Live data from Hacker News

How I cracked my neighbor's WiFi password without breaking a sweat

arstechnica.com

141–144 of 144 posts

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#141
post #68

When addressing various physical home security issues, I came to the realization that if a trained team of attackers equipped with body armor and night vision broke into my home, the issue escalated beyond anything I could sensibly prepare for. The article reminded me of that. If someone attacks my home wifi with network sniffing hardware, sophisticated password guessing tools, hours of planning and execution, etc th…

A physical assault carries a high chance of being noticed, and unless carried out by law enforcement, a significant chance of being punished with jail time. So it's not something that has a high chance of happening. Additionally, it's hard to defend against, and you definitely don't want to defend against a SWAT team. Whereas a bored teenage neighbor could attack your wireless network with a very small chance of bein…

a bored teenage neighbor could attack your wireless network

He would have to be very bored indeed. Singling out my home to spend considerable time at an inconvenient in-range location to crack passwords to access ... what, exactly? view pictures of my toddlers? copy my slightly deranged music collection? If he's looking for free network access, he can go down the street and get it from McDonalds or Starbucks or wherever while sitting in a comfortable chair sipping a soda.

I realize a bored teen is different from a SWAT team. Both, however, would need unusual motivation to turn their talents on my abode.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#142
post #140

Earlier quoted context omitted.

I think you're missing my key point: you have to compare two different risks, based on observation. The first risk is the risk of continuing to use a compromised password. The second risk is the risk of users introducing weaker passwords because they continually change them. We can use our reasoning to come up with a decent probability for the first risk. We cannot do so for the second risk, since it depends on how p…

I think I see your point but you have to admit you haven't really established a foundation for your argument. You seem to feel (and I may be wrong of course) that one person selecting a fairly secure pass phrase once would be much more secure at any single point in time rather than a hap-hazard, dictionary based pass phrase that in comparison would be likely trivial to compromise at that same point of time. If that i…

You've almost got it, but you've missed the main subtlety: I'm asking a question, not making a statement. I'm not advocating what we should do. I'm stating that what we should do is actually unknown because we don't have all of the information. Specifically, we don't know human behavior when it comes to rotating passwords. If it turns out that people actually choose good passwords under a rotating password policy, then we should keep the rotating password policy.

My only prescription is to say, instead of telling everyone "this is how you should behave" in order to achieve the best security, we should design our security policies based on how people actually behave. My assertion here is that if we do this, we will end up with better actual security than if we came up with a policy that, on paper, is better, but is not well implemented by people in the wild.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#143
post #126

Earlier quoted context omitted.

My understanding is that when people build password-cracking dictionaries, they include common permutations in the script. That is, for the dictionary word "dolphin", the script puts in "Dolphin" and "d0lph1n" and so forth. I'd be very surprised if someone building a table based on common quotations didn't do the same thing. I mean, how many memorable punctuation-mangling strategies are there on a common phrase anywa…

>I mean, how many memorable punctuation-mangling strategies are there on a common phrase anyway? How do you define common? The person has the entirety of literature, movies, music, etc to draw from. They might select any given fragment of a work, and the attacker has no way of knowing where the fragment begins or ends. Is a purely random key strictly more secure? Sure. But my goal isn't to get the purest possible lev…

They might select any given fragment of a work

Just like someone told to select an arbitrary password might select any sequence of characters. They might theoretically select anything, but most of them will choose something like 'password'.

So with your users. Star Trek fans are going to choose "makeitso". And a database of famous quotes will catch them.

Re: How I cracked my neighbor's WiFi password without breaking a sweat

#144
post #143

Earlier quoted context omitted.

>I mean, how many memorable punctuation-mangling strategies are there on a common phrase anyway? How do you define common? The person has the entirety of literature, movies, music, etc to draw from. They might select any given fragment of a work, and the attacker has no way of knowing where the fragment begins or ends. Is a purely random key strictly more secure? Sure. But my goal isn't to get the purest possible lev…

They might select any given fragment of a work Just like someone told to select an arbitrary password might select any sequence of characters. They might theoretically select anything, but most of them will choose something like 'password'. So with your users. Star Trek fans are going to choose "makeitso". And a database of famous quotes will catch them.

What I'm really getting at, though, is that I think playing cat and mouse with professional hackers is a losing game. You shouldn't spend a few seconds trying to come up with something that they won't think of when it's their entire vocation. You're just not that creative, and too many people think alike.

Just roll dice. That way your choice is provably random.

Post reply on HN