Search
Search internet.com
News Reviews Insights Tutorials WiMax VoIP HotSpots Forums Events Products Glossary About






Subscribe Now!
Networking Daily Newsletter



More Free Newsletters


Wi-Fi Glossary
Find a Wi-Fi Term

Wi-Fi® is a registered certification mark of the Wi-Fi Alliance




Local Guides


internet.commerce
Be a Commerce Partner
















internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers


>> Wi-Fi Planet Marketplace
Be a Marketplace Partner


80211Planet.com news


WEP: Cracked in 60 Seconds
By Eric Griffith

April 9, 2007

It's no secret that wired equivalent privacy (WEP) (define)is considered the biggest joke in security since those guys in the red shirts on Star Trek. Last week, the joke got even funnier when researchers managed to crack 104-bit (define)WEP encryption in less than a minute.

With the right tools and some time, anyone can crack WEP by gathering enough information from the airwaves, which is then used to figure out the pass-phrase protecting the wireless link. The more packets (define)gathered, the better the chance of success. Traditionally, though, the packet gathering still took time -- sometimes hours to get the 4 to 6 million packets needed. Later, that was reduced: 500,000 to 2 million packets.

Researchers at the Darmstadt University of Technology in Darmstadt, Germany have reduced the number yet again, to just 40,000 captured packets. That gave them enough to get a 50% probability of recovering the passkey. 60,000 packets pushed the chance to 80%, and 85,000 made it 95%. They did this with a tool they call aircrack-ptw, and they wrote a paper about it, available here.

Their recommendation is pretty obvious: WEP should not be used. It's better than no security, but it's also close to no security if you've got trespassers with enough desire and smarts. As they say in the paper, "While arguably still providing a weak deterrent against casual attackers in the past, the attack presented in this paper greatly improves the ease with which the security measure can be broken." And it's true -- there are still products coming out today that only support WEP, even though Wi-Fi Protected Access (WPA) officially replaced it long ago. It has been required by the Wi-Fi Alliance since 2006 for a product to be Wi-Fi Certified.

That said, companies like AirDefense say that businesses still have a lot invested in legacy WEP-only products, and in some cases -- like retail distribution centers -- it could take millions of dollars to upgrade the equipment. That's why they offer a module for their security software called WEP Cloaking, which sends out extra packets to prevent aircrack-like tools from gathering the data they need. AirDefense says it plans to stay ahead of new WEP cracking efforts, and claims it is already successful in beating this new under-60-second crack.

 

RELATED ARTICLES
Tips for Securing Your Home Router
Yoggie Gatekeeper
New Module Cloaks Crackable WEP Encryption

Tools: Email this Article View Printable Version
News Archives | 7 day summary

Add wi-fiplanet.com to your favorites
Add wi-fiplanet.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed