Newsletters Welcome, Guest Log In | Register

SMB Tech

Expert tech insight and advice for small businesses with big goals

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Time to Switch over to WPA2

Posted by Paul Mah Nov 12, 2008 11:06:45 AM

Just when you thought WPA was the perfect solution for your company's wireless network comes news of game-changing research. It appears that two researchers from the Technical University of Darmstadt in Germany have managed to exploit a weakness in the Temporal Key Integrity Protocol (TKIP) used by the Wi-Fi Protected Access (WPA) encryption standard. The duo used a number of clever tricks and a revolutionary mathematical method to correctly decrypt a very limited number of TKIP protected data packets. Additional information will probably come to the fore at the researchers' scheduled presentation at the PacSec conference in Tokyo later this week. Because of the extremely limited data that can be uncovered, WPA is still not considered to be "compromised" at this point; you can read more about the mechanics of the hack here.

 

In addition, there are a number of technical tweaks that you can do to reduce the chances of an attack succeeding against a WPA-based wireless network. Indeed, simply switching to AES - instead of TKIP - will result in immunity against this new vector. The initial feedback from security analysts is that this attack vector is probably something that can be fixed with new drivers.

 

However, the worrying aspect has to be the fact that limited packet injection is now possible on vulnerable systems. The surreptitious insertion of such data packets could potentially result in the installation and execution of exploit tools, which in turn could allow hackers to gain access to computers connected to the wireless network.

 

So assuming your hardware already supports WPA2, now would be as good a time as any to switch over to that. Organizations considering a wireless setup will also probably want to start on the get-go with wireless base stations that support WPA2.

 

I'm sure more practical recommendations and tips will surface once other security researchers have time to delve into this new vulnerability. I'll be sure to get back to you when that happens.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Data Deduplication

Data manipulation strategies that make data stores more manageable and reduce the need for storage capacity and its associated costs.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Laptop Security

Answers to the ongoing challenges of the mobile office: to work anywhere, securely and efficiently.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

IT Manager Development Library

Learn all the basics of IT Management: budgeting, staff motivation, business planning and more with this unique eBook bundle.

Learn more >

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >