|
|
Log in / Subscribe / Register

Security quotes of the week

Multiple protocols are used to generate a secure encryption key for a Wi-Fi network. We already knew that most common one, the Wi-Fi password, is insecure against a nearby attacker. A proximate attacker can listen for the "handshake,"–the agreement process between the access point and the client. Then, the attacker can use that information to launch a "brute force" attack, trying as many passwords as necessary until a check against the captured information shows the guess is correct.

So unless your Wi-Fi password looks something like a cat's hairball (e.g. ":SNEIufeli7rc"–which is not guessable with a few million tries by a computer), a local attacker had the capability to determine the password, decrypt all the traffic, and join the network before KRACK.

Nicholas Weaver

But the situation is critical. The Internet is dangerous -- and the IoT gives it not just eyes and ears, but also hands and feet. Security vulnerabilities, exploits, and attacks that once affected only bits and bytes now affect flesh and blood.

Markets, as we've repeatedly learned over the past century, are terrible mechanisms for improving the safety of products and services. It was true for automobile, food, restaurant, airplane, fire, and financial-instrument safety. The reasons are complicated, but basically, sellers don't compete on safety features because buyers can't efficiently differentiate products based on safety considerations. The race-to-the-bottom mechanism that markets use to minimize prices also minimizes quality. Without government intervention, the IoT remains dangerously insecure.

Bruce Schneier

to post comments

That's some great security advice from Nicholas

Posted Oct 26, 2017 21:47 UTC (Thu) by HelloWorld (guest, #56129) [Link]

From now on, I'll only ever use :SNEIufeli7rc as my WiFi password.


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds