McAfee repeats Wifi security warning

WPA vulnerable unless you take care, insists security firm after accusations of scaremongering

Written by Marc Delehanty

Security firm McAfee has repeated a warning about weaknesses in the highest level of Wifi security dispite accusations of scaremongering.

The company warned that home and professional users to move away from the older WEP encryption and use the newer WPA technology. WPA is less vulnerable than WEP to being cracked by running eavesdropped network traffic through a mathematical algorithm.

But even WPA can be broken if only a simple password is used, warned Ken Baylor, of McAfee's Foundation division.

Some web discussion following our original story implied that McAfee was talking up the problem to boost business.

But Baylor insisted that the threat is real. He explained: 'WPA eavesdropping is possible and is easy. The hard part is "cracking" what you have captured.'
Ordinarily a network can detect that it's being subjected to a brute-force attack - that is, when a hacker tries every possible password - and will shut out the would-be intruder.

WPA can be cracked if a hacker eavesdrops when a computer connects to the network, which is when the pre-shared key is broadcast.

A hacker who intercepts this can run a brute force 'dictionary' attack on the key offline, when the target network cannot detect it, and return to gain access if the key is cracked.

But this is only practical when simple passwords are used. Strong passwords, which may include numbers, some punctuation, and upper and lower-case letters are very very to crack by brute force.

Foundstone is currently promoting awareness of network security issues, often neglected by home users more concerned with viruses, spyware and spam.

See also:

reader comments

related articles

 

Hackers issue BT Home Hub warning

Popular wireless router 'easily cracked' 17 Apr 2008

Google used as password cracker

Hashed passwords fall prey to search engine 23 Nov 2007

Security expert slams PCI auditing

PCI compliance does not guarantee security 04 Apr 2008

latest news

Resellers hit by delivery disruption as Amtrak fails

UK courier company Amtrak has entered receivership due to financial difficulty 29 Aug 2008

Dell’s profits plunge 17 per cent

PC vendor's net profit takes a tumble as turf war with HP in EMEA hurts bottom line 29 Aug 2008

Avnet upgrades and expands Bracknell demo centre

Distributor refurbishes five-year-old centre to provide vastly expanded proof-of-concept opportunities 29 Aug 2008

poll

A new Linksys era?

A new Linksys era?

Will the Linksys brand fizzle out when Cisco folds it into its SME operation?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories