Showing posts with label Wireless. Show all posts
Showing posts with label Wireless. Show all posts

GPU-Accelerated Wi-Fi password cracking goes mainstream

Elcomsoft Wireless Security AuditorNo weak password can survive a GPU-accelerated password recovery attack. Last week’s released Wireless Security Auditor is prone to shorter the time it takes for a network administrator to pen-test the strength of the WPA/WPA2-PSK passwords used on the wireless network. Its core functionality of shortening the wireless password recovery time up to a hundred times based on the GPU used, is naturally going to empower unethical wardrivers with the ability to easily guess the no longer considered secure 8 character passwords.

What’s particularly interesting about the Wireless Security Auditor is that it attempts to accomplish the password recovery in an offline/stealth mode, instead of the noisy direct router brute forcing approach :

“Elcomsoft Wireless Security Auditor works completely in off-line, undetectable by the Wi-Fi network being probed, by analyzing a dump of network communications in order to attempt to retrieve the original WPA/WPA2-PSK passwords in plain text. Elcomsoft Wireless Security Auditor requires a valid log of wireless communications in standard tcpdumptcpdump. The tcpdumptcpdump format is supported by all commercial Wi-Fi sniffers. In order to audit your wireless network, at least one handshake packet must be present in the tcpdump file.”

Meanwhile, pen-testing companies have once again urged IT managers and end users to go beyond the 8 character password strength myth, and anticipate the risks posed by the increasingly efficient password recovery solutions hitting the market :

“David Hobson said: “It’s a wake-up call to IT managers, pure and simple. IT managers should now move to 12 and even 16 character keys as a matter of urgency. It’s not very user-friendly, but the potential consequences of staying with eight character keys do not bear thinking about.”

As previously discussed, best practices wake-up calls remains largely ignored prompting radical solutions in countries like India for instance, which recently announced that a Wardriving police unit will be locating insecure wireless networks and notifying the owners in order to “prevent the commission of a cognizable offense”.

[Source: zdnet]

Apple looking to hire iPhone hacker

Apple looking to hire iPhone hacker Apple is in the market for someone capable of hacking into the iPhone.

According to this job listing, the company is looking for an iPhone Security Engineer capable of, among other things, developing “proof of concept” attacks on the device’s current security mechanisms.

The successful candidate will be tasked primarily with validating the security architecture for the iPhone.

Some responsibilities:

  • Review and provide feedback on security mechanisms implemented in OS X
  • Provide risk analysis of potential security threats to our embedded products
  • Develop “proof of concept” attacks on the current security mechanisms
  • Come up with new and innovative ways of increasing security while preserving ease-of-use and increasing the quality of the end-user experience.
  • Work cooperatively with other parts of CoreOS on cross-functional technologies and initiatives to enhance security and security policies

[ SEE: Apple caught neglecting iPhone security ]

This moves comes amidst news that the latest versions of iPhone are vulnerable to vulnerabilities that could aid phishing and spamming attacks.

Apple has also been criticized in the past for inordinate delays in shipping iPhone patches, a problem caused mostly because Apple’s agreement with carriers require every minor release is reviewed and approved, a mind-numbingly slow/exhaustive process.

* Photo credit: quinn.anya’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]