Grab an Italian masterpiece for less

Computer users have been warned of the dangers of using wi-fi hotspots after it emerged that cyber-criminals are targeting the networks in café chains including Starbucks.
Times Online has uncovered evidence that criminals are using a technique known as an 'evil twin attack', where victims think that they are logging on to the genuine network in a café but are in fact being diverted to a 'rogue' connection.
Once logged on to the twin network, the victim's every keystroke is captured by the fraudster, who controls the connection from a nearby laptop and uses it to extract information for the purpose of committing identity fraud.
In a chatroom used to discuss the technique, also known as a 'man in the middle' attack, Times Online saw information changing hands about how security at wi-fi hotspots – of which there are now more than 10,000 in the UK – can be bypassed.
During one exchange in a forum entitled 'T-Mobile or Starbucks hotspot', a user named aarona567 asks: "will a man in the middle type attack prove effective? Any input/suggestions greatly appreciated?"
"It's easy," a poster called 'itseme' replies, before giving details about how the fake network should be set up. "Works very well," he continues. "The only problem is,that its very slow ~3-4 Kb/s...."
Another participant, called 'baalpeteor', says: "I am now able to tunnel my way around public hotspot logins...It works GREAT. The dns method now seems to work pass starbucks login."
From the language used, the criminals appear to be US-based, though at one point one says: "i doubt that the architecture of the tmobile hotspot networks in europe varies from the technologies deployed here in the US."
T-Mobile, which runs a network of 2,000 hotspots, including those in Starbucks cafés, said it was aware of the technique, but was yet to have any incident reported in the UK. It advised customers to update their virus protection software and "ensure they were connected to a valid, certified website."
Security experts said, however, that safeguards such as digital certificates could not always guarantee protection, and that users would continue to be fooled by imitation sites, which were increasingly sophisticated.
"This is the most pressing current security threat that remains to be addressed," Paul Cronin, technical director at Pentura, which test wireless security, said. "People are spending all this money on firewalls and yet their machines with wireless cards immediately go searching for the nearest network."
"It's shocking how easy it is to set up a 'soft access point' and get devices to connect to it," he added
A police source said that evil twin attacks were 'not uncommon', but that they mostly went undiscovered. The problem was being "talked about", according to a spokeswoman for the Metropolitan Police, but she said there had been no reports of any crimes yet.
In a speech about wireless security last week, Phil Cracknell, a technology officer at Deloitte's, said: "This type of attack where the operator sits around and harvests details while you are connected to the hotspot is destined to become the new type of phishing.
"All you need to clone the Starbucks hotspot is a laptop, and the software can be configured within two hours," Mr Cracknell told an audience at InfoSec, in London.
Paul Vlissidis, technical director at NCC, another security firm, said: "It's a more costly scam to run, but we'll certainly see it happen as the number of wireless networks continues to grow."
There are now more than 10,000 hotspots across the UK, and blanket wi-fi coverage is now offered in large portions of Manchester, Edinburgh and, as of last week, the City of London.
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
1998
£47,955
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
Check your free Experian credit report before applying
Car Insurance
to £60K + bonus (OTE £90k)
Lord Search & Selection
Location Flexible
If interested, call Oliver Luscombe on 0207 212 3065
PwC
£85k
CPA
Highly Competitve
Specsavers
Whiteley, near Southampton
Moments from Battersea Park.
For sale with Winkworth
Find out about shared ownership.
See your free Experian credit report beforehand
Book now & save over £100pp.
11 cool resorts, lowest prices... Early Booking offers 15 Nov.
20% off selected Azores holidays taken in October with Sunvil Discovery
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.