Live data from Hacker News

Researcher cracks Wi-Fi passwords with Amazon cloud

theregister.co.uk

11–14 of 14 posts

Re: Researcher cracks Wi-Fi passwords with Amazon cloud

#11
post #2

Not judging but I love how the term "researcher" has been adopted as a way to guise whitehat activities. I wish I could use that to get out of speeding tickets "Officer I am just a researcher and trying to determine if the 55mph speed limit sign is really the law and if it's possible to break it"

Meh, as long as you're only picking your own locks, who cares? (And yes, there are people who pick locks for fun.)

Yup, they found the kyrptonite lock bic pen loophole and made a whole bunch of bikes more safe today. But they also educated a whole bunch of dumb thieves who didn't know in the first place (the smart thieves knew but they are far more rare). So it's always a mixed bag.

Still, in the end I'd rather know about security problems even if it means the "bad guys" get told at the same time, otherwise you just have security theater.

Re: Researcher cracks Wi-Fi passwords with Amazon cloud

#12
post #8

Wasn't this done months ago? (/me looks for the article) Well, this was more generic: http://news.ycombinator.com/item?id=1907513 Oh, it was over a year ago: http://it.slashdot.org/story/09/12/07/2322235/WPA-PSK-Cracki...

In the nicest way possible, this is probably just an ad piece for his service ( http://www.wpacracker.com/ ) It has been possible to brute force WPA-PSK for ages, you just needed a lot of computing power. It appears he did this with a dictionary attack, not bruteforce (see: http://www.h-online.com/security/news/item/Cracking-WPA-keys... ) and, so, it is no wonder it was fast - but that is limited. EC2 is an option, s…

>Still, nothing you couldn't do on a decently fast "local" machine for cheaper

The fun thing is that you can now do it in the field. You could potentially grab the hashes with a netbook, then crouch in your hiding place behind the bins at Enemy HQ for six minutes while EC2 does the cracking, then go straight into the network, without having to risk sneaking out and back in again. Past the guards.

Dunno what espionage-based fantasy world I'm in today. I don't even play video games! However people really do this stuff. And now we can all have a go! Hooray! The kind of people who do these things dont generally have to worry about expenses though...

Re: Researcher cracks Wi-Fi passwords with Amazon cloud

#13
post #8

Wasn't this done months ago? (/me looks for the article) Well, this was more generic: http://news.ycombinator.com/item?id=1907513 Oh, it was over a year ago: http://it.slashdot.org/story/09/12/07/2322235/WPA-PSK-Cracki...

In the nicest way possible, this is probably just an ad piece for his service ( http://www.wpacracker.com/ ) It has been possible to brute force WPA-PSK for ages, you just needed a lot of computing power. It appears he did this with a dictionary attack, not bruteforce (see: http://www.h-online.com/security/news/item/Cracking-WPA-keys... ) and, so, it is no wonder it was fast - but that is limited. EC2 is an option, s…

wpacracker.com is run by Moxie Marlinspike, not this Thomas Roth. (and no, Thomas Roth is not his real name). Furthermore I can't find any link between this (or the others) news article and Moxie's wpacracker.com, and I can't figure out why he would only be presenting wpacracker at blackhat now.

Re: Researcher cracks Wi-Fi passwords with Amazon cloud

#14
post #8

Earlier quoted context omitted.

In the nicest way possible, this is probably just an ad piece for his service ( http://www.wpacracker.com/ ) It has been possible to brute force WPA-PSK for ages, you just needed a lot of computing power. It appears he did this with a dictionary attack, not bruteforce (see: http://www.h-online.com/security/news/item/Cracking-WPA-keys... ) and, so, it is no wonder it was fast - but that is limited. EC2 is an option, s…

wpacracker.com is run by Moxie Marlinspike, not this Thomas Roth. (and no, Thomas Roth is not his real name). Furthermore I can't find any link between this (or the others) news article and Moxie's wpacracker.com, and I can't figure out why he would only be presenting wpacracker at blackhat now.

Ah sorry. I got the impression there was a link die to how it was presented.
Post reply on HN