Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-05-2012, 02:29 PM
John Navas
Guest
 
Posts: n/a
Default ALERT: WPA-TKIP isn't secure - use WPA2 instead

SUMMARY:

WPA-PSK is vulnerable to offline attack.
WPA-TKIP has been cracked.

TO AVOID THESE PROBLEMS:

1. USE WPA-AES or WPA2 instead of WPA-TKIP (or WEP)

2. USE A PASSPHRASE WITH MORE THAN 20 CHARACTERS. Examples:
BAD: "vintage wine"
GOOD: "floor hiking dirt ocean"
(pick your own words, even longer is better)
FOR HIGH SECURITY, USE MORE THAN 32 CHARACTERS.

BACKGROUND:

Weakness in Passphrase Choice in WPA Interface
<http://wifinetnews.com/archives/002452.html>

Practical attacks against WEP and WPA
<http://dl.aircrack-ng.org/breakingwepandwpa.pdf>

A Practical Message Falsi cation Attack on WPA
<http://jwis2009.nsysu.edu.tw/location/paper/A%20Practical%20Message%20Falsification%20Attack%2 0on%20WPA.pdf>

New attack cracks common Wi-Fi encryption in a minute
<http://www.networkworld.com/news/2009/082709-new-attack-cracks-common-wi-fi.html>

Passphrase Flaw Exposed in WPA Wireless Security
<http://www.technewsworld.com/story/32070.html>

Cracking Wi-Fi Protected Access (WPA)
<http://www.ciscopress.com/articles/article.asp?p=369221>
<http://www.ciscopress.com/articles/article.asp?p=370636&rl=1>

Cracking WEP and WPA Wireless Networks
<http://docs.lucidinteractive.ca/index.php/Cracking_WEP_and_WPA_Wireless_Networks>

Reply With Quote
  #2 (permalink)  
Old 05-21-2012, 04:45 PM
Arklin K.
Guest
 
Posts: n/a
Default Re: ALERT: WPA-TKIP isn't secure - use WPA2 instead

On Sat, 05 May 2012 14:29:45 +0000, John Navas wrote:
> WPA-PSK is vulnerable to offline attack.
> WPA-TKIP has been cracked.


Hi John Navas,

I don't know you but you seem to be crontabbing alerts so you might want
to consider making an alert for the WPS vulnerability which negates all
other security on all wi-fi certified routers.

Details here:
http://www.kb.cert.org/vuls/id/924307

Reply With Quote
  #3 (permalink)  
Old 05-21-2012, 04:46 PM
Arklin K.
Guest
 
Posts: n/a
Default Re: ALERT: WPA-TKIP isn't secure - use WPA2 instead

On Mon, 21 May 2012 16:45:16 +0000, Arklin K. wrote:

> On Sat, 05 May 2012 14:29:45 +0000, John Navas wrote:
>> WPA-PSK is vulnerable to offline attack.
>> WPA-TKIP has been cracked.

>
> Hi John Navas,
>
> I don't know you but you seem to be crontabbing alerts so you might want
> to consider making an alert for the WPS vulnerability which negates all
> other security on all wi-fi certified routers.
>
> Details here:
> http://www.kb.cert.org/vuls/id/924307


Ooops. Wrong Cert.

Details here:
http://www.kb.cert.org/vuls/id/723755

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: ALERT: WPA-TKIP isn't secure - use WPA2 instead Dr Who alt.internet.wireless 1 06-04-2011 02:00 PM


All times are GMT. The time now is 12:51 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45