TCPmag.com for Cisco Internetworking Professionals Thursday, September 02, 2010  
Search:
Advanced Search        
-- advertisement --
  Resources
  Articles
  Community
.. Home .. News .. Article


 
print article printable format
e-mail article e-mail to a friend
comment on the newscomment on news


More News
read... At (Long) Last: WiMAX Has Arrived?
read... Cisco, VMWare and NetApp Once Again Reach for the Clouds
read... IPv4 Addresses Could Dry Up by Year's End
read... Cisco Sitting Pretty in High-Flying SBC Segment
read... WLAN Set to Soar in the Enterprise
 

News

Analysts Push WPA2 Migration After Security Concerns

11/11/08 — Don't look now, but Wi-Fi Protected Access (WPA), the gold standard for wireless security, might not be so secure. At the PacSec 2008 Conference, held this week in Tokyo, a group of researchers is expected to demonstrate a way to partially crack WPA-encrypted traffic.

Since at least 2004, WPA has been the preferred alternative to the Wired Equivalency Protocol (WEP), an insecure encryption mechanism that's still used by many consumer devices. But WPA -- in spite of a spate of theoretical vulnerabilities -- has been perceived as practically impregnable. Not anymore.

Industry giant Gartner Inc., for one, urged customers to take action. Even in the absence of a verified proof-of-concept -- much less a bona-fide WPA-cracking-exploit -- organizations need to seriously think about shifting away from WPA and toward its successor, WPA2, Gartner said.

-- advertisement (article continued below) --

For one thing, Gartner analysts John Pescatore and John Girard wrote, it's been a long time coming. "Reports of this new crack are not surprising, and in fact represent the normal cycle of security solutions becoming vulnerable over time," they wrote, noting that "WPA has long been known to be theoretically vulnerable to 'dictionary attacks,' which require massive computational resources not available to most hackers and so are not a serious threat."

The new attack, on the other hand, doesn't require any special resources. It exploits a vulnerability in WPA's Temporal Key Integrity Protocol (TKIP), with the result (sources say) that an attacker can actually crack the TKIP key. This could enable them to read, and perhaps even change, data as it's sent between a wireless access point and client devices.

The upshot, Pescatore and Girard stressed, is that it's time to make the switch to WPA2. "Wherever possible, migrate WLANs from WPA to WPA2. If this is not feasible, use installed WLAN intrusion prevention systems...to monitor WPA usage and detect attempts to compromise TKIP," they wrote. "If no migration to WPA2 is planned and no form of WLAN monitoring is in place, ensure that vulnerable access points are not used in public areas." --Stephen Swoyer

Current TCPmag.com user comments for "Analysts Push WPA2 Migration After Security Concerns"
No postings yet.
Post your comment about " Analysts Push WPA2 Migration After Security Concerns" here:
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comments:  
 
top







home | certification basics | features | exams | exam reviews | salary surveys
forums | link state update | news | q & a | article archive | tech library webcasts | Rss Feeds from TCPmag.com
Application Development Trends | Campus Technology | CertCities.com | The Data Warehousing Institute
E-Gov | EduHound | ENTmag.com | Enterprise Systems | Federal Computer Week | FTPOnline.com | Government Health IT
IT Compliance Institute | MCPmag.com | Recharger | Redmond Developer News | Redmond
Redmond Channel Partner | Redmond Events | Redmond Report | T.H.E. Journal | TechMentor Conferences
Virtualization Review | Visual Studio Magazine | VSLive!
Free Print or Digital Subscriptions: Redmond | Redmond Channel Partner | Redmond Developer News
Virtualization Review | Visual Studio Magazine
Copyright 1996-2009 1105 Media, Inc. See our Privacy Policy.
1105 Redmond Media Group