8 ms·
I'm not sure why this is amazing enough to make the first page but W/E it's HN :). Just so less informed are aware, this has been feasible for maybe 7 years (si
by throwasehasdwi 9y ago
I'm not sure why this is amazing enough to make the first page but W/E it's HN :). Just so less informed are aware, this has been feasible for maybe 7 years (since GPU calculation became possible).
Just so nobody freaks out, this is cracking weak passwords, not broken WPA.
I have myself cracked countless WiFi passwords when security testing. It's easy if the passwords are bad, which is maybe 90% of the time for home networks and 60% for businesses. The attack is completely passive if you don't want to be noticed, and with a cheap dish you can pickup both ends of the handshakes from up to around a quarter mile away (line of sight).
- amluto 9y ago> Just so nobody freaks out, this is cracking weak passwords, not broken WPA. I beg to differ. The fact that WPA is subject to a passive attack at all is a defect. It should use a PAKE, which would entirely avoid this type of attack. There are simple balanced PAKE protocols that would do the trick. DH-EKE, SPAKE2, J-PAKE, and even the venerable SRP would all work. I believe that several are old enough that no patents are possible, and, even when WPA was standardized, something should have been available.
- throwasehasdwi 9y agoYes, this is still a major problem with WPA. Also the fact that certain control packets aren't authenticated is nearly unforgivable. If correctly designed the only reasonable attack on wifi would be channel jamming, sadly after many years this still is not the case.
- d33 9y agoThis is probably a good occasion for a call for WPA3: https://github.com/d33tah/call-for-wpa3 https://github.com/d33tah/call-for-wpa3
- kees99 9y agoWEP, WPA, WPA2... why keep reinventing the same wheel? Each new iteration inevitable turns out to be less-than-perfect and keep adding more and more complexity and overhead - for one, join/leave times keep increasing, up to a point where we have a separate standard (802.11r) just to get back pre-WPA roaming speeds (at cost of even more protocol complexity overhead). Here's crazy idea: Why not run open network + IPSEC, or heck, even OpenVPN? Obviously, drop all non-VPN traffic right on the AP (or first router after it) to nip freeloaders in the bud.
- djsumdog 9y agoMost captive portal routers don't block DNS (because they use iptables rules to handle authentication). That's why you can use iodine to proxy TCP-over-DNS on such APs. So if you just had an open access point, unless you provided no DNS servers except over VPN, people would still be able to use your AP.
- poizan42 9y agoPresumably you want to reply to DNS requests for a hostname for your captive portal. You might try to just use a raw ip address, but then you can't use https. So then you have the problem that you can't just reply with a fake answer for other domains due to caching. E.g. Windows caches negative responses for 5 minutes, which would be a pretty bad experience for your customers. I guess you might be able to just fail to reply to DNS requests for domains outside you captive portal, I have no idea if anyone has tried that or there might be other complications. Edit: Actually not replying wouldn't work great either because then the user can't be redirected to the captive portal. This might be less of an issue today since most devices have standardized a way to detect captive portals using a small set of hostnames.
- hunter2_ 9y agoAside from custom root certs being installed, https is out either way, not only with IP address, right? HSTS makes that even more of a problem, and pinning makes even the custom root cert a problem. Captive portals seem like an increasingly fragile idea, except that OSes increasingly intervene appropriately.
- MadSax 9y agoFor those that don't know, like me, how would PAKE etc protect cracking of weak passwords used during client authentication?
- throwasehasdwi 9y agoIt doesn't give you a hash to crack. It reduces your speed of guessing passwords from "how quick can you hash X", which is millions of times per second, to "how many times can I attempt to get in before the access point blocks me". This major issue with WPA password cracking today is that it can be done "offline". You can pull the handshake out of the air and bang on it as long as you want. It's pretty much the same thing as trying to guess a password from some leaked hashes vs trying to guess a password using the gmail interface.
- MadSax 9y agoThanks. I also hope that deauth frames are encrypted in the next version of WPA.
- throwasehasdwi 9y agoThey are a current feature but not the baseline which means in practice implementations are buggy or non existent. I've had a few nicer routers where I could turn the options on but most clients are not able to connect :( . I need to be in the baseline standard to get qualified or nobody will implement it.
- xori 9y agoI'm not sure how PAKE works, but how would an AP block you? MAC address are forgeable. And any nonce an AP sends down as a one-time salt would be visible to you and you could still just brute force it offline. EDIT: After reading up on SPAKE2, it's basically just a Diffe-Hellman exchange. You can still totally do a brute force because you know what the first encrypted payload should look like and you can listen in for that encrypted message and use that as your "test that you got it right" I think that at the end of the day, no matter what key stretching techniques you use. A bad starting key results in a bad end key.
- throwaway91111 9y agoAgreed. However, WPA has been obviously broken for years; just use WPA2 instead. It's also way easier to set up on your grandmother's random router.
- mdeeks 9y agoCan someone define what is considered a weak vs strong password now for WiFi? The only guides I found online are years old. Is 10 characters considered weak for mixed case letters, numbers, plus punctuation now?
- fhood 9y agoWeak = is in rainbow table that hashcat is using
- throwasehasdwi 9y agoWifi password cracking is only around 1000X slower than a SHA256 brute-force if I remember right. So your password needs to be secure enough that if a hash of it was leaked it would never be cracked.... So very strong. WPA enterprise using certificates is usually much harder to crack since you need to interrogate server, you can't just brute force hash. This method only really applies to PSK mode (home networks and small businesses usually)
- domenukk 9y agoIf you consider your random keyspace with 26 * 2 chars + 10 numbers + 20ish special chars then to crack 10 letters you'll have to try an average of ((26 * 2 + 10 + 20) ^ 10) / 2 = 6.8724016e+18 keys. If you then assume around 3 million hashes per second it still takes around 72641 days to crack your password. Edit: As another comment said, just make sure it's not easy to guess based on rainbow tables and whatnot
- 1wd 9y agoDid you mean 72641 days or years? (And could / should we include somehow that "hashes/second" increases by factor of ~2(?) each year?)
- rocqua 9y agoTo do this formally, you need to consider information entropy. This is all about how you generated your password. 10 characters of totally random mixed case, numbers and punctuation gives about 60 bits of entropy which is strong enough. HOWEVER, that calculation only works if all 10 characters were generated uniformly and randomly. Humans are terrible at this. Now, maybe your trick for turning words into safe passwords is great, but there is no way to be sure. Sadly, remembering 10 random characters is hard. Luckily, easy to remember and strong passwords are possible. The system I would recommend is diceware: www.diceware.com
- lqdc13 9y agoNowadays most routers I've seen come with a pre-shared key that's something like 20 chars long. It's been the case with Comcast + Verizon for a while now. Not sure about AT&T. Still might work 10% of the time though.
- paulgerhardt 9y agoSome regional bias here. Most of Asia (so most of the world) use digits only for their wifi password. Lack of fluency with Latin characters was not a big concern in the original implementation. That should be fixed with WPA3
- lqdc13 9y agoWhy does that matter? 15 character digits-only password is impossible to crack really. It's all about the length really.
- thomastjeffery 9y ago> but W/E it's HN Would you please simply type "whatever", instead of this "W/E" nonsense? Considering the amount of 8+ character adjectives you used, you clearly aren't trying to be less verbose.
- hartator 9y agoI am okay with abbreviations, but I had to think twice for this one.
- hyperdunc 9y agoIn the same spirit of improving grammar and readability - I think you meant to type 'number' of 8+ character adjectives.
- Markoff 9y agoi am not native speaker so didn't even know what does it mean, since it's much less common than Without written this way
- melq 9y agoYou understood him perfectly well, what exactly is your criticism? If he agrees to comply to your arbitrary standards of style, only to say the exact same thing, will you agree to "please simply" refrain from being obnoxious for no reason?
- thomastjeffery 9y agoI did not understand perfectly well. Understanding for me required a Google search. It's quite a nuisance for me to have to google an uncommon abbreviation for one of the most common words in my native language.
- frankzinger 9y ago> arbitrary standards of style Spelling words correctly is not "arbitrary", it's conventional.
- TheAceOfHearts 9y agoIn your opinion, is setting up a RADIUS server and using WPA2-Enterprise worth it for a consumer? I'm pretty paranoid, and also think it could be an insightful experience to tinker around with networking tools. Any advice for what constitutes a strong or weak password in this context?
- ComputerGuru 9y agoI wanted to do that in my home, but good luck getting IoT devices to connect which may be a good thing..) You'd probably have to set up a separate network for those devices (again, technically a good thing) which can be a source of some friction. It used to be only good routers had a guest network option, but now even $20 TP-Links can use Radius for the main network and WPA2 for the guest network; though I'm not sure you can do something like whitelist by MAC on only the guest network.
- pixl97 9y ago>In your opinion, is setting up a RADIUS server and using WPA2-Enterprise worth it for a consumer? It can be a pain in the ass when the consumer device requires a valid SSL certificate. On active directory networks this isn't much of a problem because a CA is pushed out to devices, but automating this at home can be a bigger issue.
- daurnimator 9y agodynamic dns + letsencrypt?
- cpach 9y ago~15 random characters (printable ASCII of course) should be enough for a WPA2 password.
- jagermo 9y agoIf I might ask, how would you compile a password list for a non-english speaking country? Just look for a wordlist in the respective language or also try to create your own via tools like CeWL?