Skip to main content
  1. Home
  2. Computing
  3. News

Wi-Fi vulnerability could allow attackers to steal your data on unencrypted sites

Add as a preferred source on Google
Casezy/Getty Images

Computer scientists at the University of California, Riverside, have discovered a security flaw that affects all Wi-Fi routers. Hackers could exploit the weakness in the transmission control protocol (TCP) and perform a web cache poisoning attack to steal passwords, login information, and other private data. Unfortunately, a fix isn’t possible, as the vulnerability stems from a 20-year-old design based on TCP and Wi-Fi. To prevent hackers from using the exploit, researchers recommend that manufacturers build routers that operate on different frequencies for transmitting and receiving data.

Fortunately, this attack technique won’t work with encrypted sites that use HTTPS and HSTS. Users on Ethernet connections are similarly not affected. Given that the attack won’t work on encrypted sites, most users who browse the internet on a modern browser shouldn’t be affected. Many browsers, including Google’s Chrome, already warn users if they visit an unencrypted site.

Recommended Videos

TCP works by breaking down data into manageable chunks, called packets, for computers to communicate. The data packets begin with a random first number, but the subsequent numbers in the sequence will predictably increase, and hackers can guess the next number to intercept communication between the sending and receiving computers. Given that there are approximately 4 billion sequence numbers, it is difficult for hackers to make a correct guess.

“But if the attacker can figure out which number triggers a response from the recipient, they can figure out the rough range of the correct number and send a malicious payload pretending that it comes from the original sender,” the researchers wrote in a blog post detailing the attack. “When your computer reassembles the packets, you’ll see whatever the attacker wants.”

When the victim visits a website that’s controlled by the hacker — who can be connected remotely using a different Wi-Fi network — the site will run a JavaScript that creates a TCP connection to a banking website. The exploit will work if the victim stays on the site for as little as 1 minute. Hackers can display pirated movies, for example, in an attempt to lure the victim to stay on the site for longer. While the victim is on the site, the hacker can guess the sequence number for the banking packet and inject a malicious copy of the bank webpage into the victim’s cache to steal passwords and login information.

This web cache poisoning tactic ensures that the victim will always see the malicious site whenever they try to visit the banking website in the future, and the malicious copy of the site can sit in the browser cache for deacdes or until the victim clears the cache.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
I didn’t think fake shopping could trick my brain until I tried the viral dopamine websites
On these fake shopping and delivery sites, nothing ever ships or costs a cent, yet the dopamine hit still felt real.
fake-shopping-on-viral-dopamine-websites

I spent some time in the internet's fakest mall, filling a shopping cart with things I could not buy, hunting for discounts on products that do not exist, and checking out three separate times for a grand total of $0.00. Then I placed a fake food order and smoked a cigarette I could not taste, with strangers I will never meet, on a rooftop that does not exist either. My bank balance never changed, but my brain, annoyingly, did.

When I first heard about South Korea's growing "dopamine sites," I assumed they were another internet oddity I would poke around for five minutes and forget by lunch. Instead, I found a surprisingly clever idea hiding beneath the absurdity. You can browse endless imaginary products, add everything to your cart, and complete a purchase that never actually exists. These websites aren't trying to sell you anything. They're trying to recreate the feeling of shopping while removing the part that empties your wallet.

Read more
LG wants to build humanoid robots, and NVIDIA is giving it the brains
This isn't just another robot teaser. LG and NVIDIA just outlined actual hardware.
Robot, Appliance, Device

With time, more and more legacy hardware companies seem to be racing to bolt a humanoid robot onto their roadmap. The latest entrant is LG, joining the race with tentative timelines.

The company's bipedal humanoid, built on Nvidia's robotics stack, is planned for early 2027, and it's backed by a broader push into AI factories and self-driving vehicle platforms.

Read more
Googlebook may use older Snapdragon chips to build more affordable laptops
Snapdragon X Plus and X Elite models could be in development
Googlebook

Google has already confirmed that Googlebook will support more than one chipmaker, and a new leak may have revealed the first Snapdragon models in development.

New code references uncovered by GbookHub reportedly link two Googlebook designs, codenamed Annite and Pic, to Qualcomm’s Snapdragon X Plus X1P-42-100 processor. Both are also said to be tied to a board platform called Mica.

Read more