ALERT: WPA-TKIP isn't secure - use WPA2 instead

SUMMARY:

WPA-PSK is vulnerable to offline attack. WPA-TKIP has been cracked.

TO AVOID THESE PROBLEMS:

  1. USE WPA-AES or WPA2 instead of WPA-TKIP (or WEP)

  1. USE A PASSPHRASE WITH MORE THAN 20 CHARACTERS. Examples: BAD: "vintage wine" GOOD: "floor hiking dirt ocean" (pick your own words, even longer is better) FOR HIGH SECURITY, USE MORE THAN 32 CHARACTERS.

BACKGROUND:

Weakness in Passphrase Choice in WPA Interface

Practical attacks against WEP and WPA

A Practical Message Falsi cation Attack on WPA

New attack cracks common Wi-Fi encryption in a minute

Passphrase Flaw Exposed in WPA Wireless Security

Cracking Wi-Fi Protected Access (WPA)

Cracking WEP and WPA Wireless Networks

Reply to
John Navas
Loading thread data ...

Why are you telling people to use dictionary based words rather than a random character string?

A random character string over 25 characters long is basically uncrackable on a home PC.

Reply to
Dr Who

character string?

And very forgettable .... I put an punctuation mark every now and then in my passphrase to make it harder to crack. :)

Reply to
Shadow

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.