Fifteen minutes to crack WPA protocol, says researcher

By Tim Conneally | Published November 6, 2008, 12:26 PM

Wi-Fi Protected Access (WPA) is considered a superior encryption protocol to the aged and inherently flawed WEP (Wired Equivalent Privacy), but it is not without its vulnerability, as one researcher is preparing to demonstrate.

Security researchers are now saying they have refined an existing WPA crack, making it more efficient that earlier reports.

Cryptographic expert Erik Tews will appear at PacSec security conference in Tokyo next week with his presentation, "Gone in 900 seconds: Some Crypto issues with WPA." There, Tews is expected to show off his discoveries in TKIP (Temporal Key Integrity Protocol) cracking, that allow WPA to be broken in a brief 12-15 minute window.

TKIP itself is not really crackable, since it is a Per-Packet Key, but once it is initialized, the Pairwise Master Key (PMK) can be obtained. From there, the conventional method of breaking in involved a brute force dictionary attack, or a long process of elimination by trying millions of options.

PC World says that Tews and his partner Martin Beck have discovered a "mathematical breakthrough" that allows the WPA encryption to be cracked dramatically faster. Some of the tools Tews and Beck used are rumored to have been already included in Aircrack-ng WEP/WPA PSK cracking tool. However, the encryption keys from PC to Router have not been cracked in this attack.

Comments

As already mentioned, this is OLD news, the TKIP bandaid was totally insufficient to remediate the totally incorrect manner in which the RC4 cipher promitive was utilized.

The only thing interesting about this story is that it is 4-5 years late!

Why anyone is messing with this stuff and simply not using 802.11i-AES is fascinating...But then the credit card PCI DSS system will have commercial vendors off WEP in 2 years! LOL!

This is like reading a paper taken from a time capsult stuck in the corner of an old building that has been razed.

What next? ...writing digitized data to new plastic disks?

Score: 0

|

This article is just stating that new research has got the crack time down to 15 minutes.

It's like when they reported on WEP being cracked within 1 minute quite recently.

Yes, it's been cracked before, but this is a refining of the method.

Score: 0

|

I understand.

But when someone essentially has an unlimited time period (limited only to the duration of the message and how continuous or bursty the transmission is) to crack it, what does this matter?

Does this have a real impact on the net result when someone doesn't even have to worry about being discovered in the act?

Aircrack has been out for years. This is only news to those oblivious to the Swiss cheese nature of the protocol. And ironically, these are the same people who CONTINUE to use it - regardless of the announcement.

I only wish it made a difference to the masses where the message should not be on how long it takes to crack it, but rather "Why in hell are you still using it?!"

Manwhile the credit card industry is still using WEP to transmit your credit card data 'for only 2 more years'!!

Just get a laptop (with a few extra batteries (as you are going to be BUSY!) and sit in a courtyard in the mall with Aircrack! And have a lucrative Christmas season. :-S

Score: 0

|

I hacked NATO Ghostcom in less than 15 seconds.

Score: 0

|

WPA using TKIP has been exploitable using brute force dictionary attack on the passphrase for years. This is nothing new. WPA2 with AES however has yet to be cracked. You're also safe if your passphrase is a bunch of random non-dictionary word characters (16+) even with TKIP.

Nothing like people taking credit for something that is common knowledge.

Score: 0

|

I think you misunderstood. The article says the brute force or the dictionary attack (two different options actually) were the OLD hacking techniques. "Martin Beck have discovered a "mathematical breakthrough" that allows the WPA encryption to be cracked dramatically faster."

Score: 0

|

I can't imagine an effective brute force without a word list. They are one in the same in my opinion. For the record, I've cracked WPA TKIP in about 20 minutes on a dual quad xeon number cruncher. So this is nothing new to me and many others. Regardless, I'm very interested in seeing the details behind their 'claims'. Because as of right now, that's all it is.

Score: 0

|

back to the drawing board then

Score: 0

|

Well the article specifically says WPA, so since we've already got WPA2, I don't think any drawing boards are necessary.

Score: 0

|

I never could get WPA to work on any network that I configured, regardless of brands, driver verions, etc. With WPA running nodes would never see the access point so I was forced to use WEP every time. Never did figure out what caused it.

Score: 0

|

keepin the wireless router/modem business alive =] its that easy.

Score: 0

|

Yeah, a lot easier than designing and releasing an actually working wireless N dual band gigabit router.

Score: 0

|

The security standard 802.11i has been ratified since spring of 2004. It is not dependent upon N or any channel or throughput.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET