WPA2 with AES now also vulnerable to attacks

Valerion

Expert Member
Joined
Oct 13, 2003
Messages
1,967
Reaction score
36
Location
::1
So far WEP and WPA-TKIP have been slated as insecure. Now WPA2-AES has also shown to have issues, due to the way the standard is written.

http://www.networkworld.com/newsletters/wireless/2010/072610wireless1.html

AES is not broken, and you still need to be an authorized user on the network, so it doesn't allow an outside attack vector. However, it does allow you to decrypt the communications of other wireless devices on the same AP, which may contain sensitive traffic.

And with nothing on the horizon to update this, there's no viable upgrade path for large corporates where this may be an issue.
 
Running encryption inside the wireless session will work, as that can't be broken. However, it puts extra load on the end user devices, especially embedded devices. But if you want to be safe from snooping, it's the only option right now. More fun for IT support to get a user to work after the VPN tunnel doesn't properly establish itself.

This does remove the "plug & play" encryption that was supposed to be part of the wireless standard.
 
Top
Sign up to the MyBroadband newsletter
X