Stronger Encryption for Wi-Fi
sp00 writes "The first products certified to support Wi-Fi Protected Access 2, the latest wireless security technology, were announced by the Wi-Fi Alliance on Wednesday. The Wi-Fi Alliance says WPA2 is a big improvement on earlier wireless security standards, such as Wired Equivalent Privacy (WEP), which hackers have found easy to circumvent. It includes Advanced Encryption Standard, which supports 128-bit, 192-bit and 256-bit keys."
Please don't tell my neighbors about this technology. Thanks. :)
The World Wide Web is dying. Soon, we shall have only the Internet.
The real question is will the manufacturers come out with new drivers/firmware to take advantage of this new technology?
I feel I speak for wireless users everywhere when I say "Good". What more is there to say?
All these new ways of encrypting data over wireless is great. Security of data is a good service. But how much will it cost, do you need more expensive hardware to create such encryption, will there be a loss of performance and other related factors. These are important and must be tested before we start saying that wap2 is the world's greatest thing for wireless encryption.
Correct me if I'm wrong, but isn't WPA2 just the WiFi Alliance being stuborn about what to call 802.11i? I mean, WPA was just supposed to be 802.11i minus everything that required hardware upgrades. WPA2 is just 802.11i, only not a real standard, ooh boy!
I believe MAC filters are inherently less secure than encryption: The MAC addresses, I believe, are sent in the clear (i.e., not encrypted), so all someone has to do is listen to which devices are already operating on the network, then spoof their MAC to match.
It is not as easy as everyone says. Try it with some brand-new, high quality equipment and you may be surprised at the result.
Oh well mine is enabled
----
Free IPods
So now instead of just a few hours with a current computer, it will take a bit longer, maybe a week or something. Then someone will figure out that the key string is MAC dependent based on time signitures, or something, and there we go, no more security.
I have no illusions about the "security" of WiFi, no matter how encrypted it may be. The signal is traveling through open space for anyone to look at, and if you look at enough of the signal, you can find the pattern. This just increases the processing power needed by the AP and Card, further pushing the development of more advanced, procs. (Don't get me wrong, I'm all for this)
I understand that corperations are interested in this for security, but for an average joe like me, I keep my access point wide open for anyone to use. If you want to look at my GF's reciepe's or our photos, go right ahead.
Security is only as important as you make it to be.
--sig fault--
Using 128 bit encription on most residental points will take several weeks of listening to break (correct me if I am wrong here) Shouldn't we concentrate on convinceing users on just doing something.
One of WEP's biggest design flaws has been that all data is encrypted with the same key. Sure, there needs to be some shared secret for authentication, but the actual data transfer should use a negotiated key known only to the user and the AP. WEP is all right for authentication, but when it comes to security it's useless against other authenticated users.
It wouldn't be a bad idea to use something like this for non-broadcase Ethernet either, now that I think of it.
Karma: Segmentation fault (tried to dereference a null post)
Our network uses a 802.1x system with dynamic WEP keys.. the system requires you to re-authenticate (handled automatically by 802.1x client software) with a randomly generated key every 15 minutes.
What is the real advantage to WPA here?
At first, you don't trasmit anything. (Since, as you point out, the whitelist would prevent the access point from responding to you, anyway.) However, you just listen to the existing legitimate traffic. Then clone your device with the same MAC as one of these legitimate (and already on the whitelist) devices.
As long as these acess points are shipped with encryption turned *OFF* by default this is like pissing in the wind. It could be 1 billion bit one time pads and woulnd't make any difference. In my neighboorhood there are 10 unencrypted networks....all on the default channels. Out of the box straight onto the network is how they are set up. Joe Sixpack doesn't have time to deal with encryption.
*don't worry much residential war drivers..there will still be free lunch for a long time to come...
the original design specks for WPA included the ability to flash/bios upgrade the code on the wireless adaptor to support these new fangled protocols...pending the original hardware has the processing ability to support the new stuff (256 bit aes encryption for eg. might be difficuilt on really early adaptors)..although i might add aes encryption is actually less cpu intensive than say wep, but it could remain a problem.
I believe the AES implementation they are using actually does encrypt the ethernet (MAC) address, unlike WEP. (See Tying It All Together in this article for corroboration of that.)
WPA2 with AES is the real deal.
- jon
Ganymede, a GPL'ed metadirectory for UNIX
The number of bits used by the key is not enough to judge the security of the system. You could have a crap cryptographic algorithm or, more likely, a crap protocol.
People talk about WPA security and how it's important, but the fact is most home users don't even change the default password for their wireless routers.
Bored? Visit my exciting counter page!
So this means to take advantage of the latest security, I would again have to upgrade all my AP's and Clients... $ $ $ When will this whole industry be commoditized enough that we have 'soft' radios for wireless (Like AC97 Audio) that allow us more flexibility in upgrading older hardware to newer standards? Heck, with a true soft-wireless chipset we could use one RF device for WiFi and Bluetooth and whatever they dream up next...
Sufficient for what?
Keeping a serious attacker away from your data, if it's specifically you he's after? Possibly not.
Keeping a casual war(mode-of-transport)'er out of your WLAN to stop him leeching your bandwidth? Probably.
or against it?
Karma? Karma? I don't need no stinkin' karma.
Link level security is fairly useless. It's fine for the average user, but the average user doesn't know how to turn it on. It would be great if there was some kind of auto-negotiated application layer security. Like IPSeC that has the user transport a USB dongle with the keys or something. This is just frivilous.
There are still so many devices that don't support WPA one.. Tivo, I'm looking at you. All this nonsense about a supplicant this and that. When is Tivo going to get on the WPA 1 train?
To me the chief advantage of WPA is a human readable password.
I just setup a wireless access point in the conference room at my company's headquarters. Not my idea but when the CEO wants to use his centrino notebooks wireless its move or be moved. Anyway, they wanted to leave it open and just turn it on when needed but I talked them out of that. Instead I set it up with 64bit WEP. The AP supports 128 bit but getting them to all key in a huge hex pass isnt going to fly. Havent figured out how to get the passphrase to parse on XP SP1. SP2 looks nicer. Anyway all the wifi equipment is new, within the last year or two, and as netstumbler has shown me we're not the only kids on the block to have wifi with WEP in the building. I've read conflicting reports about how easy it is to crack WEP with tools as simple as those included with knoppix std, so I think what I'm asking is, is 64bit enough, and should I be more paranoid, setting up VPNs and the like?
Were talking about light traffic (email, little browsing) from 5 or 6 users about 8 hours a day.
Im dreaming ofa big bndwdth, That can resist the
you guys can piss and moan all you want but AES is rock solid. This is a great solution for those who don't have time resources or knowledge to use 802.11x with RADIUS. Finanaly a secure encruption scheme for home users who know absolutely nothing about encryption and how it works. I give it 2 thumbs up :)
presmike
WEP is a LOT more secure than people imagine these days. Most AP's and clients refuse to use weak IV's making the statistical attack used by Airsnort and other apps effectively useless.
Theres a very small minority of people still using weak 64-bit ASCII key generator algorithms that were found to be only 21-bits of effective keyspace. These can be cracked offline in about 15 seconds with a single encrypted frame but other than that, offline cracking of WEP is still a hard thing to do (from a practical point of view).
Yesss.. that sounds like a great idea.
However, if you don't mind, I think I'll skip all the "take a look at my recipies" formalities and go straight to
- sniffing your email passwords,
- reading your email,
- sending email under your account from your IP,
- using your wireless access point to spam,
- surf some underage porn using your IP,
- seed my "next big worm" from your connection,
- browse/sample your internal network from the IP your WAP so conveniently gave me,
- and finish up by making various explicit threats against the president on the newsgroups while simultaneously using your cable connection to make VoIP calls to the NSA and reading them some of your previously mentioned fine recipes.
I almost forgot to say thank you for the free access point. Where are my manners...
I was told that I could listen to the radio at a reasonable volume from nine to eleven...
You would need special equipment, I imagine,
Nope.
unless there is a way to get a standard card to listen to all traffic on a given channel
Yep. Lots of normal cards can do this easily. The rare cards that can't are considered "crippled". A few cards can collect more than 1 channel at once.
allows for a variety of client systems to connect.
I'm thinking of setting up a small WLAN using old equipment that i can get almost for free.
I would just plug another NIC in my OpenBSD firewall and keep nothing but the necessary ports for the VPN open.
There's a broad range of encryption and authentication methods available, and if the one I use
would be too weak, I could just change to another one instead of having
to buy new hardware such as PCMCIA cards, APs etc.
If you use WEP at the moment, some operating systems will prompt you to enter the key. Not the passphrase, but the digested key. So even though I know the passphrase, I must type 26 characters of hexidecimal into my iPaq with a stylus. Linux is no better for wireless and the last time I looked required hex too. Linux is particularly lousy if you use more than one WLAN since all the dists I've tried only store the details for one of them.
It is absolutely ludicrous. XP doesn't do that and I doubt (though I haven't tried) that OS X would either.
Given that, it would not surprise me that of those who even know to enable crypto if half don't just give up or use MAC filters or no security at all.
My preference would be whatever standard they choose be mandated to use crypto by default - and by virtue of the even longer key length it will force software makers to improve their support for it.