craig mathias
Principal

Bulletin: WPA Cracked?

Opinion
Nov 6, 20082 mins

The Web is buzzing this afternoon with news that WPA has been cracked. While we’ve known for some time that WPA and even WPA2 are susceptible to dictionary attacks (duh), this appears to be a new technique. While I’m going to wait to see a little more info on this crack before recommending that everyone panic, any news like this should be taken seriously until the whole story is known – and possibly after that as well.

I have recommended for some time that good WLAN security practice include the use of either WPA or WPA2, a VPN, encryption of sensitive data wherever it is stored, and strong authentication, ideally two-factor, with no access to data or the network allowed unless and until the user authenticates. If you’re using this approach, a vulnerability in WPA is relatively minor in importance.

But since all new adapters and APs now include WPA2, it might be a good idea to cut over to that if you’ve not already. As I’ve said for some time now, absolute security is an abstract, theoretical concept, but WPA2, based on AES, is totally different from WPA and much more secure. A crack of WPA2 might thus in fact be worthy of the Nobel Prize in Hacking – but I’m not expecting the folks in Stockholm to be awarding that any time soon.

craig mathias

Craig J. Mathias is a principal with Farpoint Group, an advisory firm specializing in wireless networking and mobile computing. Founded in 1991, Farpoint Group works with technology developers, manufacturers, carriers and operators, enterprises, and the financial community. Craig is an internationally-recognized industry and technology analyst, consultant, conference speaker, author, columnist, and blogger. He regularly writes for Network World, CIO.com, and TechTarget. Craig holds an Sc.B. degree in Computer Science from Brown University, and is a member of the Society of Sigma Xi and the IEEE.

More from this author