R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

McAfee repeats Wifi security warning

WPA vulnerable unless you take care, insists security firm after accusations of scaremongering

Marc Delehanty, Personal Computer World 09 Aug 2006
ADVERTISEMENT

Security firm McAfee has repeated a warning about weaknesses in the highest level of Wifi security dispite accusations of scaremongering.

The company warned that home and professional users to move away from the older WEP encryption and use the newer WPA technology. WPA is less vulnerable than WEP to being cracked by running eavesdropped network traffic through a mathematical algorithm.

But even WPA can be broken if only a simple password is used, warned Ken Baylor, of McAfee's Foundation division.

Some web discussion following our original story implied that McAfee was talking up the problem to boost business.

But Baylor insisted that the threat is real. He explained: 'WPA eavesdropping is possible and is easy. The hard part is "cracking" what you have captured.'
Ordinarily a network can detect that it's being subjected to a brute-force attack - that is, when a hacker tries every possible password - and will shut out the would-be intruder.

WPA can be cracked if a hacker eavesdrops when a computer connects to the network, which is when the pre-shared key is broadcast.

A hacker who intercepts this can run a brute force 'dictionary' attack on the key offline, when the target network cannot detect it, and return to gain access if the key is cracked.

But this is only practical when simple passwords are used. Strong passwords, which may include numbers, some punctuation, and upper and lower-case letters are very very to crack by brute force.

Foundstone is currently promoting awareness of network security issues, often neglected by home users more concerned with viruses, spyware and spam.


All Wireless Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Required: Software Engineering/ and or Support Engineer experience, Java, OO My client is leaders in supplying cutting edge trading software solutions for a number of high profile clients. Currently they require a talented Application Support ... more >
| Computer People
Leading IT Company seeks a talented Senior Software Developer / Team Leader to be based in North West Hampshire, near Aldershot. You will work on all areas of the development lifecycle as part of an ... more >
| Computer People
Recognised internationally as a leading defence systems software engineering house our client seeks a C Windows Software Engineer. This role will also involve some low level development and hardware interfacing work with Serial Comms. You ... more >
| Aston Carter
Front to Back, Senior Business Analyst required by leading Investment Bank with strong OTC Derivatives, Credit Derivatives and Hybrids business knowledge to deliver a strategic front to back programme of work from capture, analysis of ... more >
More job opportunities