Gongalong Posted July 3, 2013 Posted July 3, 2013 Hi All, I've setup a test SSID with a 504 bit WPA passphrase, in the belief that (a) this is as strong as they get and (b) this makes it as difficult as possible to hack. Are there any downsides to using such a high strength passphrase e.g. (and forgive my naivety) would it make the connection slower? I'm checking ahead of deploying this in a wider environment. TIA
chazzy2501 Posted July 3, 2013 Posted July 3, 2013 connection speed no, just a pain to enter on mobile devices... 1
plexer Posted July 3, 2013 Posted July 3, 2013 If you are deploying this to an enterprise then you're using the wrong security method really. Ben 1
plexer Posted July 3, 2013 Posted July 3, 2013 also make the SSID very long and random Why? the ssid is broadcast and hiding it is no security. Ben
Michael Posted July 3, 2013 Posted July 3, 2013 The passphrase has no bearing on connection speeds, but as above, it'll be a pain for manual configurations. It's more important to focus on the security features of the passphrase including capitals, numbers, random characters and with a length of 8 characters or more. WPA2-PSK AES is the strongest and is highly recommended. 1
Michael Posted July 3, 2013 Posted July 3, 2013 I think if security has to be incredibly high, making the SSID hidden, applying mac address filtering, along with what I wrote above is as strong as it gets. Alternatively ditch wireless and use Ethernet all round 2
plexer Posted July 3, 2013 Posted July 3, 2013 But even with Ethernet you're looking at encryption and port security to make that secure. Ben 1
ConradJones Posted July 3, 2013 Posted July 3, 2013 Why? the ssid is broadcast and hiding it is no security. because the encrytion uses the SSID name together with the passkey. the more unique and long both of them are more processor time it takes to crack and much less likely that the "basic rainbow tables" pack includes your SSID and Passkey.
chazzy2501 Posted July 3, 2013 Posted July 3, 2013 if I were a bank I'd do all of the above but I think a long wpa key is enough. having tried to hack my own wifi I can say it's too bloomin difficult to hack a simple key let alone a huge one. far easier to steal a laptop or login.
ConradJones Posted July 3, 2013 Posted July 3, 2013 if I were a bank I'd do all of the above but I think a long wpa key is enough. having tried to hack my own wifi I can say it's too bloomin difficult to hack a simple key let alone a huge one. far easier to steal a laptop or login. WEP is incredibly easy.
chazzy2501 Posted July 3, 2013 Posted July 3, 2013 WEP is incredibly easy. yes I tried that it took 5 mins nice turn key app. wpa is way more involved
ConradJones Posted July 3, 2013 Posted July 3, 2013 yes I tried that it took 5 mins nice turn key app. wpa is way more involved agreed, and expensive.
paulfinlay Posted July 8, 2013 Posted July 8, 2013 The longer, and more random, the key the better, but generally 20 ascii characters is enough to make it very difficult to crack. If you really need security you want to look at using 802.1x which ultimately gives each wireless client a dynamic unique encryption key per session.
m25man Posted July 17, 2013 Posted July 17, 2013 Ok so you introduce your ridiculously hard to manage WPA passphrase that whilst it may be hard to crack OTA it can normally be defeated in a few seconds if a savvy user has physical access to a device using it? In most cases just revealing the text of the passphrase is a single mouse click or device tap, which in my mind defeats the object? WirelessKeyView: Recover lost WEP/WPA key/password stored by Wireless Zero Configuration service There are tools out there and scripts to simply retrieve it from a currently logged in user session and email it back to the would be attacker. Don't forget the key here is physical access. Remember the passphrase only controls the encryption of the initial associations between client and network after which the encryption key is changing constantly and automatically controlled by your wireless hardware. Once you have successfully joined a network the encryption is handled for you and virtually impossible to decipher as is. To compromise the system the attacker only has to join the same network as the target. Once joined, with no other barriers in place they own your system. As has been stated so many times before WEP/WPA/WPA2 were not designed to be your primary means of network access control. Yes make it strong enough to prevent occasional users and passers by to not want to waste their time trying or get into a situation where they may get associated to your wifi and be able to capture packet data as it passes OTA. It should definitely NOT be used as the only way to control access to your network no matter how many bits you are using. You need to use a secondary method of access control. Once initial passphrase has been exchanged use NAC or Radius methods to authorise the device. WPA whilst an essential stage of the entire wireless process is going to be a cumbersome method of control and your efforts would be better spent deploying a secondary security layer. Sure at Home on your BT-Home hub protecting yourself from your neighbours a half decent WPA policy may be all you need to deter all but the most determined, but in some ways that complacency is also the weakness. You are a sitting target with all the time in the world to be hacked. At some point all of my neighbours will have had their WPA keys compromised, their networks examined and in some cases their dubious video collections browsed. In fact when you think about it, if WPA/WPA2 is your only means of network security you would need to be changing it on a regular basis!
tech_guy Posted July 17, 2013 Posted July 17, 2013 You'd be surprised as to how many individuals and organisations are still using WEP, or scarily, in some cases - no encryption at all. In my home town when I'm out and about I usually find one or two with my netbook when I'm bored.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now