3 ms·
No, it shouldn't. WPA2's 4-way handshake allows client/supplicant & access point to prove they both know the PMK without directly disclosing it: https://en.wiki
by semenko 11y ago
No, it shouldn't. WPA2's 4-way handshake allows client/supplicant & access point to prove they both know the PMK without directly disclosing it: https://en.wikipedia.org/wiki/IEEE_802.11i-2004#The_Four-Way_Handshake https://en.wikipedia.org/wiki/IEEE_802.11i-2004#The_Four-Way...
- SunboX 11y agoOh, ok. Didn't know about that, it's some time I tried it. Thanks for teaching me!
- duskwuff 11y agoI suspect you've never tried it. This technique didn't work with WEP either: open system WEP simply encrypts every packet with a key derived from the password, and shared key WEP has the client encrypt a challenge from the AP using that key and send it back. In neither case is the password ever sent over the network in any recoverable form.
- nly 11y agoThe AP doesn't prove any such thing to the client in PSK mode. If I scan your house, and write down your AP SSID and BSSID, I can later follow you to a coffee shop, spoof your home AP, get your device to connect, and then glean enough key derived material to go away and bruteforce your password. What you can't do, afaik, is the opposite (coax an AP to give up key derived material)... of course many APs have their own problems. By modern standards the authentication protocol used in WPA2-PSK is dire. You should use long random keys (something like 9oc46NLMbq7ujAEgXcQU), anything dictionary based puts you at real risk.