8 ms·
Cracking Linksys “Encryption”
- georgemcbay 13y agoThe more things change, the more they remain the same: Back in 1995 I "cracked" Cisco's router password "encryption": https://groups.google.com/forum/#!original/comp.dcom.sys.cisco/WjuKAOQLfkI/HKJ18Osl7z4J https://groups.google.com/forum/#!original/comp.dcom.sys.cis... Strikingly similar 'security', which is extra funny as Linksys is owned by Cisco. (EDIT: Not anymore! Thanks for the correction) Back then net admins would regularly post their configuration files (with 'encrypted' passwords left intact in most cases) to usenet to get help/tips on how to better configure their routers, which was an unaddressed (by Cisco) security nightmare.
- ChuckMcM 13y agoWell not any more : http://www.bloomberg.com/news/2013-01-24/cisco-sells-linksys-home-router-unit-to-belkin.html http://www.bloomberg.com/news/2013-01-24/cisco-sells-linksys... (as Cisco sold LinkSys to Belkin) but the point is valid.
- rwg 13y agoFWIW, Cisco sold Linksys to Belkin. I guess slapping Cisco logos all over poorly-designed Linksys home networking products didn't do anything especially positive for people's perception of Cisco.
- georgemcbay 13y agoYou're right, it is Belkin now, somehow I missed this year old news!
- lstamour 13y agoWonderful. Either my WeMos will start working better or ... Since we know about previous security issues for firmware updates on WeMo, and since I had awful customer experiences with belkin.com ... Both WeMo and Linksys products are off my "buy" list from now on, until I see some serious improvements. It's a shame, really...
- chaostheory 13y agoYeah WeMo has been a disaster. Just wondering, did you replace yours? If so with what? Z-Wave?
- dangrossman 13y agoI'll take a WeMo I have to firewall from the internet any day over a Z-Wave device that responds to commands 50% of the time, and then only after 20-30 seconds. Which is exactly how all the ones I already own work. The WeMo switches always work, and always instantly.
- lstamour 13y agoYeah, I have a NAT and... I takes my chances. (Wait, don't they defeat those? Hmm.) Actually, they aren't hooked up right now, though I suppose if I were paranoid, I'd keep a second WiFi network disconnected from the net most of the time. It's a shame though that they used WiFi -- ZigBee Hue lights have worked great for me, and Bluetooth LE goes forever.
- chaostheory 13y agoThanks for the heads up on Z-Wave, but you've also just inadvertently described the WeMo product line as well, minus the ongoing security issues they'll have and a lot of times they just go offline completely until you manually reset them. Really horrible. What do you recommend then? Zigbee?
- dangrossman 13y agoI'm not sure an explicit description can't be inadvertent. I've had the WeMo switches and sensors for months; they've never needed a reset and have always responded and broadcast status changes instantly. Maybe you have a problem with the phone app? I don't use it. They speak UPnP, so I use that from a node.js server. http://i.imgur.com/aYOaB1e.jpg http://i.imgur.com/aYOaB1e.jpg I have no problem with connected devices using WiFi. I'd rather talk to them directly over TCP than have to use some hub to bridge different networks.
- obitoo 13y agoNot to mention the complete lack of customer support
- acqq 13y agoI don't understand why the author claims "This is truly atrocious." It doesn't matter much which algorithm is used, every one that is used for the given purpose and given circumstances can be reversed, it's just a question of invested time. Who needs it would do it, and the following publication would make his results usable to others no matter the algorithm.
- drdaeman 13y agoI don't see the point in encrypting configuration data (IPs, firewall rules etc.) from the beginning. Although, keeping password in plain text is a stupid idea, but we have hashing for that, encrypting or obfuscating passwords is pointless.
- 0x0 13y agoWouldn't a wifi access point need to access the wpa password in plaintext in order to actually implement the wpa protocol?
- smtddr 13y agosmtddr@POKEMONGYM:~$ wpa_passphrase My_AP_SSID mysup3rs3cr3tp@ssw0rd network={ ssid="My_AP_SSID" #psk="mysup3rs3cr3tp@ssw0rd" psk=a6356f17ad3bb0f18385a0faa57d10c20352b977411e636c5466f933bb415fdd } smtddr@POKEMONGYM:~$ Note that the #psk line with the plain password is commented out, so it could be removed. How exactly this works though; why can that hash be used to login.... I have no idea whatsoever. Maybe it's not a hash. I'd love for someone to explain.
- raverbashing 13y agoWPA uses PBKDF2 so that's probably how it gets to that value
- dlgeek 13y agoFirst let me explain the relationship between the first and second values. For authentcation, passphrases are used because they're a lot easier for humans to remember than 256 bit hex strings. The WPA2 standard (IEEE 802.11i) defines the passphrase to PSK derivation as "PSK = PBKDF2(PassPhrase, ssid, ssidLength, 4096, 256)" (PBKDF2 is a hashing-based key derivation function, in this case using SHA1). So, this takes us from a password to a key. Now how do we auth to the router? In WPA2, there's a master-key (known as the "pairwise master key" or PMK) which is known by both the client and the access point. This key (the PMK) is then used in a 4-way hand-shake and key negotiation that allows each party to establish that the other has knowledge of the key. This key is either handled via a complex authorization mechanism like radius (WPA-EPA) or is simply shared between all the parties (WPA-PSK). In this case, the pre-shared key ("PSK") that we derived above is used directly as the PMK to complete the 4-way handshake.
- deleted 13y ago[deleted]
- userbinator 13y agoThat's not even XOR, that's NOT! The problem is not using XOR in itself, since virtually all good crypto is based on it; it's what the XOR'ing is with.
- nitrogen 13y agoTo make it even clearer, bitwise XOR with 0xFF is equivalent to bitwise NOT.
- deleted 13y ago[deleted]