Live data from Hacker News

WPA2 wireless security cracked

sciencespot.co.uk

1–10 of 30 posts

Re: WPA2 wireless security cracked

#2
This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

Re: WPA2 wireless security cracked

#3
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

(the mobile phone could talk to the cloud but a year is still expensive)

i wonder how quickly you could solve that problem, cracking the wpa2 key, if you had $$$ resources to scale up. could it be usable? would make for a great android app :) i'd buy it!

Re: WPA2 wireless security cracked

#4
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

Have you read the actual paper or just the news article? I ask because I am thinking of buying the paper, but if it isn't any good then I won't.

Re: WPA2 wireless security cracked

#7
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

However, it is the de-authentication step in the wireless setup that represents a much more accessible entry point for an intruder with the appropriate hacking tools. As part of their purported security protocols routers using WPA2 must reconnect and re-authenticate devices periodically and share a new key each time. The team points out that the de-authentication step essentially leaves a backdoor unlocked albeit temporarily. Temporarily is long enough for a fast-wireless scanner and a determined intruder. They also point out that while restricting network access to specific devices with a given identifier, their media access control address (MAC address), these can be spoofed.

That doesn't sound like something that would take a year of CPU time, but since no one seems to have actually read and analyzed the paper yet, who knows.

Re: WPA2 wireless security cracked

#8
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

That's right, not enough information. But, however your attitude might be the right one, I'm a little bothered already, because I didn't expect that to happen so soon.

In fact, even the idea of "year of CPU time" doesn't sooth me much, because while most of your traffic might be "quickly-expiring" it's definitely not true for all of your traffic, and what's possible to do with a year of CPU time will be possible to do comparatively cheap very soon. And I guess we all remember stuff like Google collecting some wi-fi traffic anyway.

So, it sounds somewhat scary to me. We don't even have anything better than WPA2 now, do we?

Re: WPA2 wireless security cracked

#9
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

Have you read the actual paper or just the news article? I ask because I am thinking of buying the paper, but if it isn't any good then I won't.

I've requested the paper through my school's inter-library loan, I'll know in about 4 hours if the librarian can get me a copy. If you send me an email and I get a copy I can forward it on to you. (Though it wouldn't surprise me if someone else 'liberates' the paper for everyone before then.)
Post reply on HN