New hole in Wi-Fi encryption
Summary
In 2001 Scott Fluhrer, Itsik Mantin and Adi Shamir showed a passive attack on the Wi-Fi encryption WEP. It exploits weak keys of the RC4 stream cipher and the initialisation vector transmitted in plain text; the effort only grows linearly with the key length. heise advised always putting a further layer of protection such as a VPN on top of WEP, but not PPTP.
Ideas
- With WEP, the initialisation vector is sent along in plain text.
- Weak RC4 keys had been known since 1995.
- A passive attack remains invisible to the victim.
- Longer keys hardly help, because the effort only grows linearly.
Insights
- A method can fail because of known weaknesses in its building blocks long after they have been documented.
- When the cryptography of the transmission fails, a higher layer has to provide the protection.
Facts
- A 40-bit WEP key was said to be breakable in about a quarter of an hour.
- The WEP128 variant with a 104-bit key would have held up an attacker for only about 40 minutes.
- The attack also hit the WEP2 draft with 128-bit initialisation vectors.
References
Critique
- The times are estimates; the report does not say how much captured traffic was needed.
Remarks
- WPA followed as a replacement in 2003 and WPA2 in 2004; WEP has been considered completely broken ever since.
Recommendations
- Use at least WPA2, better WPA3, for Wi-Fi networks, and never WEP.
- Also encrypt sensitive connections end to end, independently of the wireless network.
Links to the original source and the Web Archive open in a new tab.