Announcement

Collapse
No announcement yet.

TKIP cracked

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • TKIP cracked

    http://tech.yahoo.com/news/pcworld/2...ptioninaminute

    TKIP, one of the major algorithms offered by WPA, has been thoroughly pwned. So yeah, use WPA2/AES.
    45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B0
    45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B1
    [ redacted ]

  • #2
    Re: TKIP cracked

    eh, not so much. It allows disclosure on the MIC key which allows for injection of a few packets but does not disclose the encryption key.

    It's the Tews-Beck attack (Which is basically the WEP chopchop attack with a timer) which came out last year with a slight refinement (that seems kinda bogus) that reduces the time to inject from 12 minutes to 1 minute by offloading the CRC checks to the attacker instead of using the AP failure messages to do the work.

    It's not a new nail, just a refinement to existing attack that was more a crack in the armour than a break. Still, nice to see work continuing on breaking anything and everything.
    Never drink anything larger than your head!





    Comment


    • #3
      Re: TKIP cracked

      Okay, sorry if my initial synopsis was a bit overzealous
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B0
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B1
      [ redacted ]

      Comment


      • #4
        Re: TKIP cracked

        If you want a longer writeup, I posted an analysis of the attack to my blog. The short summary is I agree with Renderman. The attack is good work, but the practical implications of it aren't that dire.

        http://reusablesec.blogspot.com/2009...acked-yet.html

        Comment


        • #5
          Re: TKIP cracked

          Originally posted by reusablesec View Post
          If you want a longer writeup, I posted an analysis of the attack to my blog. The short summary is I agree with Renderman. The attack is good work, but the practical implications of it aren't that dire.

          http://reusablesec.blogspot.com/2009...acked-yet.html
          Well written, thanks for sharing.

          Side note: Watched your DC talk last night, really good stuff.
          Never drink anything larger than your head!





          Comment

          Working...
          X