Insecure factory settings in Wi-Fi routers from T-Online and Vodafone
Summary
In 2011 many routers from Telekom and Vodafone came with a preconfigured WPA key that was in some cases derived from the MAC address of the Wi-Fi interface. Attackers could capture the MAC address and use it to guess the key. Looking at almost 14,000 access points, the students Stefan Viehböck and Manuel Müller found that 17 to 25 percent still used a default Speedport or EasyBox SSID, presumably mostly with the default key.
Ideas
- A key calculated from publicly visible data is not a secret.
- The MAC address of an access point can be captured over the air.
- An unchanged default SSID suggests an unchanged default configuration.
- Strong encryption is useless if the key is predictable.
Insights
- Manufacturer defaults determine the security of millions of connections.
- Apparent security through enabled encryption tempts users not to change anything.
Facts
- Access points in Stuttgart, Munich, Coburg and Berlin were examined.
- Telekom’s Speedport models and Vodafone’s EasyBox models were affected.
References
Critique
- The share of vulnerable routers is only inferred from the default SSIDs, not measured.
Recommendations
- Replace preset Wi-Fi keys with your own randomly generated key.
- Also change the default SSID so that model and configuration cannot be recognised.
Links to the original source and the Web Archive open in a new tab.