Secure Wi-Fi? Not so Much -- Gaping Hole Found in WPS Pin System
December 29, 2011 12:42 PM
comment(s) - last by
The Department of Homeland Security suggests the only solution is to disable WPS
NETGEAR, Inc. (
), Cisco System, Inc.'s (
) Linksys, D-Link Corp (
), and Belkin, Inc. are some of the biggest makers of routers. If you own a router, there's a good chance you own a router from one of these manufacturers. And if you own a router from them, there's a good chance you used Wi-Fi Protected Setup (WPS) -- a PIN protected method -- to easily set up your home network. And that means that there's a good chance your security is now at serious risk.
WPS was dreamed up by
the Wi-Fi Alliance
as a means of easing the pain of home networking. But by including a flag in the EAP-NACK message, the standard unwittingly left a gaping hole that can be exploited by hackers to subvert your router.
The message tells the user if the first half of the pin they typed was right. Thus it drastically reduces the time needed to crack the PIN using a brute force attack. Add in that the last bit of the PIN is always its checksum, you have a recipe for a security disaster.
[Image Source: Best Wireless Internet Routers Blog]
The flaw reduces the time it takes to crack your average PIN from 10
attempts to 10
attempts (11,000 attempts total). Assuming you can fire off ten requests or more a second, you should be able to crack routers in minutes.
U.S. Department of Homeland Security
issued a warning
to the public
about the flaw. It
disabling WPS. This may be a painful option for less savvy operators, though, as setting up a network with more sophisticated protections can require a bit of learning.
the vulnerability and reported it to the DHS. He claims that none of the major manufacturers stepped up to the plate with a patch. He is going to release a C-coded exploitation tool shortly -- perhaps that will help prompt the business into action.
.BrainDump (Stefan Viehbock)
Department of Homeland Security
This article is over a month old, voting and posting comments is disabled
12/30/2011 8:05:55 PM
Well at least Gibson specifies that it is not a strength meter (he's right it isn't) but calls it a keyspace meter instead (which is basically the same thing by another name). So having pointed out that is doesn't measure the password strength then goes on to describe how long it would take to brute force it. See the contradiction???
Keyspace (as calculated by that page) is irrelevant unless it represents the process of generating a key. For example, take a lowercase letter followed by 1234567879, that is a 10 character alphanumeric password but only has a keyspace of 26 (i.e. [a-z]123456789) and not (26+10)^10.
Basically don't reference that page (or that site), period. Ironically xkcd makes far better suggestions (as long as the password field is big enough).
For Wifi a 19+ length random mixed case alphnumeric password is basically totally overkill ( ~113bits of security) since with 4096 rounds of PBKDF2 hardening we are nearly at the 128bit security level (the level that even thermodynamically speaking would require the entire planet's energy output for nearly a decade for a perfectly efficient computer to simply count to that number let alone actually SHA1 hash something that many times). Makes 256bit security look a bit silly really doesn't it?
"Spreading the rumors, it's very easy because the people who write about Apple want that story, and you can claim its credible because you spoke to someone at Apple." -- Investment guru Jim Cramer
Homeland Security Warns About Latest Dangerous Apple Browser Bug
May 10, 2010, 5:20 PM
WiGig Specifications Completed
December 10, 2009, 11:16 AM
Windows 8.x Marketshare Fell During September, Windows 7 Still King
October 2, 2014, 12:00 PM
"Mo' Money", Less Problems: Google Offers Cold Hard Cash for Finding Its Browser Bugs
October 1, 2014, 3:04 PM
eBay to Spin Off PayPal Business Next Year
September 30, 2014, 7:28 AM
Facebook to Use Your Browsing Data to Sell Offsite Display Ads
September 29, 2014, 3:52 PM
After Microsoft Complains, EU Rejects Google's Search Settlement for Second Time
September 23, 2014, 4:58 PM
Microsoft Expands Free Office 365 to All College Students
September 22, 2014, 3:21 PM
Most Popular Articles
New AT&T Mobile Share Value "Double Data" Promotion Lasts Through October
September 28, 2014, 8:32 AM
Update: Apple Releases iOS 8.0.2 Update to Make Up for Botched 8.0.1 Release
September 25, 2014, 8:19 PM
Appalling Negligence: Decade-Old Windows XPe Holes Led to Home Depot Hack
September 8, 2014, 8:58 PM
TiVo Mega Features 24TB of Storage, Can Record Three Years* Worth of TV Content
September 8, 2014, 8:45 AM
FBI Outraged That Apple, Google are Adopting Digital "Locks" to Protect Users
September 26, 2014, 1:00 PM
Latest Blog Posts
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information