Doh! First serious crack in WPA encryption appears

Thu Nov 6, 2008 11:43AM EST

See Comments (2)

Researchers claim that they managed to crack WPA Wi-Fi encryption in about 15 minutes, and they plan to show the world how they did it next week. Better get your WPA2 encryption settings warmed up.

Up to now, the only real way to crack WPA was through a "dictionary" attack—a time-consuming, brute-force method that calls for plowing through an "extremely large number" of permutations to find the right encryption key, PC World notes.

But according to the PC World story, researchers Erik Twes and Martin Beck say they've developed a "mathematical breakthrough" that helped them crack WPA encryption in just 12 and 15 minutes. The researchers say they'll divulge more details next week at a conference in Tokyo and in a report later this month.

Now, we're only talking a partial hack here, according to PC World, which notes that the new attack only compromises data sent from a router to a laptop, not the other way around.

Still, the attack—partial though it is—could well mark the beginning of the end for WPA as a reliable Wi-Fi security measure.

So, what to do? For now, most casual Wi-Fi users are probably fine sticking with WPA for now—hey, it's still far more secure than WEP encryption, which is crackable in just a matter of seconds.

But if you're more serious about wireless security, consider bumping your router encryption up to the next line of defense: WPA2, which (according to PC World) is still safe from the new attack. The only downside: Not all wireless devices (such as phones, gaming consoles, and the like) support WPA2 encryption, so you'll have to weigh your paranoia against the potential inconvenience.

Related:
Once Thought Safe, WPA Wi-Fi Encryption Is Cracked [PC World]

Comments on Doh! First serious crack in WPA encryption appears

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 1 Posted by bucksohio234 on Thu Sep 3, 2009 3:15PM EDT Report Abuse

    It would be nice if the idiots wouldn't show us how they did it......whats the point of releasing how it was done other than let criminals know how to steal peoples information!!

  • 2 Posted by alcalavic on Thu Sep 3, 2009 2:49PM EDT Report Abuse

    Thats great that they were able to crack it. Anyone with a WAP should be using WP2 encryption or be upgrading. That will open 802.11x to addditional wardriver vulnerabilities but WAP owners should be aware of this along with all the wireless hacking tools available on the web. Best defense for WPA owners, for now is turn off SSID and turn on MAC filtering.

More Posts: 1

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.