They were equipped with a computer with Wi-Fi enabled and a free application to monitor Wi-Fi traffic at a frequency of 2.4 GHz. The experiment showed how easy it is to view browsing activity, searches, passwords, videos, emails, and other personal information.
The study revealed that users in Asia are more vulnerable to attacks. More than half of web traffic in Asia is on unsecured HTTP sites, 97% of users connect to open and unsecured Wi-Fi networks, and seven out of ten password-protected routers use weak encryption methods, making them easy to hack. Users in San Francisco and Barcelona tend to take more steps to protect their Wi-Fi sessions; however, the percentage remains very small, with only 20% taking precautions.
“This experiment has revealed that most mobile device users are not taking adequate precautions to protect their personal data and privacy from cybercriminals,” says Jude McColgan, president of Avast’s mobile division. “People use seatbelts to stay safe in the car; they should use a security app when using public Wi-Fi.”
Beware of unsecured Wi-Fi networks.
The study showed that people worldwide prefer to connect to unsecured, unprotected Wi-Fi networks rather than password-protected ones. Mobile device users in Asia connect to open networks most frequently, while Europeans and Americans do so less often. In Seoul, 99 out of 100 users connect to unsecured networks, compared to 80 out of 100 in Barcelona and San Francisco.
1) Seoul: 99 out of 100
2) Hong Kong: 98 out of 100
3) Taipei: 97 out of 100
4) Chicago: 96 out of 100
5) New York: 91 out of 100
6) Berlin: 88 out of 100
7) London: 83 out of 100
8) Barcelona: 80 out of 100
9) San Francisco: 80 out of 100
Dangers of HTTP Browsing:
Avast discovered that a significant proportion of mobile device users primarily browse insecure HTTP sites. Nearly half of web traffic in Asia is on unsecured HTTP sites, while in the United States it's a third and in Europe a quarter.
Because HTTP traffic is unsecured, the Avast team was able to see users' browsing activity, including domain and page history, searches, personal information, videos, emails, and comments. Websites like eBay, Amazon, Wikipedia, and Bing do not use the HTTPS standard unless the user is logged in. In each city, Avast was able to see examples of users visiting websites for medical services, insurance, banking, and adult videos. All of this occurred on public and unsecured Wi-Fi networks.
Weak encryption:
Most of the Wi-Fi hotspots Avast tested were protected by some form of encryption. However, most of these methods were weak and easy to hack. Using WEP encryption can be just as dangerous as not using a password at all, since users often feel more secure when entering personal information, but their data remains accessible.
San Francisco and Berlin have the lowest percentage of access points with weak encryption, while more than half of the access points in London and New York, and nearly three-quarters of the access points in Asia, are vulnerable to attacks.
1) Seoul: 70.1%
2) Taipei: 70%
3) Hong Kong: 68.5%
4) London: 54.5%
5) New York: 54.4%
6) Chicago: 45.9%
7) Barcelona: 39.5%
8) Berlin: 35.1%
9) San Francisco: 30.1%
