The Web is buzzing this afternoon with news that WPA has been cracked. While we’ve known for some time that WPA and even WPA2 are susceptible to dictionary attacks (duh), this appears to be a new technique. While I’m going to wait to see a little more info on this crack before recommending that everyone panic, any news like this should be taken seriously until the whole story is known – and possibly after that as well.
I have recommended for some time that good WLAN security practice include the use of either WPA or WPA2, a VPN, encryption of sensitive data wherever it is stored, and strong authentication, ideally two-factor, with no access to data or the network allowed unless and until the user authenticates. If you’re using this approach, a vulnerability in WPA is relatively minor in importance.
But since all new adapters and APs now include WPA2, it might be a good idea to cut over to that if you’ve not already. As I’ve said for some time now, absolute security is an abstract, theoretical concept, but WPA2, based on AES, is totally different from WPA and much more secure. A crack of WPA2 might thus in fact be worthy of the Nobel Prize in Hacking – but I’m not expecting the folks in Stockholm to be awarding that any time soon.




