Live data from Hacker News

WPA2 wireless security cracked

sciencespot.co.uk

21–30 of 30 posts

Re: WPA2 wireless security cracked

#21
post #18
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

I'm confused. They downloaded aircrack-ng and wrote a paper about it? How is this news?

As some others pointed out, the title is very alarming and misleading. "cracked", to us, means "has a flaw, i.e. broken." If it were true, it would be very big news.

Fortunately, this is far from the case.

Re: WPA2 wireless security cracked

#22
post #18
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

I'm confused. They downloaded aircrack-ng and wrote a paper about it? How is this news?

Ive seen similar "papers" on BCompSc degrees.

Re: WPA2 wireless security cracked

#23
What I normally tell people to do when setting up a WiFi access point...

  1. Set up a PSK of at least 30 random lower case letters.
  2. Switch off WPS.
(I used to tell people 20 random characters using mixed case letters, digits and symbols. Using lower case letters only is easier to type on a phone.)

Is a WiFi access point set up this way vulnerable to this new attack?

So many times I've been warned that "WPA2 has been cracked" but when reading, it turns out that someone has just built a system to perform brute force dictionary attacks.

Re: WPA2 wireless security cracked

#24
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

Easy way of driving traffic to a website; disappointing that it's just a long paper on aircrack.

Re: WPA2 wireless security cracked

#25
post #18
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

I'm confused. They downloaded aircrack-ng and wrote a paper about it? How is this news?

I'd assume that if this were an actual break-through result it would be published in a reputable academic conference and not a random journal..

Re: WPA2 wireless security cracked

#26
post #18
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

I'm confused. They downloaded aircrack-ng and wrote a paper about it? How is this news?

Not that alone. They show that that is "practical", which may be semi-new, but the main trick:

" it is the de-authentication step in the wireless setup that represents a much more accessible entry point for an intruder with the appropriate hacking tools. As part of their purported security protocols routers using WPA2 must reconnect and re-authenticate devices periodically and share a new key each time. The team points out that the de-authentication step essentially leaves a backdoor unlocked albeit temporarily."

Re: WPA2 wireless security cracked

#27
post #26
post #18

Earlier quoted context omitted.

I'm confused. They downloaded aircrack-ng and wrote a paper about it? How is this news?

Not that alone. They show that that is "practical", which may be semi-new, but the main trick: " it is the de-authentication step in the wireless setup that represents a much more accessible entry point for an intruder with the appropriate hacking tools. As part of their purported security protocols routers using WPA2 must reconnect and re-authenticate devices periodically and share a new key each time. The team poin…

I take offence to their statement "leaves a backdoor unlocked". It's no such thing. The de-auth step merely saves you the time of having to wait for the client/ap to renegotiate on their own. Even if your de-auth step is successful, you still have to conduct a brute force against the handshake you captured. Nothing, at any time, is unlocked.

Re: WPA2 wireless security cracked

#28
post #23

What I normally tell people to do when setting up a WiFi access point... 1. Set up a PSK of at least 30 random lower case letters. 2. Switch off WPS. (I used to tell people 20 random characters using mixed case letters, digits and symbols. Using lower case letters only is easier to type on a phone.) Is a WiFi access point set up this way vulnerable to this new attack? So many times I've been warned that "WPA2 has bee…

It appears that it isn't (vulnerable).

Re: WPA2 wireless security cracked

#29
post #2

This isn't clear about "how" cracked it is. If it is going to take an attacker a year of CPU time, I'm not going to be too bothered. If it could conceivably run in a few minutes on a mobile phone then it's much more of a problem.

Just to put this in some context, if we're talking about 1 core-year (I hope this unit becomes popular) what it really means is just over 500$ will give you the same result in one year / possible parallelisation. If the process ends with brute-forcing independent branches to look for an answer, that may be effectively an hour or less for each case. Not much of protection really...

That's true, but it means someone has to have a $500 incentive. Nobody driving around looking to break into networks opportunistically is going to drop $500 per network.

Re: WPA2 wireless security cracked

#30
post #14

Further technical details and quotes from the paper are available at: http://www.securityweek.com/researchers-outline-how-crack-wp... The methodology appears to be as naive as a brute force attack against the Pre-Shared Key (PSK): "At the beginning, the area was scanned-sniffed with ‘Airodump’ and then a deauthentication attack was made with ‘Aireplay’," according to the paper. "Through that, an instance of the PSK w…

Exactly. We've known that WPA2-PSK was vulnerable to dictionary attacks since before it was even popular. Also, a ~700k password dictionary is not what I would describe as "very big". This still won't crack my wireless, nor many of the wireless networks I've used that have relatively easily predictable passwords.
Post reply on HN