November 06, InternetNews.com - Weakness found in Wi-Fi security protocol.

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 11/07/03


Date: Fri, 7 Nov 2003 11:27:40 -0500

November 06, InternetNews.com - Weakness found in Wi-Fi security protocol. Wireless
security expert Robert Moskowitz has detected a glaring weakness in the interface design of
a Wi?Fi Protected Access (WPA) protocol deployed in numerous Wireless LAN products.
According to a research paper written by Moskowitz, the weakness could allow intruders to
crack poorly chosen passphrases via offline dictionary attacks. The paper means that Wi?Fi
hardware products that ship with WPA might be less secure than the older Wirele-s
Encryption Protocol (WEP), which it replaced in 2002. The WPA standard was designed to
improve upon the security features in wireless networks. The weakness only takes effect
when short, text?based keys are used and does not reflect a fault in the WPA protocol. The
weakness can be avoided if WLAN hardware manufacturers build units with the ability to
generate random keys that can be copied and pasted across systems. Manufacturers can also
restrict the ability to enter weak keys by requiring passphrases with numerous characters
instead of words that can be found in the dictionary. Moskowitz warned that dictionary
based programs used to crack passwords are heavily used by criminal hackers.
The paper is available online: http://wifinetnews.com/archives/002452.html

Source: http://www.atnewyork.com/news/article.php/3105271



Relevant Pages

  • OpenAir pen-testing
    ... setup/issues of any "OpenAir" wireless devices? ... I can't seem to find any *real* information on the protocol, ... there is a shared security ID that needs to be sent to join the network. ... An earlier wireless LAN protocol endorsed by the Wireless LAN ...
    (Pen-Test)
  • Re: Budding wifi protocoler
    ... That days when wireless was magic and required high paid magicians are ... If you concentrate on just the protocol aspects, ... You'll find that these form the basis of most design work. ... Suffice to say that the real standard ...
    (alt.internet.wireless)
  • Re: Using TCP/IP for File sharing behind Netgear Router-Modem?
    ... You're right there as well, but it became a problem on the wireless, because ... it's not a routable protocol, well it was a problem for the old Linksys ... through the typical wireless bridge. ... Windoze networking was at one time totally NETBIOS ...
    (alt.internet.wireless)
  • Wireless security
    ... What do you need to look for on a wireless network product in order to ... Will these new cards support the new, AES based protocol? ... to rely on encryption in the higher levels? ...
    (sci.crypt)
  • Re: lpx
    ... you not recomend netdisk in wireless networks at all? ... is the slow wireless connection. ... Is this an Ethernet-level protocol? ... I found on my system that the connection became ...
    (comp.sys.ibm.pc.hardware.storage)