bk99.de entertain the web since 1997

Insecure factory settings in Wi-Fi routers from T-Online and Vodafone

Summary

In 2011 many routers from Telekom and Vodafone came with a preconfigured WPA key that was in some cases derived from the MAC address of the Wi-Fi interface. Attackers could capture the MAC address and use it to guess the key. Looking at almost 14,000 access points, the students Stefan Viehböck and Manuel Müller found that 17 to 25 percent still used a default Speedport or EasyBox SSID, presumably mostly with the default key.

Ideas

  • A key calculated from publicly visible data is not a secret.
  • The MAC address of an access point can be captured over the air.
  • An unchanged default SSID suggests an unchanged default configuration.
  • Strong encryption is useless if the key is predictable.

Insights

  • Manufacturer defaults determine the security of millions of connections.
  • Apparent security through enabled encryption tempts users not to change anything.

Facts

  • Access points in Stuttgart, Munich, Coburg and Berlin were examined.
  • Telekom’s Speedport models and Vodafone’s EasyBox models were affected.

References

Critique

  • The share of vulnerable routers is only inferred from the default SSIDs, not measured.

Recommendations

  • Replace preset Wi-Fi keys with your own randomly generated key.
  • Also change the default SSID so that model and configuration cannot be recognised.

Read the original article

Search the Web Archive