Jump to content

Recommended Posts

Posted

Hi All,

 

I've setup a test SSID with a 504 bit WPA passphrase, in the belief that (a) this is as strong as they get and (b) this makes it as difficult as possible to hack.

 

Are there any downsides to using such a high strength passphrase e.g. (and forgive my naivety) would it make the connection slower?

 

I'm checking ahead of deploying this in a wider environment.

 

TIA

Posted

The passphrase has no bearing on connection speeds, but as above, it'll be a pain for manual configurations.

 

It's more important to focus on the security features of the passphrase including capitals, numbers, random characters and with a length of 8 characters or more. WPA2-PSK AES is the strongest and is highly recommended.

  • Thanks 1
Posted
I think if security has to be incredibly high, making the SSID hidden, applying mac address filtering, along with what I wrote above is as strong as it gets. Alternatively ditch wireless and use Ethernet all round :D
  • Thanks 2
Posted
Why? the ssid is broadcast and hiding it is no security.

 

because the encrytion uses the SSID name together with the passkey. the more unique and long both of them are more processor time it takes to crack and much less likely that the "basic rainbow tables" pack includes your SSID and Passkey.

Posted
if I were a bank I'd do all of the above but I think a long wpa key is enough. having tried to hack my own wifi I can say it's too bloomin difficult to hack a simple key let alone a huge one. far easier to steal a laptop or login.
Posted
if I were a bank I'd do all of the above but I think a long wpa key is enough. having tried to hack my own wifi I can say it's too bloomin difficult to hack a simple key let alone a huge one. far easier to steal a laptop or login.

 

WEP is incredibly easy.

Posted
The longer, and more random, the key the better, but generally 20 ascii characters is enough to make it very difficult to crack. If you really need security you want to look at using 802.1x which ultimately gives each wireless client a dynamic unique encryption key per session.
  • 2 weeks later...
Posted

Ok so you introduce your ridiculously hard to manage WPA passphrase that whilst it may be hard to crack OTA it can normally be defeated in a few seconds if a savvy user has physical access to a device using it?

 

In most cases just revealing the text of the passphrase is a single mouse click or device tap, which in my mind defeats the object?

WirelessKeyView: Recover lost WEP/WPA key/password stored by Wireless Zero Configuration service

There are tools out there and scripts to simply retrieve it from a currently logged in user session and email it back to the would be attacker.

Don't forget the key here is physical access.

 

Remember the passphrase only controls the encryption of the initial associations between client and network after which the encryption key is changing constantly and automatically controlled by your wireless hardware.

Once you have successfully joined a network the encryption is handled for you and virtually impossible to decipher as is. To compromise the system the attacker only has to join the same network as the target. Once joined, with no other barriers in place they own your system.

 

As has been stated so many times before WEP/WPA/WPA2 were not designed to be your primary means of network access control.

Yes make it strong enough to prevent occasional users and passers by to not want to waste their time trying or get into a situation where they may get associated to your wifi and be able to capture packet data as it passes OTA.

 

It should definitely NOT be used as the only way to control access to your network no matter how many bits you are using. You need to use a secondary method of access control.

 

Once initial passphrase has been exchanged use NAC or Radius methods to authorise the device. WPA whilst an essential stage of the entire wireless process is going to be a cumbersome method of control and your efforts would be better spent deploying a secondary security layer.

 

Sure at Home on your BT-Home hub protecting yourself from your neighbours a half decent WPA policy may be all you need to deter all but the most determined, but in some ways that complacency is also the weakness. You are a sitting target with all the time in the world to be hacked.

 

At some point all of my neighbours will have had their WPA keys compromised, their networks examined and in some cases their dubious video collections browsed.

In fact when you think about it, if WPA/WPA2 is your only means of network security you would need to be changing it on a regular basis!

Posted
You'd be surprised as to how many individuals and organisations are still using WEP, or scarily, in some cases - no encryption at all. In my home town when I'm out and about I usually find one or two with my netbook when I'm bored.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...