WPA Wi-Fi security cracked

this is nothing new, guys like sensepost have done this months ago.
 
Looks like encrypted vpn's over wi-fi are probably the current safest bets.
Damn .. there goes all the speed advancements.

@GaryVDH, mac filtering is where the wi-fi router only "speaks" to devices identified by a particular MAC identification code. You tell the router that it is only allowed to talk to a list of mac's. The problem is that, I can make my wi-fi card have any mac number I wish, so .. although it adds a level of safety, it's not perfect either. And .. the hassle of updating the allowed mac addresses every time a visitor needs access is a pain, and then remembering to revoke their access when they leave is even more painful.
 
Last edited:
what is that mac filtering thingy? doesn't that help?

Enabling MAC filtering is simply another level of security but it's nothing more than a nuisance to hackers to be honest. One can easily spoof a MAC address of a wireless adapter (after determining your legitimate MAC address, the hacker uses your MAC address as if it is his own, the router gives access regardless since the MAC address appears on the list).

Anyway, as far as WPA security goes... this is quite a big blow! WEP has been proven to be non-secure a long time ago so just about everybody has switched to WPA, me included. The hack referred to in the article does mention that WPA2 is still secure but a LOT of routers out there only support WPA, not WPA2 (like my Netgear!). So that means after the actual hack is published, time to get a new router that supports WPA2. My Intel PROSet 3945ABG wireless adapter seems to support it already.

The chances of someone eventually using the WPA crack to compromise your wireless connection if you're a home user is rather slim but it is definitely a real risk to businesses and airport type hotspots where hackers can "intrude" on a bigger scale.

In the end, I guess the only way to secure a wireless connection will be to use a VPN tunnel.
 
In the end, I guess the only way to secure a wireless connection will be to use a VPN tunnel.

Seems to be leaning that way... you can also use nonstandard ports for the VPN connection so the attacker will waste more time.

Bleh.

Safest is to switch the wireless router off when not in use...
 
Well, thinking about it a bit, if you turn off WEP/WPA encryption and just use the encrypted VPN type access, the speed should be back to max.

This news must make the developers of WEP and WPA and WPA2 want to cry.
 
woohooo hooo, its all beeen doooooooooonneeeeee befoooooore.
I have every single WEP and key and 90% of the dataphrases for WPA routers that are within range of my office. And when I get over my laziness and actually build the packet injection drivers for my linksys router then I should have another 60 more.
The point is this, its not very hard to crack Wireless security, so as Stokey recommends - an encrypted local VPN is another added level of security.

All quite annoying isnt it?
 
what is that mac filtering thingy? doesn't that help?

MAC filtering is useless if you have access to the MAC's allowed... since spoofing a MAC is really not hard. It's as easy as running an application and selecting a MAC address and clicking APPLY.

WPA was never to be a tough cookie to crack with the technology and computing abilities we have today. It's simply not strong enough.
 
I am using WPA2-AES and since they mentioned WPA-TKIP I am guessing that we are secure for now? ^$%#* sake can't they get this right????
 
wpa pfffffffft wpa wep woop soup coffee please
 
I am using WPA2-AES and since they mentioned WPA-TKIP I am guessing that we are secure for now? ^$%#* sake can't they get this right????

yes pkid. you're fine with AES. For now. :)

We were on WPA-AES. After reading this article I switched our office APN to WPA2-AES. I am still using the full 63 characters with special characters.

I can't even connect to this APN in Linux because the characters for the password don't show up right.
 
Top
Sign up to the MyBroadband newsletter
X