Skip to content

Biting the hand that feeds IT

The Register ®

Comms:


Related Whitepapers

[Print][Mobile][Alerts]

Snag in next-gen Wi-Fi security unearthed

Down to weak passwords, again

Published Thursday 6th November 2003 15:55 GMT

Security researchers have identified a potential security problem involving use of the Wi-Fi Protected Access (WPA) protocol, the second generation wireless LAN security standard.

Although WPA itself remains cryptographically secure, a method used for making the technology easier for consumers to use is susceptible to attack, according to a paper by Robert Moskowitz, senior technical director at the ICSA Labs division of TruSecure.

The issue involves the use of Use of Pre-Shared Key (PSK) as an alternative to 802.1X based key establishment, the approach preferred by corporate environments.

Pre-Shared Keying (PSK) is provided in the WPA and 802.11i standards to simplify deployments in small, low risk, networks. A PSK is a 256 bit number or a pass phrase eight to 63 bytes long.

Cryptographic weaknesses in PSK - particular when used in conjunction with simple pass phrases - mean attackers may be able to crack into systems through passive monitoring of wireless networks followed up by offline dictionary attacks. So the consumer-implementation of WPA is subject to the same kinds of shortcomings that afflicted the weak and broken WEP system, the industry's first (now rejected) stab at a security protocol for wireless networks.

Moskowitz's paper concludes: "The risk of using PSKs against internal attacks is almost as bad as WEP. The risk of using pass phrase based PSKs against external attacks is greater than using WEP.”

"Thus the only value PSK has is if only truly random keys are used, or for deploy testing of basic WPA or 802.11i functions. PSK should only be used if this is fully understood by the deployers," he adds. ®

Related Stories

New WPA wireless security on its way
Wi-Fi Alliance drives improved WLAN security
WLAN security is still work in progress
Tool dumbs down wireless hacking (AirSnort - WEP cracking tool)

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

Enabling the Data Center Metamorphosis

This independent analyst paper gives real world advice on transforming your datacenter into a streamlined, dynamic, liquid engine capable of handling growth..
whitepaper title

Solution Brief: Reduce Energy Costs

Energy consumption has become a big issue. Dramatically increase server utilization and significantly reduce energy costs through Virtualization..
Whitepapers

The Wireless Event 08

Delivering wirefree enterprise mobility & services. Meet 100+ suppliers. Attend Free seminars.

21st–22nd May
London, UK
Add to calendar

More Details

Top 20 storiesAll The Week’s HeadlinesArchiveSearch