NetStumbler.org Forums

Go Back   NetStumbler.org Forums > WiFi Forums > News
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 08-28-2009   #1 (permalink)
Starpoint
Pr0nStumbler Expert Level
 
Starpoint's Avatar
 
Join Date: Apr 2003
Location: Houston
Posts: 2,536
WPA useless now?

Saw this blurb on TheRegister WPA gone in 60 seconds

I use wpa 2 on mine atm
__________________
Against the run of the mill, static as it seems

We break the surface tension with our wild kinetic dreams
Curves and lines -- of grand designs...


Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management

My mind is like a Steel trap - Rusty and Illegal in most states
Starpoint is offline   Reply With Quote
Old 08-28-2009   #2 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,361
Quote:
Originally Posted by Starpoint View Post
Saw this blurb on TheRegister WPA gone in 60 seconds

I use wpa 2 on mine atm
<sigh> Not Really. It's WPA-TKIP only. WPA2 (aka WPA-AES) isn't affected, nor is WPA-RADIUS.

There has been a lot of hype over this particular attack in the last few days, and I want people to understand that this only another partial break in WPA.

Anyone who's using WPA should not panic over this. Yes, it's compromised, but this is just a faster version of the Tews-Beck attack. Tews-Beck, basically the WEP chopchop attack with a timer, came out last year. This is very a slight refinement that reduces the time to inject from about 15 minutes to about 1 minute by offloading the CRC checks to the attacker instead of using the AP failure messages to do the work.

This attack allows disclosure of the MIC key. That in turn allows for injection of limited number of packets but does not disclose the WPA encryption key. Now, packet injection is a bad thing, but the amount that can be injected is limited by several factors.

While switching to a stronger encryption method is always a good idea, this isn't going to allow wide attacks on WPA encrypted networks. It is just a refinement to an existing, limited attack. WPA was always known to be somewhat vulnerable since it was introduced, as WPA is based on WEP for backward compatibility reasons.

The mildly paranoid among us switched to WPA2 when it was first introduced. The moderately paranoid switched to WPA-RADIUS. The truly paranoid don't even use wireless.

The bottom line is that this is another warning shot to WPA, which as I stated, has been know to be somewhat weak since its very introduction. If people are still using WPA, they ought to be actively planning to a switch to WPA2 or better, as soon as is reasonably possible.
__________________
Thorn
"Read Altas Shrugged. Compare it to today. Repeat as necessary"
Thorn is offline   Reply With Quote
Old 08-28-2009   #3 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,240
In a few more years, I'm gonna switch back to WEP because no one would possibly suspect that it would still be used.. I'll be safe that way.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary.
streaker69 is offline   Reply With Quote
Old 08-28-2009   #4 (permalink)
Starpoint
Pr0nStumbler Expert Level
 
Starpoint's Avatar
 
Join Date: Apr 2003
Location: Houston
Posts: 2,536
Quote:
Originally Posted by streaker69 View Post
In a few more years, I'm gonna switch back to WEP because no one would possibly suspect that it would still be used.. I'll be safe that way.
And change your luggage combos back to 1 2 3 4 5?

__________________
Against the run of the mill, static as it seems

We break the surface tension with our wild kinetic dreams
Curves and lines -- of grand designs...


Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management

My mind is like a Steel trap - Rusty and Illegal in most states
Starpoint is offline   Reply With Quote
Old 08-28-2009   #5 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,240
Quote:
Originally Posted by Starpoint View Post
And change your luggage combos back to 1 2 3 4 5?

Back? I never changed them off of it.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary.
streaker69 is offline   Reply With Quote
Old 08-29-2009   #6 (permalink)
Starpoint
Pr0nStumbler Expert Level
 
Starpoint's Avatar
 
Join Date: Apr 2003
Location: Houston
Posts: 2,536
Quote:
Originally Posted by streaker69 View Post
Back? I never changed them off of it.

like hiding in plain site. People will overthink things and figure no one would use them but its not a bad way to fool them
__________________
Against the run of the mill, static as it seems

We break the surface tension with our wild kinetic dreams
Curves and lines -- of grand designs...


Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management

My mind is like a Steel trap - Rusty and Illegal in most states
Starpoint is offline   Reply With Quote
Old 08-29-2009   #7 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,240
Quote:
Originally Posted by Starpoint View Post
like hiding in plain site. People will overthink things and figure no one would use them but its not a bad way to fool them
Yeah, it's this new method of security that I came up with. I call it "Security by Obscurity". It's virtually unbeatable.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary.
streaker69 is offline   Reply With Quote
Old 08-29-2009   #8 (permalink)
Scruge
Nyuk nyuk!
 
Scruge's Avatar
 
Join Date: Jan 2005
Location: TX
Posts: 1,445
Quote:
Originally Posted by streaker69 View Post
In a few more years, I'm gonna switch back to WEP because no one would possibly suspect that it would still be used.. I'll be safe that way.
LOL.. Being everyone now thinks outside the box, you need to think inside to be different.
__________________
KNSGEM
A wifi boundary plotter for Google Earth
Click Me
Scruge is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 08:38 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.