« Dongle Upgrade Incentives | Main | What happened to Low-Power and High Speed Bluetooth? »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451c34f69e2010535ed6863970b

Listed below are links to weblogs that reference WPA Insecurities:

Comments

Edson

Martin,
Please take a look at SecurityNow episode #170 (http://www.grc.com/securitynow ) Steve Gibson explanation about this "hack" makes it clear that we are overestimating this issue. BTW, TKIP stands for Temporal Key Integrity Protocol.
Cheers,

Edson

mobilesociety

Hi Edson,

Thanks for commenting. The link you provided looks interesting, I'll listen to the podcast over the weekend.

Thanks also for the TKIP tip, indeed a mistake on my part. I've corrected it above.

Best regards,
Martin

mobilesociety

Hello all,

Edson's tip has been very useful and I had to change my post after listening to the podcast and reading the paper again. In the original article, I stated that the attack allowed to decrypt the data flow from the access point to a client. However, that is not correct, as it is only possible to decrypt a single ARP packet and then use the knowledge to send up to 7 short packets to the client. This is less severe than what I have understood originally.

I have 'striked through' the original passages which were wrong and inserted some more text to correct my mistake and to make things more clear. Sorry for the initial false information.

Martin

The comments to this entry are closed.

My Photo

The Books to this Blog

My Pictures on Flickr

  • www.flickr.com
    martin.sauter's photos More of martin.sauter's photos

Android Cell Logger App

Misc

  • Clicky
    Clicky Web Analytics