Advertisement
Promo

Security threats Toolkit

Wireless networks lure hackers

Published: 13 Jul 2001 09:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new way to attack wireless networks underscores the lack of security for PC owners using the airwaves to connect their computers, said security experts speaking at the Black Hat Briefings conference.

On Thursday, Tim Newsham, a researcher for security firm @Stake, presented the details of weaknesses in the password system of wireless networks that could lead to a break in security in less than 30 seconds. The flaw is the third to be uncovered in the so-called Wired Equivalent Privacy, or WEP, protocol that supposedly secures wireless networks.

"WEP is inherently insecure," said Newsham. "So using WEP is essentially just throwing another barrier--and a small one--in front of the attacker."

That barrier can be overcome in five to 30 seconds in certain cases, he said.

Specifically, wireless systems that rely on a 64-bit key--used in many homes and earlier hardware--can be broken in less than a minute, letting the attacker see the data beamed across the networks.

Newer 128-bit wireless LAN (local area network) cards are fairly strong. But poorly chosen passwords can still be cracked with an old technique known as a dictionary attack: Using a list of common passwords and a dictionary of words, the potential intruder can try various combinations until the password is broken.

"Either it works or it doesn't," Newsham said. "If it doesn't, you can try one of the other attacks."

Earlier at the Black Hat conference, Ian Goldberg, chief scientist for private network seller Zero Knowledge Systems, presented details on a variety of techniques for cracking the encryption of wireless networks.

"The point of a cryptographic protocol is to be able to communicate securely over an insecure medium," he said.

Using Goldberg's techniques, which he developed while earning a doctorate at the University of California at Berkeley, data on wireless networks can be modified, added or, in some cases, decrypted.

In the end, people need to understand that wireless networks are completely insecure. For the security conscious, "virtual private network" technology such as Secure Shell, known as SSH, or other encryption techniques should be used, he said.

"People need to treat wireless networks just as they do the Internet," Goldberg said. "That means using encryption technology to secure their data."

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
72 out of 116 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

homer

lets show everyone that labour has compasion[whilst there counting the votes] running upto march/april 2010...http://tinyurl.co...nus very good nb gordon brown said today on our... More

Post a comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters