We've lost the war [in cyberespionage] and we need to gain back ground." – Mark Culp, FBI San Diego Cybercrimes Division
Cybercriminals last year targeted hotels more than any other industry for credit card theft, according to a recent report by data security company Trustwave.
Hotels are being targeted because they have large amounts of credit card data and frequently neglect to implement the most basic security precautions, such as changing default passwords or ensuring programs are up to date, said Nicholas Percoco, senior vice president of Trustwave's SpiderLabs.
The Hotel Technology Next Generation (HTNG), a nonprofit hotel trade association, recently issued a security standard which defines how card data should securely flow between a hotel's various systems.
Additionally, large, brand-name organizations are beginning to take data security seriously, experts said. But many others are lagging."
Hotels: Globally targeted for industrial espionage
There's more to it than just credit card data being lost, but the same lax security principles affect your intellectual privacy as discussed previously. While there are ways to minimize risk, the ultimate reality is to simply assume that every time you leave your laptop in your hotel, someone else can and will try to gain access to it.There are many underemployed private investigators, intelligence analysts and the like who [globally] have the ability to quickly gain access into a hotel whether through social engineering by financial incentive [Read: BRIBE] or through a cousin [Read: INSIDER]. In a conversation this last weekend with a retired LEO, the issue of a warrant to search a hotel room was mentioned in connection with our tales of war stories and 'there I was.'The difference between law enforcement officers' approach and the private sector was underscored in the simple methods we used. Where they would get a search warrant in the course of an investigation I, acting [LEGALESE] as a private individual not acting as an agent of the law, would simply wave my investigation credentials at the clerk with a good story (sometimes accompanied by a couple dead presidents) and after a quick discussion often a room key would appear.- What really worked about 95 percent of the time was when two LEOs were parked outside in squad cars because often they were after the very same bad guy.
- Good story like, these guys sitting behind me in the squad cars are waiting for their boss to show up with the search warrant. I'm supposed to recover the stuff and you'll really be saving me hours of work if I just go in with them right now and get it back.
- Twenty to 30 minutes later, my toss of the room was done and the key went back to the clerk.
See Social engineering, Part 1: No school like old school
Regarding Wi-Fi and hotel business centers: Don't!
One simple rule is: Don't use them. Ever. That pretty much covers the widespread threat of hotel networks, hotel business centers. Just like gas pumps and credit card skimmers have become so thoroughly compromised, everything short of your own WWAN cell-based solution and a VPN back to your home network is to be treated as completely unsecure and compromised.- Even WWAN has drawbacks: it gets costly when global roaming data charges are figured in.
- Further, as the YouTube source interview with a wireless executive for our previous Spy vs. Spy on mobile states, in some countries where no formal boundaries between government and commerce exist, even the cell towers are not considered secure and private data is captured while in motion.
- Finally, if you must use hotel networks, make it harder by using a VPN or, at the very least, https:// and changing your passwords and logins immediately upon returning home.
Three rules to counter hotel intelligence efforts
Rule one: You get what you pay for – justify spending more for increased security.
Rule Two: Leverage the corporate experience you have.
Rule Three: Harden the target and make bad guys work for a living.
Counterintel: Corporate travel checklist
- What role does this traveler have?
- Where is this person heading?
- Who are they visiting?
- What information can they completely leave behind?
- What information must they have to perform their duties?
- What sensitive projects or information may they need to access while they are traveling?
When in Rome vs. HOTSU
Let's face it, the top way to cope with jet lag is not by sleep. In the industrial espionage game, however, industrial espionage interrogations aren't a water-boarding affair – unless you count body shots done at a karaoke bar.When in Rome, we do as the Romans do. Since 85 percent of the world's business population would be offended by a guest not partaking in a host's offer to go, we go along with, and the hardware we carry either stays in the hotel or in the host's office.Think that part through – if, as is recommended in other Spy vs. Spy articles, you don't have the hardware then you make the bad guy work for a living. As for the human element, the acronym HOTSU is often applicable: He's Out To Screw U: whether intentionally or unintentionally, a good night getting sloshed puts your common sense into a hurt locker.- After a very late night out with the locals who pour you back into a cab, you arrive at your hotel with 12 to 16 hours to recover before your flight.
- Hard to remember what you said if too much, and even harder to notice if anything in the room has been moved.
- On top of everything, nobody wants to tote a laptop all around Tokyo/Paris/London/Dubai or Singapore, so chances are you'll leave it someplace deemed 'secure enough' by reasonable standards.
