Slashdot Mirror


Researchers Crack WPA Wi-Fi Encryption

narramissic writes "Researchers Erik Tews and Martin Beck 'have just opened the box on a whole new hacker playground, says Dragos Ruiu, organizer of the PacSec conference. At the conference, Tews will show how he was able to partially crack WPA encryption in order to read data being sent from a router to a laptop. To do this, Tews and Beck found a way to break the Temporal Key Integrity Protocol (TKIP) key, used by WPA, in a relatively short amount of time: 12 to 15 minutes. They have not, however, managed to crack the encryption keys used to secure data that goes from the PC to the router in this particular attack. 'Its just the starting point,' said Ruiu."

30 of 311 comments (clear)

  1. Ha ha ha ha by Anonymous Coward · · Score: 3, Funny

    All your AP are belong to us.

    You have no chance to survive make your time.

  2. Hahaha! by u38cg · · Score: 5, Funny

    I use WEP!

    --
    [FUCK BETA]
    1. Re:Hahaha! by PotatoFarmer · · Score: 5, Funny

      We know. By the way, do you think you could talk your ISP into increasing your download bandwidth?

    2. Re:Hahaha! by blhack · · Score: 2, Funny

      Yeah, and I run an open access point with the SSID hidden called "secret_awesome".

      I feel like its the least I can do to help any new geeks in the area :).

      --
      NewslilySocial News. No lolcats allowed.
    3. Re:Hahaha! by Lisandro · · Score: 2, Funny

      So you are the one slowing down my torrents...

    4. Re:Hahaha! by russotto · · Score: 4, Funny

      Yeah, and I run an open access point with the SSID hidden called "secret_awesome".

      I run one called "man_in_the_middle". Best pay attention to those certificate warnings when you're using it.

    5. Re:Hahaha! by tkdtaylor · · Score: 2, Funny

      I call mine "HoneyPot"

    6. Re:Hahaha! by layer3switch · · Score: 2, Funny

      No, that would be me, Comcast.

      --
      "Don't let fools fool you. They are the clever ones."
  3. Re:Meh by von_rick · · Score: 2, Funny

    Of course you can.

    If you want to take it to its logical conclusion, you can make that person hand you all his passwords and personal information if you storm into his house swinging a baseball bat or a samurai sword. I have seen some hollywood movies where the the president hands over the codes to national treasury to criminal masterminds who threaten to detonate nuclear bombs in metropolitan areas during some ceremonial parade -- that is until the retarded hero (usually Bruce Willis) shows up.

    --

    Face your daemons!

  4. Re:OHNOES! by Coraon · · Score: 4, Funny

    I know I just got root access...BTW could you put in some bread? I'm trying to install pop-up's.

    --
    -Ours is the wisdom of Solomon, the magic of Merlyn, the fall of Icaris.
  5. Re:I use ROT13 by ale_ryu · · Score: 2, Funny

    Meh, that's nothing, I use DOUBLE ROT13. Learn 2 secure your data you n00b!

  6. Re:Who uses TKIP instead of AES? by Anonymous Coward · · Score: 1, Funny

    I herd you liek TKIPs

  7. Re:WPA2 is NOT broken by sexconker · · Score: 4, Funny

    Nerds like to sit.
    You can sniff packets while sitting just about anywhere. In your kitchen. In your car. On the crapper.
    To tap a line, you usually have to get up, and you often have to use some archaic toolset like Screw.Driver or Flash.Light that you haven't supported since 3 forks ago.

  8. Re:WPA2 is NOT broken by MasterNetHead · · Score: 3, Funny

    Its funny... my neighbors are probably thinking the same thing.

  9. Re:Meh by monkeySauce · · Score: 4, Funny

    Bah... cat5 is already broken, and cat5e is next.

    Got to think cat6 at least, if not cat7. They're much thicker; harder to break.

  10. Re:Secure Wi-Fi by Anonymous Coward · · Score: 2, Funny

    My security is a lot simpler and more effective: one of my neighbors has an open WAP with "linksys" for an ssid.

    Don't worry, I changed the default admin password for them.

  11. Re:Meh by Otto · · Score: 3, Funny

    You can even do it without physical access on cheap routers and/or modems, by pointing a good digital camera and a telescope at the blinkenlights on the front of them. :D

    --
    - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  12. Re:'Story' tag by athakur999 · · Score: 4, Funny

    They should tagged it "tagged" if it is tagged and "!tagged" if it's not tagged.

    --
    "People that quote themselves in their signatures bother me" - athakur999
  13. Re:Meh by Endo13 · · Score: 4, Funny

    Apparently you just haven't watched enough movies. Obtaining physical access IS trivial. All you need is a hot chick to go swipe the security guard's badge that he conveniently left lying on his desk, and you're guaranteed access anywhere in the building.

    --
    There is no -1 Disagree mod. Slashdot.org/faq defines mod options. USE IT.
  14. Re:Meh by Endo13 · · Score: 4, Funny

    Well duh, of course it's trivial. They're always swooning over you. (Well, except when they're pretending to fight with you, but even then they always come around just in time.) Haven't you learned anything from Hollywood??

    --
    There is no -1 Disagree mod. Slashdot.org/faq defines mod options. USE IT.
  15. Re:Who uses TKIP instead of AES? by psydeshow · · Score: 2, Funny

    Look, obviously TKIP is more secure, becuase it has more letters.

    You geek types are always saying I should use a longer password, right? This is the same thing.

    And anyway, they wouldn't make it an option if it wasn't secure.

  16. Re:Meh by fataugie · · Score: 5, Funny

    Yeah, except smarts and hotness are inversly proportianal in most cases.
    What good is getting access when the bubblehead can't figure out what a wiring closet looks like.

    --

    WTF? Over?

  17. Re:Who uses TKIP instead of AES? by fataugie · · Score: 4, Funny

    What's also funny is that my router gives me better throughput with WPA/AES than WEP

    That's because your router is laughing at you using WEP in between encrypting/decrypting the packets....that's why it takes longer.

    --

    WTF? Over?

  18. Cracked and Mad by Anonymous Coward · · Score: 1, Funny

    If WPA is Cracked then is WPA2 Mad?

  19. Re:Meh by RiotingPacifist · · Score: 3, Funny

    hey its "yes, you can08" to meet the new stricter password requirements

    --
    IranAir Flight 655 never forget!
  20. Obviously by spazdor · · Score: 3, Funny

    over 9000.

    --
    DRM: Terminator crops for your mind!
  21. Re:Meh by Killer+Orca · · Score: 2, Funny

    Or I could just whip out my Mr. Fusion.

    Is that what the kids are calling it nowadays?

  22. Re:'Story' tag by arelas · · Score: 2, Funny

    A hole even!

  23. Re:Meh by Logic+and+Reason · · Score: 4, Funny

    smarts and hotness are inversly proportianal

    Wow, you must be really hot...

  24. Re:Who uses TKIP instead of AES? by g-san · · Score: 2, Funny

    LOL! Is there a patch for that? He probably just needs to pull the UDP plug out the bottom and let all the dropped packets drain out. Where do you think they go when they are "dropped?" Dropped packet buildup has killed more routers than I can count.