3 ms·
Good God, what a comedy of errors. First, that WPS even lets you get around a 256-bit key with a 10^8 PIN (like others, I thought WPS was pushbutton-only), but
by jaylevitt 15y ago
Good God, what a comedy of errors. First, that WPS even lets you get around a 256-bit key with a 10^8 PIN (like others, I thought WPS was pushbutton-only), but second, that this vulnerability brings the brute-force complexity down to 10^4 + 10^3, or 11,000 attempts: http://www.kb.cert.org/vuls/id/723755 http://www.kb.cert.org/vuls/id/723755
- yuhong 15y agoThey used Diffie-Hellman to prevent offline cracking.
- extension 15y agoAny idea why it splits up the PIN like that? It costs $100 just to download the spec.
- jacquesgt 15y agoSee my response below. I think they're trying to protect against potential weaknesses in the HMAC by requiring both sides to prove they know part of the PIN before sending information derived from the second part of the PIN. If a weakness is discovered in the HMAC, this scheme is supposed to allow either side to bail without leaking the whole PIN. This (supposedly) protects against someone spoofing the AP and selecting nonces that allow the PIN to be recovered.
- jaylevitt 15y agoI'm no crypto guy.. is there any conceivable situation in which their idea works? I mean, when is it actually more secure to say 'I'll let you know if you got the first half of the password right before you enter the second'?
- noneTheHacker 15y agoCan you, or maybe someone else please explain why it becomes 10^4 + 10^3. My math skills are a little rusty.
- law_of_poe 15y agoNot much math necessary for the explanation. Follow the link jaylevitt posted: When the PIN authentication fails the access point will send an EAP-NACK message back to the client. The EAP-NACK messages are sent in a way that an attacker is able to determine if the first half of the PIN is correct. Also, the last digit of the PIN is known because it is a checksum for the PIN. This design greatly reduces the number of attempts needed to brute force the PIN. The number of attempts goes from 108 to 104 + 103 which is 11,000 attempts in total.
- noneTheHacker 15y agoI followed that link before I posted. I was unable to determine what 10^4 and 10^3 represented and the link did not explain it in a way for me to understand. Obtu was able to explain it to me.
- obtu 15y ago10^4 attempts (worst case) to bruteforce the first four digits using the early NACK, 10^3 attempts (worst case) to bruteforce the entire pin once you know the first four (this part only has to iterate on three digits of the second half, and compute the checksum to get the last digit).
- noneTheHacker 15y agoThanks. This explains it perfectly to me.