5 ms·
> WPA2, when properly implemented, is very secure Not really: https://github.com/d33tah/call-for-wpa3/ https://github.com/d33tah/call-for-wpa3/
by d33 8y ago
> WPA2, when properly implemented, is very secure
Not really:
https://github.com/d33tah/call-for-wpa3/ https://github.com/d33tah/call-for-wpa3/
- zokier 8y agoIf I'm not completely mistaken, only the DoS ("Anyone can disconnect you") is valid for true scotsman WPA2 (aka WPA2-EAP aka WPA2-Enterprise). "Silly "terms of service" in your cafe can break your applications and expose you to risk" is hardly fault of WPA2; while some sort of side-channel for provider-provided messages would be nice, I think at least the ToS case could be handled by e.g. DHCP option.
- prophesi 8y agoI think the deauthentication issue was fixed with 802.11w, which is required for vendors to implement to get their 802.11ac license[1]. It was introduced in 2009, so you can be sure there are plenty of vulnerable consumer routers out in the wild. Of course, WPA3 will also suffer this same issue of adoption. [1] https://security.stackexchange.com/a/64440 https://security.stackexchange.com/a/64440
- zokier 8y agoGreat, I haven't been tracking the situation that closely. Additionally googling around I did also find that there are standards to replace the typical captive-portal wifi setup, namely "online sign-up" (OSU) and "additional steps required for access" (ASRA). While I don't know how well they do work in real life, they do demonstrate that the problem is manageable within the WPA2 framework. That being said, the whole landscape around wifi is ridiculously muddied and complex, so if WPA3 does tackle the issues more natively (which I somewhat doubt), then that would be very welcome.
- gruez 8y ago>Anyone can disconnect you so can someone with a jammer. I'm not sure how a protocol upgrade would protect against that. >The password can be cracked offline true, but the solutions presented don't really address the issue. they're variants of key stretching (using a better kdf, mandating stronger passwords, etc.). at the end he mentions "Contemporary cryptography provides tools that could solve this problem.", but that's hand wavy at best. i'm not quite sure it's even possible to implement such a feature in a PSK setting. >Once you know the password, you can sniff traffic and spoof anyone >This problem could be solved by using Diffie–Hellman key exchange (DH). Doubt it. DHE does not offer protection against MITM attacks, which an active attacker can certainly do with a powerful enough antenna. >From the user's perspective, unless you really know what you're doing, I advise you not to browse any sensitive websites (especially banking) over wireless this is fearmongering. most "sensitive" websites already use https, which makes this an non-issue. >It won't let you secure a passwordless network >How could this be solved? The new WPA security standard could support the "passwordless" mode that requires no authentication, but keeps an encrypted channel of communication so that the anonymous user can identify himself and make traffic only readable by the access point. how does this protect against MITM? that is, a rogue router pretending to be an hotspot? > Silly "terms of service" in your cafe can break your applications and expose you to risk valid point, but already solved: https://en.wikipedia.org/wiki/Hotspot_(Wi-Fi)#Hotspot_2.0 https://en.wikipedia.org/wiki/Hotspot_(Wi-Fi)#Hotspot_2.0
- da_chicken 8y agoEDIT: Ignore me I've confused terminology. > Doubt it. DHE does not offer protection against MITM attacks, which an active attacker can certainly do with a powerful enough antenna. Huh? That's precisely what Diffie-Hellman is for. It's a protocol for establishing a shared secret over an insecure channel. Have you got an antenna big enough to read the private key? Sure, you can argue that pure DH is weak compared to ECDH or PKCS, but this is exactly what the system does. No, DH doesn't stop impersonation or spoofing attacks. It doesn't do authentication. That much I agree with you on. You need something like ECDSA for that. But those types of attacks aren't MITM.
- Godel_unicode 8y agoYou don't think that MITM is a kind of impersonation attack? DHE is a mechanism for agreeing on a secret; it does nothing to authenticate the station you're agreeing on that secret with. Think of what happens in TLS interception; DHE still takes place with the intercepting device, it's PKI which tells you who you're agreeing with.
- da_chicken 8y agoYeah, I had my terminology confused. I was mistaken.
- comex 8y agoIn fact, you were closer to the truth than the person you replied to. The new standard uses a PAKE (password-authenticated key exchange) protocol. This type of cryptographic construct is similar to an unauthenticated key exchange protocol (such as Diffie-Hellman), but in addition succeeds only if both parties know the same password, without leaking any information about the password to a party if they don’t know it. At least one of the best-known PAKE algorithms, namely SRP, is quite similar to Diffie-Hellman in structure, although it’s not the one being used here (which I don’t know anything about).
- sandworm101 8y ago
- gsich 8y ago>It won't let you secure a passwordless network Yes it does. 802.1x solves this. Just allow any user/password combination. This has been in use successfully. It worries me that the author doesn't mention this.