BT
Users of BT Home Hub could be open to attack

Hackers issue BT Home Hub warning

Popular wireless router 'easily cracked'

Written by Guy Dixon

The bad guys can break into your network if you're using the default encryption key

GNUCitizen 

Ethical hacking group GNUCitizen.org has warned that the default settings on one of the UK's most widely used wireless routers is leaving customers open to attack.

The group showed in a blog posting that the BT Home Hub, the wireless router supplied to BT Broadband customers, uses algorithms that make the device easy to crack when in default mode.

Using reverse-engineering techniques the group said that the hub's Wired Equivalent Privacy (WEP) keys can be predicted in just 80 guesses, but had decided against making its automated guessing program publicly available.

GNUCitizen's findings appear to confirm long-term concerns about the security of the WEP encryption protocol.

"It is quite likely that the bad guys can break into your network if you are using the default encryption key. Our advice is to use WPA rather than WEP and change the default encryption key now," GNUCitizen said.

Responding to the criticisms, BT denied that real-life users of the device were in any serious danger of hack attacks.

"It is important to realise that, although it has been possible to demonstrate a scenario where the hub may be vulnerable, we do not believe it is something that should affect the majority of BT customers in real life," the company said in a statement.

BT, which has published details on how to more effectively secure the router, said that other operators supplying the Thomson-manufactured device were also affected by the issue.

Further reading

BT acquires Wire One

Telco expands videoconferencing portfolio   More...

Ben Verwaayen steps down at BT

Ian Livingston picks up the baton   More...

BT confirms secret Phorm trial

Telco insists user data was not compromised   More...

BT hamstrings Home Hub hackers

Remote Assistance feature switched off completely   More...

Related articles

Staff wireless networks put data at risk

Employees plugging their own routers into access points   More...

Online love seekers warned of flirt-bots

Porn overcomes Turing Test   More...

Black hat IPS reverse engineering poses 'serious threat'

Gartner warns enterprises to be on their guard   More...

DRam crack breaks encryption software

Researchers find way to foil disk encryption   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement