Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New attack cracks common Wi-Fi encryption in a minute
Network World ^ | 27 August 2009 | Robert McMillan

Posted on 08/28/2009 10:58:25 AM PDT by ShadowAce

Computer scientists in Japan say they've developed a way to break the WPA encryption system used in wireless routers in about one minute.

The attack gives hackers a way to read encrypted traffic sent between computers and certain types of routers that use the WPA (Wi-Fi Protected Access) encryption system. The attack was developed by Toshihiro Ohigashi of Hiroshima University and Masakatu Morii of Kobe University, who plan to discuss further details at a technical conference set for Sept. 25 in Hiroshima.

Last November, security researchers first showed how WPA could be broken, but the Japanese researchers have taken the attack to a new level, according to Dragos Ruiu, organizer of the PacSec security conference where the first WPA hack was demonstrated. "They took this stuff which was fairly theoretical and they've made it much more practical," he said.

They Japanese researchers discuss their attack in a paper presented at the Joint Workshop on Information Security, held in Kaohsiung, Taiwan earlier this month.

The earlier attack, developed by researchers Martin Beck and Erik Tews, worked on a smaller range of WPA devices and took between 12 and 15 minutes to work. Both attacks work only on WPA systems that use the Temporal Key Integrity Protocol (TKIP) algorithm. They do not work on newer WPA 2 devices or on WPA systems that use the stronger Advanced Encryption Standard (AES) algorithm.

The encryption systems used by wireless routers have a long history of security problems. The Wired Equivalent Privacy (WEP) system, introduced in 1997, was cracked just a few years later and is now considered to be completely insecure by security experts.

WPA with TKIP "was developed as kind of an interim encryption method as Wi-Fi security was evolving several years ago," said Kelly Davis-Felner, marketing director with the Wi-Fi Alliance, the industry group that certifies Wi-Fi devices. People should now use WPA 2, she said.

Wi-Fi-certified products have had to support WPA 2 since March 2006. "There's certainly a decent amount of WPA with TKIP out in the installed base today, but a better alternative has been out for a long time," Davis-Felner said.

Enterprise Wi-Fi networks typically include security software that would detect the type of man-in-the-middle attack described by the Japanese researchers, said Robert Graham, CEO of Errata Security. But the development of the first really practical attack against WPA should give people a reason to dump WPA with TKIP, he said. "It's not as bad as WEP, but it's also certainly bad."

Users can change from TKIP to AES encryption using the administrative interface on many WPA routers.


TOPICS: Computers/Internet
KEYWORDS: cyberattacks; cybersecurity; encryption; wireless; wpa
Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last

1 posted on 08/28/2009 10:58:26 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

2 posted on 08/28/2009 10:58:41 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Pingaling


3 posted on 08/28/2009 11:01:09 AM PDT by Danae (- Conservative does not equal Republican. Conservative does not compromise.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Mac address filtering is your friend. :)

4 posted on 08/28/2009 11:03:11 AM PDT by TSgt (I long for Norman Rockwell's America.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

So much for security on my Wi-Fi at home. Guess it’s back to hardwiring for now.


5 posted on 08/28/2009 11:03:34 AM PDT by OCCASparky (Steely-Eyed Killer of the Deep)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

6 posted on 08/28/2009 11:03:35 AM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

My home office wireless router was installed by Verizon, and it has a WEP key printed right on the side of the unit. Should I be worried? Freeper experts, any feedback on how an average user can protect their wireless networks?


7 posted on 08/28/2009 11:03:36 AM PDT by Califelephant
[ Post Reply | Private Reply | To 1 | View Replies]

To: MikeWUSAF

If somebody wants to hack something bad enough and they have the time to do it, they will always find a way.


8 posted on 08/28/2009 11:04:34 AM PDT by dfwgator
[ Post Reply | Private Reply | To 4 | View Replies]

To: MikeWUSAF

MAC filtering will prevent connection to and use of the WAP. But will it prevent the interception and decryption of wireless traffic?


9 posted on 08/28/2009 11:05:08 AM PDT by Hazwaste (Liberals love the average American the same way that foxes love the average chicken.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ShadowAce

Good. WPA2 is safe......for now.


10 posted on 08/28/2009 11:05:51 AM PDT by Red in Blue PA (If guns cause crime, then all of mine are defective!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Califelephant

WEP is the weakest of any security. Should be at least WPA.....preferably WPA2 if your router supports it.


11 posted on 08/28/2009 11:06:37 AM PDT by Red in Blue PA (If guns cause crime, then all of mine are defective!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Califelephant

I’m in I.T., but not an expert in wireless security. I use MAC filtering, WEP, and non-broadcasted SSID. Not perfect, but it’s the best that my WAP provides.

Don’t forget to change the default login and password for the WAP admin account.


12 posted on 08/28/2009 11:09:06 AM PDT by Hazwaste (Liberals love the average American the same way that foxes love the average chicken.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ShadowAce

Pinging you Ski, just in case you’re not on the tech list. This is scary.


13 posted on 08/28/2009 11:09:35 AM PDT by Miss Behave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Petronski

Pinging you Ski, just in case you’re not on the tech list. This is scary.


14 posted on 08/28/2009 11:10:29 AM PDT by Miss Behave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Califelephant

You may want to cover it up with a piece of tape.

The main reason to have your wireless network password protected is to keep your neighbors from using your network. Not so much to keep them from getting into your data, but to keep them from stealing your bandwidth (a neighbor kid downloading music and video can impact your speed.)

There are people that drive around looking for home networks to hack into to steal data, but there are so many unsecured (no password) home networks out there that they don’t need to hack into one with a password.

Unless one of your neighbors (or their kids) saw the password and wrote it down you are probably OK.


15 posted on 08/28/2009 11:11:42 AM PDT by Brookhaven (http://theconservativehand.blogspot.com/)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ShadowAce

WPA 2 is pretty well established by now, having been part of the standard with which compliance is required since 2006 in order for the WiFi logo to be used on a product. If you have a pre-2006 router, maybe it’s time to upgrade. First, check to see if a firmware update is available which might provide WPA 2. Else, get a new router. They’re cheap and there have been speed, security and functionality improvements. My personal recommendation, after a lot of research, has been the D-Link DIR-655, for its speed and superb firewall.


16 posted on 08/28/2009 11:16:42 AM PDT by RightOnTheLeftCoast (Cheney/Palin 2012!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MikeWUSAF

yes


17 posted on 08/28/2009 11:22:00 AM PDT by mowowie
[ Post Reply | Private Reply | To 4 | View Replies]

To: MikeWUSAF; Hazwaste; dfwgator

MACs can be spoofed quite easily


18 posted on 08/28/2009 11:22:10 AM PDT by rabscuttle385 (May God save the American Republic.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Califelephant
"My home office wireless router was installed by Verizon, and it has a WEP key printed right on the side of the unit. Should I be worried?"

Much depends on what the password is, and what it pertains to. It may be a login password for the Verizon PPoE (or whatever) network, not the WiFi. If it's for the WiFi, then there are two issues: (1) Who has seen the password, and (2) Is the password a proper gobbledegook password, or is it some silly insecure default thing like "ADMIN" or "LINKSYS".

If it is indeed for your WiFi link, why not just change the password to be sure? It's generally not difficult, though you'll have to update the login for any computer or other device (printer, iPhone...) that accesses your WiFi network.
19 posted on 08/28/2009 11:22:38 AM PDT by RightOnTheLeftCoast (Cheney/Palin 2012!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Califelephant

Go to Staples and buy a new WPA2 wireless router for 30 bucks.


20 posted on 08/28/2009 11:23:31 AM PDT by mowowie
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson