when I asked them practical questions, they could not answer them, so they did not get the job. This is because I had junior personnel who could answer the questions, so how could I give someone a position over one of them at about 5 times the amount of pay they were getting. I could not justify it, and never did waiver on that. If  a person has desire that is the most important thing.  I had a guy come in fresh out of bootcamp that did not even know what UNIX was, and in 6 months he became my UNIX expert.</p>
<p>Another thing that helps is <strong>understanding programming</strong>, you do not have to be proficient at it, but being able to look at code and at least understand the fundamental concepts of it is very important in this field.</p>
<p><strong>Finally, it is all about research</strong>, I learned to do research in Graduate school, I had a Professor Frank Coyle that specializes in using JAVA for real time systems, and he was instrumental in teaching me how to do research, and that is the intent of these short research topics, the more practice you get the better you get to be at it. Today with the amount of online information you can  research  in a few hours with the Internet. When I was in graduate school, I spent weeks doing research at libraries, take advantage of this opportunity we have today. Recommend you dedicate one hour a night to reading something, a whitepaper etc. <em>There is a saying in the consultant field that as long as you can read the manual and understand it faster than the client you will always get the contract. That is why research is so important.</em></p>
<p>As I like to tell my clients, up until 2006 my certification count was 0, and now it is at 20, so it is not about getting a certification, it is what you do before and after you get that cert.</p>
<p><strong>- Kevin</strong></p>
<p>Kevin Cardwell currently works as a free-lance consultant and provides consulting services for companies throughout the world, and as an adviser to numerous government entities within the US and UK.</p>
<p>He is an Instructor, Technical Editor and Author for Computer Forensics, and Hacking courses. He is the<strong> author of the Center for Advanced Security and Training (CAST) Advanced Network Defense</strong> course. He is <strong>technical editor of the Learning Tree Course Ethical Hacking and Countermeasures</strong> and Computer Forensics. He is author of the Controlling Network Access course. He has presented at the Blackhat USA Conferences. He is a <strong>contributing author</strong> to the <strong>Computer Hacking Forensics Investigator V3 Study Guide and The Best Damn Cybercrime and Digital Forensics Book Period</strong>. He is a Certified Ethical Hacker (CEH), Certified Security analyst (E|CSA), Qualified Penetration Tester (QPT), Certified in Handheld Forensics, Computer Hacking Forensic Investigator (CHFI) and Live Computer Forensics Expert (LCFE), and holds a BS in Computer Science from National University in California and a MS in Software Engineering from the Southern Methodist University (SMU) in Texas.</p>
<p>You can find more information about Kevin at <a href="http://www.elitesecurityandforensics.com">www.elitesecurityandforensics.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2011/12/21/so-you-want-to-be-a-security-consultant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Offensive Mobile Forensics</title>
		<link>http://www.netstumbler.com/2011/12/12/offensive-mobile-forensics/</link>
		<comments>http://www.netstumbler.com/2011/12/12/offensive-mobile-forensics/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 16:32:26 +0000</pubDate>
		<dc:creator>Brad Slavin</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wi-Fi]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/?p=3028</guid>
		<description><![CDATA[Christmas is around the corner. Some of the top gifts are going to be shiny new mobile devices – smartphones, tablets, hacked Kindle Fires, Playbooks, and others. Is Exchange ActiveSync turned on in your environment? What is your plan for handling mobility in the Enterprise? But the biggest question of all is – What does [...]]]></description>
			<content:encoded><![CDATA[<p>Christmas is around the corner. Some of the top gifts are going to be shiny new mobile devices – smartphones, tablets, hacked Kindle Fires, Playbooks, and others. Is Exchange ActiveSync turned on in your environment? What is your plan for handling mobility in the Enterprise? But the biggest question of all is – What does a lost or stolen mobile device mean to your organization in terms of risk? What about when the CEO loses her device? Can you quantify your risk today?</p>
<p>The data leakage disclosed in this post has been gathered from a technique the author refers to as Offensive Mobile Forensics.  The term forensics is usually associated with incident response and management.  In other words, an activity performed after something bad has happened.  In contrast, offensive forensics is the act of preemptively performing a forensic analysis of systems or applications as a function of security testing, or for the purpose of quantifying risk.  An interesting side-effect of applying this technique to mobile device analysis is that it enables one to truly understand the risk of an attacker stealing or finding a lost device.  For example, if your analysis turns up native or third-party applications storing user credentials in cleartext – the author has seen everything from Facebook and Twitter to enterprise users’ Exchange ActiveSync credentials stored in the clear – depending on the accounts and data available, that could be a serious issue.<br />
<span id="more-3028"></span><br />
This technique depends on the ability to jailbreak (iOS) or root (Android) the target device, which provides root access to the underlying file system. If the reader is unfamiliar with these terms, some great resources to learn about jailbreaking and rooting are <a href="http://www.redmondpie.com/">Redmond Pie</a> (iOS) and <a href="http://www.xda-developers.com/">XDA-Developers</a> (Android). The author typically utilizes <a href="http://blog.iphone-dev.org/">Redsn0w</a> for iOS and <a href="http://forum.xda-developers.com/showthread.php?t=803682">SuperOneClick</a> for Android, performing virtually all Android analysis on Samsung devices.</p>
<p><strong>iOS</strong></p>
<p>After jailbreaking is complete, only one other tool is necessary, OpenSSH, used to pull data from the device to a host computer for analysis over WiFi.  However, as is always the case with information technology, there’s more than one way to accomplish your objective.  So, experiment with other tools, and tweak and tune your own methodology.</p>
<p>Although outside the scope of this blog post, readers interested in learning about some of the other tools used for this analysis technique can check out the <a href="http://hakin9.org/hacking-data-1111/">iOS Insecurities</a> article in November’s issue of Hackin9 Magazine. The article is a greatly expanded version of what’s here, and also includes a table listing physical locations on iOS devices that contain interesting information for analysis.</p>
<p>There are many different locations containing interesting data on iOS devices.  Data often resides in SQLite databases, the chosen format for local storage on mobile devices.  The next best place to find sensitive information is in plist, or property list files – these are the primary storage medium for configuration settings in iOS, and they are also a fantastic source of sensitive information.  User credentials are often stored here, instead of inside the KeyChain where they should be.  Rounding out the top three data sources are binary or binary-encoded files, such as the device’s keyboard cache and pasteboard.  Although storage locations commonly change with the release of new iOS firmware, it is fairly simple to poke around the general area and find what you’re looking for.</p>
<p>The most severe threat to mobile devices and applications is loss or theft of the device.  As the old saying goes, “if an attacker has physical access, it is game over.”  It only takes a few days of analyzing applications on a device to discover that the vast majority of mobile application developers fail to consider the threat of physical access to their data.  Simply put, they are stuck in the mindset of web application or client/server developers, where virtually all threats affect applications remotely.  Add some terrible design and implementation decisions related to native apps and services from Apple themselves, and you have a device that can pose a significant risk to enterprises and consumers in the event of loss or theft.  The following examples are provided in no particular order.</p>
<p><strong>Keyboard Cache (dynamic-text.dat)</strong></p>
<p>In an effort to learn how users type, iOS devices utilize a feature called AutoCorrection to populate a local keyboard cache on the device.  The problem is this feature records everything a user types that is not entered into a SECURE text field, which masks displayed data.  The author fondly refers to this feature as “Apple’s native keylogging facility”.  Data typed into text fields for virtually any application can remain in the cache for more than a year if it is not reset periodically by the user:</p>
<p>Settings &gt; General &gt; Reset &gt; Reset Keyboard Dictionary</p>
<p>Developers can also disable this feature programmatically by using the AutoCorrection = FALSE directive in desired UITextFields, although studies conducted with applications disabling this feature have shown users unanimously disapprove of it.</p>
<p>The file itself is a binary file, so passing it to the utility ‘strings’ is all that is required to generate newline-terminated output suitable for analysis.  Figure 1 displays the result of running ‘strings’ against the file, and Table 1 provides examples of near-complete conversations recorded by AutoCorrection.</p>
<div id="attachment_3035" class="wp-caption alignleft" style="width: 242px"><img class="size-medium wp-image-3035" title="KeyBoardCache" src="http://cdn.netstumbler.com/wp-content/uploads/KeyBoardCache-232x300.png" alt="" width="232" height="300" /><p class="wp-caption-text">Figure 1: Keyboard cache output to stdout in terminal</p></div>
<p>The keyboard cache is a well-known weakness in the iOS system, and there are many more interesting system-related locations to explore as an exercise for the reader.</p>
<div id="attachment_3036" class="wp-caption alignleft" style="width: 738px"><img class="size-full wp-image-3036" title="keyboard-cache" src="http://cdn.netstumbler.com/wp-content/uploads/keyboard-cache.jpg" alt="" width="728" height="179" /><p class="wp-caption-text">Table 1: Keyboard cache entries - read column top-down</p></div>
<p><strong>Application Data Leakage</strong></p>
<p>Third-party applications represent the greatest threat of data leakage on iOS devices.  This is usually the result of lazy or poorly-informed, or trained, developers storing user credentials or other sensitive information in clear text.  This threat can be mitigated by developers in several ways including storing user credentials in the KeyChain, encrypting sensitive information in plist files with the <a href="http://developer.apple.com/library/mac/">Common Crypto</a> library, or encrypting sensitive information in <a href="http://sqlcipher.net/ios-tutorial/">SQLcipher</a> SQLite databases. Figure 2 shows one example of a mobile application improperly storing credentials in a plist file.  Unfortunately, this particular application utilizes various Internet APIs for authentication including Evernote, Google Docs, Dropbox, and others, which in the event of loss or theft, could result in the compromise of each account.</p>
<div id="attachment_3037" class="wp-caption alignleft" style="width: 675px"><a href="http://cdn.netstumbler.com/wp-content/uploads/app-data-leakage-creds.png"><img class="size-full wp-image-3037" title="app-data-leakage-creds" src="http://cdn.netstumbler.com/wp-content/uploads/app-data-leakage-creds.png" alt="" width="665" height="369" /></a><p class="wp-caption-text">Figure 2: Credentials disclosed in an application&#39;s configuration PLIST</p></div>
<p><a href="http://cdn.netstumbler.com/wp-content/uploads/WiFi_creds_annotated.png"><img class="size-full wp-image-3046" title="WiFi_creds_annotated" src="http://cdn.netstumbler.com/wp-content/uploads/WiFi_creds_annotated.png" alt="" width="334" height="551" /></a></p>
<p><strong>Android</strong></p>
<p>Although there are many similarities between iOS and Android, there are a few notable differences that should be discussed. First, Android does not use property list files (“plist”) for storing configuration data, which is common on iOS devices. Android uses XML files instead of plists. Also, analysts will find many more SQLite databases on an Android device. In fact, configuration information is sometimes stored in SQLite database in lieu of utilizing XML files. Similarly to the configuration files for iOS, the XML files storing preferences for Android applications commonly include user credentials and other sensitive information. Finally, there is a very rich diagnostic and debugging environment in the Android platform, and unfortunately this output is also a common source of data leakage.</p>
<p>A huge difference between iOS devices and Android devices is the presence of the Android Debug Bridge (“ADB”) for the latter. Using the ADB, one can push or pull files to the device, review diagnostic information, and even gain access to a remote shell. The ADB Shell is the primary method of accessing the device&#8217;s file system for the purposes of pulling data to a host computer for analysis, or performing analysis on the device itself. More information on this, and other, differences can be found in the <a href="http://hakin9.org/hakin9-mobile-111-1/">Android Insecurities</a> article in January’s issue of Hakin9 Magazine.</p>
<div id="attachment_3046" class="wp-caption alignleft" style="width: 839px"></dt>
<dd class="wp-caption-dd">Annotated WiFi Credentials</dd>
</dl>
</div>
<p><strong>Email</strong></p>
<p>The Android system, like iOS, stores email in a SQLite database. Unlike iOS however, which stores email credentials in the KeyChain, user credentials on an Android system are stored in cleartext in the email database. This may seem like a trivial occurrence of data leakage, but in addition to personal email accounts such as Gmail, Exchange ActiveSync (“EAS”) credentials are also stored there. As if credentials weren&#8217;t bad enough, the database also stores messages in the clear, along with email addresses of contacts that have sent the user mail. This could be particularly devastating for corporate enterprises utilizing EAS, in the absence of a proper mobile device management (“MDM”) solution.</p>
<p>EAS and personal email account credentials can be discovered in a couple of different ways.  Figure 3 shows analysis of the EmailProvider.db SQLite file in Base, a GUI SQLite client. An even easier way to find user information is by simply running the ‘strings’ utility against the database file, as seen in Figure 4.</p>
<div class="mceTemp">
<dl id="attachment_3038" class="wp-caption alignleft" style="width: 839px;">
<dt class="wp-caption-dt"><img class="size-full wp-image-3038" title="EAS_GMAIL_Creds_2.3.4_Annotated" src="http://cdn.netstumbler.com/wp-content/uploads/EAS_GMAIL_Creds_2.3.4_Annotated.png" alt="" width="829" height="276" /><p class="wp-caption-text">Figure 3: Email credentials disclosure</p></div>
<p>&nbsp;</p>
<p><strong>WiFi</strong></p>
<p>The email situation is bad, but equally shocking is the method in which the Android system stores WiFi configuration information. Navigating to the <strong>/data/misc/wifi</strong> directory yields a configuration file called wpa_supplicant.conf on a Samsung Captivate that stores configuration information for every WiFi network the device has connected to – in cleartext. Assuming the data is disclosed to an attacker, an organization’s only defense is the use of multifactor authentication for their wireless networks, i.e., if corporate enterprise is using a combination of username and password exclusively, this could be a serious issue. The configuration file stores SSID, key management type, and the pre-shared key for the network.</p>
<div id="attachment_3039" class="wp-caption alignleft" style="width: 651px"><img class="size-full wp-image-3039" title="Strings_EASGMAIL_EmailProviderDB" src="http://cdn.netstumbler.com/wp-content/uploads/Strings_EASGMAIL_EmailProviderDB.png" alt="" width="641" height="172" /><p class="wp-caption-text">Figure 4: Email credentials disclosure</p></div>
<p>&nbsp;</p>
<p><strong>Conclusion</strong></p>
<p>Now, obviously various mitigating controls exist for protecting a user’s data on a mobile device, most notably the hardware-based encryption and <a href="http://developer.apple.com/library/ios/documentation/Miscellaneous/Conceptual/iPhoneOSTechOverview/iPhoneOSTechOverview.pdf">Data Protection</a> on the iPhone 4 and above, and encryption Android devices with Gingerbread. Passcodes lock devices, and in the case of Data Protection, enable a secondary layer of software-based encryption. That said, a recent study indicated over 50% of users don’t use a passcode at all on their devices, and another 20% utilize a 4-character combination that can be easily guessed in the usual 10 tries allotted – 1234, 4321, 9876, and so on. Add to this the ability to deploy OpenSSH as part of the jailbreaking process for iOS devices, the most prevalent choice for the Enterprise, or simply crack the passcode, and loss or theft is illuminated as a serious threat to data security. In the current ecosystem, with physical access to the device, it’s game over.</p>
<p><strong>Joey Peloquin</strong></p>
<p>Joey Peloquin is the director of mobile security at <a href="http://www.fishnetsecurity.com/">FishNet Security</a>, where he’s responsible for MDM technology review, mobile security research, testing methodologies, and business development. He’s spent the last twelve of twenty years in IT specializing in Information Security. His experience ranges from risk assessment to intrusion analysis and incident response, network and application penetration testing, and mobile forensics.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2011/12/12/offensive-mobile-forensics/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Novatel&#8217;s MiFi 2352 HSPA Review</title>
		<link>http://www.netstumbler.com/2009/06/22/novatels-mifi-2352-hspa-review/</link>
		<comments>http://www.netstumbler.com/2009/06/22/novatels-mifi-2352-hspa-review/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 09:34:29 +0000</pubDate>
		<dc:creator>Wayne Slavin</dc:creator>
				<category><![CDATA[3G]]></category>
		<category><![CDATA[MiFi]]></category>
		<category><![CDATA[Novatel]]></category>
		<category><![CDATA[GSM]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/?p=3005</guid>
		<description><![CDATA[SlashGear has gotten their hands on the new Novatel MiFi 2352. What makes this different from the previous version offered by Verizon and Sprint? Well, this one is GSM based and could see 3G download speeds of up to 7.2 Mbits and upload speeds of nearly 5.76 Mbits. For a detailed review, including unboxing pictures [...]]]></description>
			<content:encoded><![CDATA[<p>SlashGear has gotten their hands on the new Novatel MiFi 2352. What makes this different from the previous version offered by Verizon and Sprint? Well, this one is GSM based and could see 3G download speeds of up to 7.2 Mbits and upload speeds of nearly 5.76 Mbits.</p>
<p>For a detailed review, including unboxing pictures of this personal WiFi hotspot check out the review below.</p>
<p>Via [<a href="http://www.slashgear.com/novatel-wireless-mifi-2352-hspa-review-2147537/">SlashGear</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2009/06/22/novatels-mifi-2352-hspa-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon Opens Up, Will Support Any Device, Any App On Its Network</title>
		<link>http://www.netstumbler.com/2007/12/17/verizon-opens-up-will-support-any-device-any-app-on-its-network/</link>
		<comments>http://www.netstumbler.com/2007/12/17/verizon-opens-up-will-support-any-device-any-app-on-its-network/#comments</comments>
		<pubDate>Mon, 17 Dec 2007 23:45:00 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Spectrum]]></category>
		<category><![CDATA[Verizon]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/12/17/verizon-opens-up-will-support-any-device-any-app-on-its-network/</guid>
		<description><![CDATA[Verizon has joined the bandwagon and announced a new open access plan for its network. This plan will go into effect next year and means any application can run on any device from any manufacturer and will have full access to the Verizon spectrum. Verizon representatives say this move was prompted by two different motives, [...]]]></description>
			<content:encoded><![CDATA[<p>Verizon has joined the bandwagon and announced a new open access plan for its network. This plan will go into effect next year and means any application can run on any device from any manufacturer and will have full access to the Verizon spectrum.</p>
<p>Verizon representatives say this move was prompted by two different motives, the first being more sophisticated customer needs and the second is an explosion in innovation. They are hoping to see an wave of wireless devices flood the market in more arenas than the traditional handset market.</p>
<p>Some speculate that this decision is tied to the upcoming 700MHz spectrum auction, Verizon denies this was their motivation but the timing couldn&#8217;t be more coincidental.<br />
Via [<a href="http://arstechnica.com/news.ars/post/20071127-verizon-opens-up-will-support-any-device-any-app-on-its-network.html">arstechnica.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/12/17/verizon-opens-up-will-support-any-device-any-app-on-its-network/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Google May Get Its Open-access Wishes After All; Will Bid In 700MHz Auction</title>
		<link>http://www.netstumbler.com/2007/11/30/google-may-get-its-open-access-wishes-after-all-will-bid-in-700mhz-auction/</link>
		<comments>http://www.netstumbler.com/2007/11/30/google-may-get-its-open-access-wishes-after-all-will-bid-in-700mhz-auction/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 01:33:33 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[Spectrum]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/30/google-may-get-its-open-access-wishes-after-all-will-bid-in-700mhz-auction/</guid>
		<description><![CDATA[The much anticipated 700MHz spectrum auction in January officially has another bidder. Google has announced that it will toss its hat in the ring. A Google representative says that the company&#8217;s goal is to offer American consumers more choices in an open and competitive wireless world. Officially, Google doesn&#8217;t have to announce its plans until [...]]]></description>
			<content:encoded><![CDATA[<p>The much anticipated 700MHz spectrum auction in January officially has another bidder. Google has announced that it will toss its hat in the ring.</p>
<p>A Google representative says that the company&#8217;s goal is to offer American consumers more choices in an open and competitive wireless world. Officially, Google doesn&#8217;t have to announce its plans until December 3rd so until then speculations abound.</p>
<p>Some say Google has no interest in becoming a network provider, others look to the previously proposed four open access provisions, or possibly they will lease space to others. Nothing is certain at this point except that when Google does make its plans known it will create a nationwide buzz.<br />
Via [<a href="http://arstechnica.com/news.ars/post/20071116-its-official-google-planning-700mhz-bid.html">arstechnica.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/30/google-may-get-its-open-access-wishes-after-all-will-bid-in-700mhz-auction/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CBS Offers Midtown Manhattan Free Wireless Internet Access</title>
		<link>http://www.netstumbler.com/2007/11/29/cbs-offers-midtown-manhattan-free-wireless-internet-access/</link>
		<comments>http://www.netstumbler.com/2007/11/29/cbs-offers-midtown-manhattan-free-wireless-internet-access/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 19:12:11 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Municipal]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/29/cbs-offers-midtown-manhattan-free-wireless-internet-access/</guid>
		<description><![CDATA[CBS has just made an announcement that is sure to delight New Yorkers. From Times Square to Central Park and from 6th to 8th Avenue will become the new CBS Mobile Zone. This zone will carry free Wi-Fi for cell phones, laptops and other devices that want to access the internet or even make voice [...]]]></description>
			<content:encoded><![CDATA[<p>CBS has just made an announcement that is sure to delight New Yorkers. From Times Square to Central Park and from 6th to 8th Avenue will become the new CBS Mobile Zone. This zone will carry free Wi-Fi for cell phones, laptops and other devices that want to access the internet or even make voice over internet phone calls.</p>
<p>In return, CBS gets ad impressions, tons of them. Visitors to the region will be greeted with a sponsored homepage with hyperlocal news and information for people within the specified area.</p>
<p>CBS Outdoor Chairman and CEO, Wally Kelly, explains that this is just one example of how CBS is dedicated to turning Outdoor assets into next-generation interactive platforms.<br />
Via [<a href="http://www.centernetworks.com/manhattan-free-wifi-cbs-mta-partnership">centernetworks.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/29/cbs-offers-midtown-manhattan-free-wireless-internet-access/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Can WiMax Make It In The U.S.?</title>
		<link>http://www.netstumbler.com/2007/11/19/can-wimax-make-it-in-the-us/</link>
		<comments>http://www.netstumbler.com/2007/11/19/can-wimax-make-it-in-the-us/#comments</comments>
		<pubDate>Mon, 19 Nov 2007 19:00:56 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[WiMAX]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/19/can-wimax-make-it-in-the-us/</guid>
		<description><![CDATA[The deal struck between Sprint Nextel and Clearwire back in July has been scrubbed and the national WiMAX network took a hit. Both companies say they will continue to work on the technology independently. Although both companies appear committed to developing WiMAX, their shareholders may actually hold the reins as huge sums of money are [...]]]></description>
			<content:encoded><![CDATA[<p>The deal struck between Sprint Nextel and Clearwire back in July has been scrubbed and the national WiMAX network took a hit. Both companies say they will continue to work on the technology independently.</p>
<p>Although both companies appear committed to developing WiMAX, their shareholders may actually hold the reins as huge sums of money are necessary to go forward.</p>
<p>Manufacturers of WiMAX equipment feel the technology is still sound and they plan to go ahead with device creation, it just may take longer for the technology to take hold. AAA So, the future of WiMAX is uncertain, it may be better suited for emerging markets than the U.S., only time will tell.<br />
Via [<a href="http://www.news.com/Can-WiMax-make-it-in-the-U.S./2100-1039_3-6217947.html">news.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/19/can-wimax-make-it-in-the-us/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Clearwire, Sprint Call Their Deal Off</title>
		<link>http://www.netstumbler.com/2007/11/14/clearwire-sprint-call-their-deal-off/</link>
		<comments>http://www.netstumbler.com/2007/11/14/clearwire-sprint-call-their-deal-off/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 04:42:59 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Clearwire]]></category>
		<category><![CDATA[Sprint]]></category>
		<category><![CDATA[WiMAX]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/14/clearwire-sprint-call-their-deal-off/</guid>
		<description><![CDATA[The recent departure of Sprint CEO, Gary Forsee, is having some far reaching impact. The WiMAX build out between Sprint Nextel and Clearwire is the latest victim as the proposed joint, nationwide WiMAX effort has been dropped. Sprint&#8217;s corporate shake up was not the only reason the proposed venture was nixed,the complexities of the transaction [...]]]></description>
			<content:encoded><![CDATA[<p>The recent departure of Sprint CEO, Gary Forsee, is having some far reaching impact. The WiMAX build out between Sprint Nextel and Clearwire is the latest victim as the proposed joint, nationwide WiMAX effort has been dropped.</p>
<p>Sprint&#8217;s corporate shake up was not the only reason the proposed venture was nixed,the complexities of the transaction were also cited as a stumbling block. So that leaves the American WiMAX project in a bit of a conundrum, do Sprint and Clearwire go out and forge independent networks or will new bonds form?</p>
<p>In the meantime, WiMAX is progressing nicely overseas, proving that they technology is valid and workable.<br />
Via [<a href="http://gigaom.com/2007/11/08/clearwire-sprint-call-their-deal-off/">gigaom.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/14/clearwire-sprint-call-their-deal-off/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High-speed Wireless Video Transfers 100X Faster Than WiFi On Tap</title>
		<link>http://www.netstumbler.com/2007/11/05/high-speed-wireless-video-transfers-100x-faster-than-wifi-on-tap/</link>
		<comments>http://www.netstumbler.com/2007/11/05/high-speed-wireless-video-transfers-100x-faster-than-wifi-on-tap/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 17:56:21 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Chipsets]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/05/high-speed-wireless-video-transfers-100x-faster-than-wifi-on-tap/</guid>
		<description><![CDATA[IBM has joined forces with MediaTek to develop microprocessor chipsets that will wirelessly transmit videos almost instantly. These chipsets will let you connect HDTVs with set top boxes without the need for wires. They will also transfer data at rates of at least 100 times that of current WiFi standards. This new technology, mmWave wireless, [...]]]></description>
			<content:encoded><![CDATA[<p>IBM has joined forces with MediaTek to develop microprocessor chipsets that will wirelessly transmit videos almost instantly.</p>
<p>These chipsets will let you connect HDTVs with set top boxes without the need for wires. They will also transfer data at rates of at least 100 times that of current WiFi standards.</p>
<p>This new technology, mmWave wireless, is expected to be used widely in homes and offices.<br />
Via [<a href="http://www.networkworld.com/community/node/20854">networkworld.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/05/high-speed-wireless-video-transfers-100x-faster-than-wifi-on-tap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WiMAX Is 3G</title>
		<link>http://www.netstumbler.com/2007/11/01/wimax-is-3g/</link>
		<comments>http://www.netstumbler.com/2007/11/01/wimax-is-3g/#comments</comments>
		<pubDate>Thu, 01 Nov 2007 16:22:04 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[3G]]></category>
		<category><![CDATA[WiMAX]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/11/01/wimax-is-3g/</guid>
		<description><![CDATA[WiMAX has a reason to celebrate. The International Telecommunications Union has just approved the non-cellular technology as part of a 3G standard. This means that operators with 3G spectrum in their 2.5 GHz bands globally can use WiMAX to build out a spectrum. The last interface added was back in 1999 when ITU added IMT-2000 [...]]]></description>
			<content:encoded><![CDATA[<p>WiMAX has a reason to celebrate. The International Telecommunications Union has just approved the non-cellular technology as part of a 3G standard. This means that operators with 3G spectrum in their 2.5 GHz bands globally can use WiMAX to build out a spectrum.</p>
<p>The last interface added was back in 1999 when ITU added IMT-2000 as it established the original technologies. IMT-2000 and five other cellular standards had to be used in the 3G standard, now the door is open to WiMAX.</p>
<p>But all is not rosey for WiMAX, the debate between technologies is far from over.<br />
Via [<a href="http://www.wirelessweek.com/WiMAX-is-3G.aspx">wirelessweek.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/11/01/wimax-is-3g/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wi-Fi Health Study Gets Go Ahead</title>
		<link>http://www.netstumbler.com/2007/10/25/wi-fi-health-study-gets-go-ahead/</link>
		<comments>http://www.netstumbler.com/2007/10/25/wi-fi-health-study-gets-go-ahead/#comments</comments>
		<pubDate>Thu, 25 Oct 2007 10:57:14 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Health]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/10/25/wi-fi-health-study-gets-go-ahead/</guid>
		<description><![CDATA[The BBC has announced that the Health Protection Agency is going to begin a systematic research program on how WiFi is used. The goal of this study is to determine how WiFi is being used and the possible radiation exposure that results from such use. Spokesmen from the HPA believe that the study will confirm [...]]]></description>
			<content:encoded><![CDATA[<p>The BBC has announced that the Health Protection Agency is going to begin a systematic research program on how WiFi is used. The goal of this study is to determine how WiFi is being used and the possible radiation exposure that results from such use.</p>
<p>Spokesmen from the HPA believe that the study will confirm the safety of using WiFi, but feel that since England&#8217;s Chief Medical Officer suggested children limit their non-essential cell phone use due to potential exposure to radiation that a study into the radition emmissions of WiFi was the next logical step.</p>
<p>Results of the study will be publicly available, but officials reinforce their belief that WiFi is safe.<br />
Via [<a href="http://news.bbc.co.uk/2/hi/technology/7042334.stm">bbc.co.uk</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/10/25/wi-fi-health-study-gets-go-ahead/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>WiMAX Backers Positioning 802.16e As An Alternative To Municipal WiFi</title>
		<link>http://www.netstumbler.com/2007/10/17/wimax-backers-positioning-80216e-as-an-alternative-to-municipal-wifi/</link>
		<comments>http://www.netstumbler.com/2007/10/17/wimax-backers-positioning-80216e-as-an-alternative-to-municipal-wifi/#comments</comments>
		<pubDate>Wed, 17 Oct 2007 10:04:11 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Municipal]]></category>
		<category><![CDATA[WiMAX]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/10/17/wimax-backers-positioning-80216e-as-an-alternative-to-municipal-wifi/</guid>
		<description><![CDATA[Chicago&#8217;s WiMAX World show displayed a large rift between Mobile WiMAX supporters and municipal WiFi. With continued problems halting all progress in the municipal WiFi world, WiMAX supports say they have the solutions. They contend that their licensed spectrum will guarantee continuous coverage and that indoor reception will not be as problematic as it is [...]]]></description>
			<content:encoded><![CDATA[<p>Chicago&#8217;s WiMAX World show displayed a large rift between Mobile WiMAX supporters and municipal WiFi.</p>
<p>With continued problems halting all progress in the municipal WiFi world, WiMAX supports say they have the solutions. They contend that their licensed spectrum will guarantee continuous coverage and that indoor reception will not be as problematic as it is for WiFi.</p>
<p>But all is not rosy in the world of WiMAX, hardware is a huge problem. Every laptop has built-in support for 802.11b/g and will soon have 802.11n, this won&#8217;t be the case for WiMAX for quite some time, several years at least.</p>
<p>Right now all eyes are on Sprint and their pricing of Xohm. A reasonable price point may make or break a WiMAX solution for the masses.<br />
Via [<a href="http://arstechnica.com/news.ars/post/20070927-wimax-backers-positioning-802-16e-as-an-alternative-to-municipal-wifi.html">arstechnica.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/10/17/wimax-backers-positioning-80216e-as-an-alternative-to-municipal-wifi/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Silicon Valley Wireless Nears Crunch Time</title>
		<link>http://www.netstumbler.com/2007/10/02/silicon-valley-wireless-nears-crunch-time/</link>
		<comments>http://www.netstumbler.com/2007/10/02/silicon-valley-wireless-nears-crunch-time/#comments</comments>
		<pubDate>Tue, 02 Oct 2007 09:22:35 +0000</pubDate>
		<dc:creator>Kristin Abraham</dc:creator>
				<category><![CDATA[Municipal]]></category>

		<guid isPermaLink="false">http://www.netstumbler.com/2007/10/02/silicon-valley-wireless-nears-crunch-time/</guid>
		<description><![CDATA[Another massive wireless network has fallen behind schedule, this time the location is California&#8217;s Silicon Valley. About 40 municipalities over a 1500 square mile area are still in negotiations but representatives have said that the model should be completed by the end of the year. So far the delay has been blamed on technological improvements [...]]]></description>
			<content:encoded><![CDATA[<p>Another massive wireless network has fallen behind schedule, this time the location is California&#8217;s Silicon Valley. About 40 municipalities over a 1500 square mile area are still in negotiations but representatives have said that the model should be completed by the end of the year.</p>
<p>So far the delay has been blamed on technological improvements and changes and the deeply complex process of covering multiple technologies and different services. This may be so, but the template agreement is still not finalized and even when finally done, it still needs to go to individual municipalities for some tweaking.</p>
<p>Like the struggling citywide Wi-Fi in other cities across the country, their plan is very ambitious and progress is slow.<br />
Via [<a href="http://www.infoworld.com/article/07/09/14/Silicon-Valley-wireless-nears-crunch-time_1.html">infoworld.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netstumbler.com/2007/10/02/silicon-valley-wireless-nears-crunch-time/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached
Database Caching 6/52 queries in 0.074 seconds using memcached
Object Caching 1049/1158 objects using memcached
Content Delivery Network via Amazon Web Services: CloudFront: cdn.netstumbler.com

Served from: www.netstumbler.com @ 2012-05-16 07:58:12 -->
