Forwarded conversation
Subject: [Full-disclosure] WiFi is no longer a viable secure connection
------------------------

From: *Ivan .* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 5:48 AM
To: Full-Disclosure mailing list <[EMAIL PROTECTED]>


Global Secure Systems has said that a Russian's firm's use of the latest
NVidia graphics cards to accelerate WiFi 'password recovery' times by up to
an astonishing 10,000 per cent proves that WiFi's WPA and WPA2 encryption
systems are no longer enough to protect wireless data.

http://www.scmagazineuk.com/WiFi-is-no-longer-a-viable-secure-connection/article/119294/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

----------
From: *Cedric Blancher* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 6:21 AM
To: "Ivan ." <[EMAIL PROTECTED]>
Cc: Full-Disclosure mailing list <[EMAIL PROTECTED]>


Le samedi 11 octobre 2008 à 11:03 +1100, Ivan . a écrit :
No kinding ?! 100 times what a CPU can do[1] ?! Whaooo.

But what are they referring to saying "up to 100 times faster than by
using CPU only" ? We don't know. On, fast CPU, Aircrack cracking speed
can go up to around 650/700 psk/s. By 100, it means 65k/70k psk/s. Let's
round it to 100k psk/s.

Now, do the maths. A PSK is a least 8 ASCII printable chars between
codes 32 and 126. I let you figure how much time you will need to cover
the minimum length (8 chars) key space.

We covered the subject at BA-Con. We can reach 12k psk/s on a single
GTX280 alone[2]. That's only a factor 5 to 6 behind, without any
brilliant optimisation.

I don't see any breakthrough here that could make WPA/WPA2 PSK
inefficient. Really. Need something like a real crypto attack, or real
computation power boost, like reaching 10M/s.


[1] http://www.elcomsoft.com/news/268.html
[2] http://sid.rstack.org/pres/0810_BACon_WPA2_en.pdf

--
http://sid.rstack.org/
PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
>> Hi! I'm your friendly neighbourhood signature virus.
>> Copy me to your signature file and help me spread!

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

----------
From: *line* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 8:20 AM
To: Cedric Blancher <[EMAIL PROTECTED]>
Cc: Full-Disclosure mailing list <[EMAIL PROTECTED]>


I especially liked the fact that the tool in question is fairly priced.

  1. Up to 20 clients      -      $599
  2. Up to 100 clients      -      $1,199
  3. Up to 500 clients      -      $2,399
  4. Up to 2500 clients      -      $4,999
  5. 2500+ clients      -      contact us

----------
From: ** <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 8:50 AM
To: Cedric Blancher <[EMAIL PROTECTED]>
Cc: Full-Disclosure mailing list <[EMAIL PROTECTED]>


On Sat, 11 Oct 2008 02:36:15 +0200, Cedric Blancher said:

If we have this:
and this:
You only need a botnet of several hundred gamer's boxes and you're at 10M.

You probably want to program your botnet to only be running full speed when
the guy isn't gaming, you don't wanna wreck his FPS and make him suspicious.
;)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

----------
From: *Cedric Blancher* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 9:18 AM
To: [EMAIL PROTECTED]
Cc: Full-Disclosure mailing list <[EMAIL PROTECTED]>


Le vendredi 10 octobre 2008 à 23:05 -0400, [EMAIL PROTECTED] a
écrit :
Sure. But one question remains: is it worth it ? Using a botnet to crack
John Doe's PSK where you can just push password stealing malware on his
box ?

My problem with this kind of "announce" is that it seems to make people
believe that cracking WPA/WPA2 is easy, just like WEP. But it is not,
and really far from it. Maybe, or likely, some day, not that far away,
someone will come up with a crypto or implementation flaw that will
crush them down, but right now, it is not the case.

So we stuck to a password guessing game. A game we play for years, with
password hashing algorithms that we are *way* more efficient at cracking
than a PBKDF2.

I don't say we can't break PSK. I say that we suck at it with current
implementations, even with a x100 performance increase.

----------
From: *Anshuman G* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 9:23 AM
To: [EMAIL PROTECTED]




---------- Forwarded message ----------
From: Anshuman G <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 9:08 AM
Subject: Re: [Full-disclosure] WiFi is no longer a viable secure connection
To: Cedric Blancher <[EMAIL PROTECTED]>


Hello,

I have turned off SSID broadcast and its pretty obscure, the password is
obscure too, its WPA personal, i think its impossible to crack/get in my
router without knowing SSID :D .

Regards,
Anshuman Gholap
System Administrator.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

----------
From: *Cedric Blancher* <[EMAIL PROTECTED]>
Date: Sat, Oct 11, 2008 at 9:35 AM
To: Anshuman G <[EMAIL PROTECTED]>
Cc: [EMAIL PROTECTED]


Le samedi 11 octobre 2008 à 09:08 +0530, Anshuman G a écrit :
But your SSID is very easy to retrieve, as it is leaked every time you
associate a legitimate box to your wlan... And guess what: the regular
process of cracking a WPA PSK implies disassociating a client to sniff
the 4-way handshake. Doing this, the attacker will also sniff SSID
cleartext in the air.

Which means: *do not* rely on SSID cloaking for your security.


--------------------------------------------------------------------------

http://groups.google.com/group/Intelligence-Studies
************************************************************

--~--~---------~--~----~------------~-------~--~----~
FOSS Nepal mailing list: [email protected]
http://groups.google.com/group/foss-nepal
To unsubscribe, e-mail: [EMAIL PROTECTED]

Community website: http://www.fossnepal.org/
-~----------~----~----~----~------~----~------~--~---

Attachment: pgpssYhBMvNLx.pgp
Description: PGP signature

Reply via email to