A security researcher by the name of
Stefan Viehböck has discovered the latest vulnerability in regards to encrypted wireless networks that allows an attacker to gain access to your network in a matter of hours.
It revolves around something called “Wi-Fi Protected Setup” or WPS, this technology ships with most home and small business routers as an easy method for devices an to connect to your wireless network.
According to the
Wi-Fi Alliance, an industry group in charge of wireless standards, WPS is “designed to ease the task of setting up and configuring security on wireless local area networks. WPS enables typical users who possess little understanding of traditional Wi-Fi configuration and security settings to automatically configure new wireless networks, add new devices and enable security.”
With acronyms such as WPA, WPA2, WEP, TKIP and AES its easy to see how the average user can get easily confused. When the Wi-Fi Alliance came up with the technology most manufactures jumped at the chance and have not only incorporated it into their modern routers but also enable it by default.
WPS has a 8 digit number printed on the side of the router which you can simply enter when connecting to the network. This is where Stefan came up with a way to use a Brute Force attach (trying all possible combinations) to gain access to this PIN.
One way to protect against this attack is to only allow so many tries in a certain period of time, however this will only slow down this type of attack and not stop it. TP-Link and Dlink routers took about 4 hours to break into, where as Netgear routers took just under 24 hours.
“The Wi-Fi alliance members were clearly opting for usability” over security, Viehböck said
Carden Computers recommends to disable this feature, use the stronger encryption of WPA2 and choose a secure password, with capitals, lower case letters with numbers and symbols.
If at all in any doubt please feel free to contact us, we can offer remote assistance and can fix these kind of security holes quickly and efficiently.