[LMB] OLPC-XO1 OT:

Mark Allums mark at allums.com
Thu May 1 18:25:56 BST 2008


Franz Tomasek (Home) wrote:
> Salve
> 
> On 30/04/08 
>    at 08:35 PM, Mark Allums <mark at allums.com> said:
> 
>> WEP?   Aieeeee!!!!!  Surely you mean WPA don't you?   WEP can be cracked 
>> in about 5 minutes, now.  WPA takes a whole day.  The best bet is WPA2, 
> 
> No argument on WEP. IIRC the FBI demonstrated a three minute crack of WEP.
> (Here's a report from 2005:
> http://www.smallnetbuilder.com/content/view/24251/100/)
> 
> As far as I am aware the only ways to crack WPA involve dictionary or
> brute force attacks, so if you pick a strong passphrase it will take a lot
> longer than a day to crack.
> (http://www.smallnetbuilder.com/content/view/30278/98/)
> 
> Vale
> Franz
> 

There is a known attack for WPA Pre-Shared Key/WPA Personal.  It doesn't 
apply to the other variants, e.g. using a RADIUS server.  If I manage to 
find the paper on it, I will send you a copy.  (I printed it out, it is 
buried, don't have the original URL.)

(A dictionary attack always works, if you have a hard drive large enough 
to hold the dictionary.  For very large keys, the dictionary approaches 
the infinite in size, and the infinite in time to brute force it.  So 
use large keys.)

-- 
Mark Allums


More information about the Lois-Bujold mailing list