Live data from Hacker News

How I cracked my neighbor's WiFi password without breaking a sweat

arstechnica.com

41–50 of 144 posts

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#41

Earlier quoted context omitted.

Anecdotally, most people I know without secure WIFI passwords pick things like: - Their address (sometimes with numerals spelled out) - Their last name - Their child's name - single (common) dictionary word - single (common) dictionary word + one or two digits.

for about 80% of protected home networks i’ve accessed the password ends up being someone in the home’s phone number.. not sure if it’s just because it’s often the only 8+ character string of numbers people readily have memorized or if it’s just lazy isp’s that set it that way (and lazy owners who never change it afterwards)..?

It's the ISPs. Every time I move the tech resets my password to my home phone number.

I'm sure it cuts down their support, but it usually means brute forcing only need worry about the last four digits.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#42
post #38
post #34

Earlier quoted context omitted.

I want to add to mock's point - I will trust you more if I could download it from your site than from download.com. It has become such a dump that I actively avoid visiting it. Why delegate the user experience of downloading your products to someone whose interests don't align with yours?

OK. Point taken. We have done some A/B tests and see that download rate is the same as from our website. The benefit of redirecting to download.com is that with increased rankings we get more users who visit download.com. I know these issues you said and I saw the articles on HN before. However, you can tell download.com to stop injecting offers into the installer which we did and there are no issues.

Provide an S3 link if you are worried about bandwidth, where the name of your company is in the URL (ie, bucket name).

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#43
post #2

You know, at the cost of $2,500 per year, (although I can't actually find where to purchase the software) you'd probably be better to just YouTube some kid's backtrack tutorial.

What software are you talking about? CloudCracker?

Using the Silica wireless hacking tool sold by penetration-testing software provider Immunity for $2,500 a year, I had no trouble capturing a handshake established between a Netgear WGR617 wireless router and my MacBook Pro.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#44
A couple of naive questions about the design of the security system:

1. Why is it possible to do the password tests remotely? Why would the key on the router be allowed to be transmitted? Even a 6 character password should be safe if you don't allow multiple tries.

2. Why isn't the handshake protocol encrypted?

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#45
post #33

No doubt, this neighbor should have changed his password long ago, but there is a lot to admire about his security hygiene nonetheless. I think it's taken too much for granted that one should change passwords on a regular basis. If we assume that changing passwords more frequently means that we are more likely to use more rememberable - and, thus, more guessable - passwords, then perhaps this is not a fluke. Perhaps…

One should change passwords on an irregular basis (a regular basis is weaker protection than an irregular basis). This is just an additional layer of security, not a perfection. If the password has ever been compromised, a password change policy removes the key from bad hands. Discovered passwords are not always immediately used; in many situations, they are stored for later use, perhaps even sold/traded.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#48
I would place good money that most AT&T wireless routers (SSID = 2WIREXXX) are using the same 10-digit password that is printed on the sticker on the unit. Yes, it's more secure than the old days of a default password being "default" or "admin" but not so great if 10-digit passcodes are easily broken.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#49
post #13

Don't really want to hijack this thread so feel free to downvote me if you feel its not appropriate. We launched a product that protects you from these attacks - more discussion here - http://news.ycombinator.com/item?id=4444478

Correct me if I am wrong but the solution proposed is to use a free vpn under your control, my question is why do users have to trust you with their data?

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#50

Earlier quoted context omitted.

What software are you talking about? CloudCracker?

Using the Silica wireless hacking tool sold by penetration-testing software provider Immunity for $2,500 a year, I had no trouble capturing a handshake established between a Netgear WGR617 wireless router and my MacBook Pro.

Using the aircrack-ng suite you can do it for free.
Post reply on HN