3 ms·
WPA does not only have 256 keys. The author decided to show that if he knew all but one character of his network password, he could bruteforce the missing char
by willscott 15y ago
WPA does not only have 256 keys.
The author decided to show that if he knew all but one character of his network password, he could bruteforce the missing character. To that end, he took all 256 possibilities for that character, and computed the resulting keys. Then tried connecting with those keys.
This shows a connection rate of 30 attempts/2 minutes which is 0.25/second. That is not practical for most attacks.
- macrael 15y agoIs there any reason the attacker would know all but one character? This seems pretty silly.
- daeken 15y agoThe way my cable modem is set up, there are only 16 bits of the WPA key that aren't shared with the MAC address in an obvious way. Because of the configuration, it's impossible for me to change this. So anyone with this knowledge can break into my network by changing two characters -- pretty trivial.
- notphilatall 15y agoWho on earth do you have service with that doesn't let you set your own WIFI password?
- mnutt 15y agoI don't know who he has, but Time Warner does this in NYC. You have zero control over the configuration of the modem/router.
- moe 15y agoSounds like a great defense in a file sharing lawsuit. "Sorry, but I really have no idea how many people used my Wifi!"
- notphilatall 15y agoBut Time Warner will know it was just you :)
- daeken 15y agoTime Warner Wideband. I work around it by having a router behind the modem which firewalls off the rest of the network -- I treat the modem's side as completely untrusted. Not perfect, but it works.
- deleted 15y ago[deleted]