Monday, November 10, 2008

WPA Not Cracked, But Still Vulnerable

WPA Not Cracked, But Still Vulnerable

WPA isn’t as broken as reported: If you read the coverage early this week on two German researchers’ paper on a vulnerability in Temporal Key Integrity Protocol (TKIP), the weaker of two encryption and integrity algorithms in the Wi-Fi Protected Access (WPA) certified standard (and part of the underlying 802.11i protocol), you’d think that TKIP was broken. It’s not.

As I wrote Friday, don’t panic, but do pay attention. I’m posting about this again just to be clear.

The flaw that was discovered does not allow a WPA-protected network’s key to be recovered. It does allow short packets (network data quanta) used typically for network identification purposes to have their encryption keystream recovered: that’s the overlay of per-packet encryption derived from a key that two Wi-Fi components use to protect information sent to one another.

With a recovered keystream, a single packet of the same length can be sent back into the network (using another flaw) to fool a client (but not an access point).

That’s not to say that WPA keys (both the weaker TKIP and strong AES-CCMP) cannot be recovered. That’s just not part of this weakness.

As was theorized back in 2003, in an article Robert Moskowitz allow me to post on my site, choosing a weak passphrase could lead to a key that can be cracked through brute force. Moskowitz was part of the IEEE 802.11i security task group, and he knew of what he spoke.

His advice? For effective security, choose a passphrase that’s at least 20 characters long and contains no words found in dictionaries of any language.

Substituting 3 for e and 0 for o isn’t a good choice, by the way: Brute-force attackers build dictionaries with common substitutions. Changing “camel back liposuction” to “!cmale bc@@k lippppo___!!sction” would make much more sense. Anyway, which among us manually enters a passphrase more than once per client?

Within a couple of years, effective brute-force methods appeared that could crack shorts keys that used only words found in dictionaries. There are pre-computed dictionaries that combine the SSID (network name) and billions of short key combinations. (The network name is used as an element in creating the key, but “linksys” and other default network names are often unchanged by users. Apple names its networks by default with part of the base station identifier, making a brute-force crack probably a million, maybe a billion times harder.)

ElcomSoft recently updated their “key recovery software” to use the graphical processing unit (GPU) in modern computers, which the company said in press releases—they haven’t gotten back to a request I made for a briefing weeks ago—could improve key cracking by a factor of 100. Their software is also distributed, so you could conceivably put 1,000 computers on the task.

How does Elcomsoft’s breakthrough affect the 2003 advice on passphrases? Security experts I’ve talked to, including Erik Tews, the co-author of the paper on the new WPA flaw, said that 20 characters should still require such a vast amount of time even with all the horsepower that one could throw at it, that there’s no risk.

If there were a risk, you could increase a passphrase to 22 characters in length, and suddenly push the time to crack out by another factor of 100 (more or less; dissenting opinions welcome).

Average users can bypass all this by buying Wi-Fi gear that uses Wi-Fi Protection Setup (WPS), which uses for its source material a passphrase longer than the 20-character minimum, and employs excellent methods of securely exchanging key material over the untrusted network.

Of course, as I discovered when reviewing the excellent Linksys WRT610N (concurrent dual-band 802.11n router) for Macworld magazine, there’s surprisingly no precise standard for WPS interface implementation. That is, the Wi-Fi Alliance defines the way in which WPS works on a protocol level, but not how the details are presented to a user.

Apple has two methods neither of which match up correctly with Linksys’s three or four methods (depending on how you count). It’s frustrating. Apple never responded to a comment about the mismatch; Linksys said they’re looking in how to improve compatibility in future releases.




Mystery Illness Forces Janet Jackson to Nix More Shows
(E! Online)

Breaking News: AT&T Buys Wayport; WPA’s TKIP Cracked?; Virgin America Sets Launch Date
Janet Jackson delays 3 more shows due to illness
(AP)

Saturday, November 8, 2008

Don't Panic over WPA Flaw, But Do Pay Attention

Dont Panic over WPA Flaw, But Do Pay Attention

The flaw in WPA is minor but important, and won’t affect home users or most networks (yet): I spoke yesterday to Eric Tews, one of the co-authors of a paper covering a WPA flaw that he’ll present next week in Japan at PacSec, a security conference. Tews and his collaborator Martin Beck, who discovered and tested the flaw, found that it’s possible to use weaknesses that remain in WPA’s TKIP encryption type (the weaker of two available in WPA2) to decrypt certain data.

I wrote about this at great technical length at Ars Technica—see Battered, But Not Broken—but let me provide the high-level summary here.

The flaw is not a generic crack: it doesn’t allow a WPA key to be recovered, nor does it work on all data passing the network. The flaw only affects packets encrypted using the TKIP system, which is a backwards-compatible upgrade to 802.11’s original WEP system. It’s also only possible at this point to recover the original text for short packets—those with predictable contents that are quite short. And it requires the use of 802.11e, the Quality of Service (QoS) standard that prioritizes voice and streaming data above that of normal data to provide voice quality and avoid video and audio stuttering.

With the Tews/Beck technique, short packets with mostly predictable content can be cracked through first applying a WEP-style crack that gets an attacker most of the way there, and then using a very slow method of determining the value of the remaining unknown bytes. This allows the keystream—the cryptographic overlay used to encrypt data as it flows, not the network key itself—to be recovered and used to “replay” arbitrary data, such as a changed packet. While TKIP includes replay protection, the graduate students found that the QoS queues would let them replay the same keystream, sidestepping this protection. (Their flaw discovery is very very clever, combining the use of three interrelated protocols’ weaknesses.)

The solution for the flaw at present is to use AES, an encryption option that’s part of WPA2 (and 802.11i, the underlying standard). If your network comprises all WPA2 devices, which nearly all equipment sold starting in 2003 is capable of, then you can opt to set routers to use just the AES type. For home networks or small offices, this would mean choose WPA2-PSK or WPA2 Personal in most cases. (While Windows lets you choose to identify a WPA2 key as TKIP or AES, the router is what controls which algorithms are acceptable.)

And because the crack potentially allows only the injection of changed packets for very specific network stuff, it’s likely that you’d never see this used against a home network because there’s very little you could do with such a flaw. On a corporate network, someone might try to redirect traffic through certain kinds of short forged messages, and that could be a problem.

However, corporate networks should be using robust enough equipment that the keys used for network communication are frequently swapped out, which disrupts this crack; and corporations may already have standardized on WPA2’s AES, which is immune to any attack of this kind.

In the end, you should be wary, but not freaked out. Switching to AES has a price: older computers won’t be able to join your network. But in 2008, the odds are increasingly low that anyone concerned about security would have a Wi-Fi adapter so old that it couldn’t use WPA2.




Breaking News: AT&T Buys Wayport; WPA’s TKIP Cracked?; Virgin America Sets Launch Date
Positive Response to WiMax Launch in Baltimore
Busta Banned in the U.K.?
(E! Online)

Country star Tim McGraw rips label over hits CD
(Reuters)

Wayport Acquisition Puts AT&T at Top; Boingo Still Has Leverage

Wayport acquisition by AT&T makes me go whoompf: Yesterday’s announcement that AT&T would purchase hotspot operator Wayport for $275m in cash gave me pause for reflection. I started covering the Wi-Fi field in late 2000, spurred by testing Apple’s AirPort system, which, despite being on the market for a year, I was quite dubious about. It worked well, and it led me to find that Wi-Fi was being deployed as an amenity. I hopped on the story, and wrote a very early feature for The New York Times about public-space Wi-Fi in airports, cafes, and elsewhere. (See The Web, Without Wires, Wherever, 22-Feb-2001.)

Of the firms mentioned in the article, several disappeared within a year. And later startups like Cometa had big runs up and then giant flameouts. (I run down the failures as well as some other details of the Wayport deal at Ars Technica.)

Wayport may have survived and thrived due to two moves. First, the operator was an early partner with Boingo, renegotiating its contracts with venues to allow the pricing model of wholesale aggregation resale to work. On a panel at 802.11 Planet after Boingo launched, if I recall correctly, Wi-Fi veteran Phil Belanger (then at Wayport) explained that contracts with its venues needed to be renegotiated, but it was worth it to increase volume of use.

Wayport was right. Firms that resisted reasonable resale pricing or availability seem to have all gone by the wayside. The latest of these was T-Mobile, which had very restrictive roaming/resale agreements, and was replaced at Starbucks by AT&T, which has expansive agreements.

The other element was Wayport grabbing the McDonald’s contract through the use of a still-innovative pricing model. Instead of reselling sessions at McDonald’s to aggregators or others, Wayport offered only a flat rate based on the piece of the McDonald’s network that a reseller sliced. It had hoped to get cable systems interested as a competitive tool against 2.5G networks and other telecom advantages. It didn’t happen.

But the Wi-Fi World model, as it called the program at launch, proved the right approach for consumer electronics and gaming firms, like Nintendo for its Wi-Fi-enabled DS system, ZipIt Wireless for its instant-messaging handheld for teens, and Eye-Fi for the geotagging Explore model of its Wi-Fi memory card.

Wayport also was able to snag AT&T as a resale partner early on; AT&T was providing backhaul to many stores, and wound up buying access to resell to some of its customers. That later expanded into Wayport becoming AT&T’s managed services provider, and AT&T slowly but dramatically expanding cheap ($1.99 per month) and then free access to its base Wi-Fi network to a large portion of its wireline, fiber, business, and smartphone customers.

I’d say Wi-Fi World paid off as an approach.

Some might ask where this puts Boingo in relation to AT&T. Since Boingo is an aggregator, the advantage of which is to take many disparate networks and repackage them for resale at a predictable and reasonable price, why would you need Boingo when you can get 20,000 U.S. locations at no cost (if you’re a qualifying AT&T subscriber) or as part of AT&T’s own aggregated worldwide network of 80,000 locations ($20 per month for non-subscribers; $10 per month for those who qualify for free service)?

I checked with Boingo yesterday, and it has about 24,000 U.S. locations in its network. So…that’s nearly 85 percent AT&T when the Wayport acquisition closes. But don’t worry about Boingo. The company has a trump card: Airports.

Its acquisition a few years ago of Concourse Communications gave them the golden ticket: Boingo controls Wi-Fi access in most major airports in North America. AT&T and T-Mobile each have a handful that they operate, but Boingo has the big plums. Boingo operates the big NY/NJ airports (EWR, JFK, LGA), Detroit, Minneapolis, Chicago (ORD and Midway), and on and on. The firm has 24 airports, most of them biggies, across the U.S.

Boingo told me some time ago that the Concourse acquisition was partly for revenue, partly for marketing, and partly for strategy. With airports in hand, it has better bargaining power with networks onto which it wants its users to roam, including outside the U.S.

If AT&T were to try to push to hard as the new Wayport owner with 85 percent of Boingo’s domestic footprint, Boingo has the counterbalance of the critical airports that AT&T’s business travelers want—and increasingly consumer and leisure travelers as those categories of passenger carry mobile devices that rely on a Wi-Fi network for their sole or best performance. (Think iPod Touch as well as iPhone.)

The end of Wayport spells the end of a long period in which many hotspot operators were in play. Now it’s AT&T and a number of much smaller firms—T-Mobile will still have perhaps 3,000 locations—and company-operated networks, like Panera, run through in-house divisions or through managed services.




Colombian singer Shakira lends support to Obama
(AP)

Wee-Fi: Boingo Ups Count, Nationals-Fi, Free AU Mickey D-Fi
Boingo Tweaks Rates, Raises Global Price

Thursday, November 6, 2008

Breaking News: AT&T Buys Wayport; WPA's TKIP Cracked?; Virgin America Sets Launch Date

It’s always in threes: Three big pieces of Wi-Fi news today, folks, and I’ll post more information as I have it.

Wayport is being purchased for $275m by AT&T: This is a purely logical move, because Wayport not only has 10,000 McDonald’s that they operate the Wi-Fi service for under a direct contract and resell to AT&T for the telecom’s customers, but Wayport is also the managed services provider—the outsourced company—that handles AT&T’s “internal” Wi-Fi network of Starbucks, Barnes & Noble, and other locations. The deal is cost conservation, bringing outsourced expense inhouse. With the close of the deal, AT&T’s Basic footprint—free to its broadband, laptop 3G, iPhone, and some BlackBerry users—expands from 17,000 U.S. to 20,000 U.S. locations, sweeping in premium hotels and other locations.

Breaking News: AT&T Buys Wayport; WPAs TKIP Cracked?; Virgin America Sets Launch Date

Is TKIP dead, already? A report in advice of the PacSec conference from IDG News Service says that researchers have found a non-brute-force method of sending data to a Wi-Fi client that it accepts was transmitted by an access point. I’ve gotten more information than the IDG reporter, and the attack works only on small packets and only with the weaker TKIP key type that’s part of WPA and WPA2. The stronger AES key method isn’t vulnerable. This isn’t a generic vulnerability, and is likely to be of concern only to corporate users.

Breaking News: AT&T Buys Wayport; WPAs TKIP Cracked?; Virgin America Sets Launch Date

Virgin America has press flight set for 22-November: I’ll be on the plane if all goes well. The promotional flight of the one Wi-Fi equipped craft will be followed each week by an additional plane being unwired with the whole fleet set for Internet access by Q2 2009.




T.I. “Likes” Making Hot 100 History
(E! Online)

Zune Owners Get Free Wi-Fi at McDonald’s

Wednesday, November 5, 2008

Wee-Fi: Clearwire's New Name, Challenges; $3b in Wi-Fi; Meraki Offers $10K 1 Sq Mi Kit

Wee-Fi: Clearwires New Name, Challenges; $3b in Wi-Fi; Meraki Offers $10K 1 Sq Mi Kit

Clearwire, Sprint venture to be called New Clearwire: Along with FCC approval and the new name, New Clearwire has to build out 37,000 cells and raise money in a difficult climate—although they already have commitments from Google, Intel, and others.

Wi-Fi chipset sales will top $3b in 2008: So says ABI Research, which has a good track record on analysis and estimation. This number does not include anything but Wi-Fi chips and a few associated components; the sales figures for assembled cards and access points would have to be at least an order of magnitude higher. ABI says chip sales in 2006 were $1b and $2b in 2007.

Meraki offers 1 sq mi of Wi-Fi for 10 grand: The mesh-networking equipment vendor has a special deal for cities: $10,000 buys all the equipment and service needed to cover 1 sq mi, and includes a 60-day money-back guarantee.




Wee-Fi: Meraki Modifies, Drops Standard; Tempe’s Phoenix?; Remote Wake, Wi-Fi Need Not Apply
Meraki Extends SF, Gives Shine to Newsom
Norway consumer body challenges Apple over iTunes
(Reuters)

Metallica prevails over Ne-Yo to remain No. 1
(Reuters)

Tuesday, November 4, 2008

FCC Slams Out a Pile of News: White Spaces, Sprint/Clearwire, Verizon/Alltel

Because we didn’t have enough on our minds on election day, the FCC met and made three relatively massive decisions: Let’s start with white spaces. I have been avoiding posting too much about the topic, because it’s mindbendingly boring to the average reader or businessperson who is more interested in technology or developments when they happen, not when they’re discussed ad nauseum. The gist of the white spaces proposal is that computer industry giants want television channels that are unused in specific markets to provide assurance of a lack of interference among adjacent channels.

Microsoft, Google, Intel, HP, and many others covet the space to use for high-speed wireless networking for broadband and wireless LANs. Over short distances, rates rival 802.11n Wi-Fi speeds; over longer distances, speeds will likely be closer to 10 Mbps. The expectation is that the frequencies, way down in the 54 to 698 MHz range, would have enormously superior propagation characteristics than Wi-Fi’s 2.4 GHz or 5 GHz deployments. With adaptive scanning required to avoid stepping on licensed users, the white spaces technology would likely be much more resilient than Wi-Fi, too, as well as having a larger span of channels on which to choose to operate.

The National Association of Broadcasters, representing owners of TV stations and networks, protested that regardless of how well designed devices were to avoid interfering with TV signals, it was inevitable that they would. Dolly Parton surprisingly entered the fray—nearly a la Wi-Fi patron Hedy Lamarr—on behalf of the wireless microphone industry, which has a licensed low-power use for theater and performance.

The FCC voted 5-0 to move forward. Manufacturers would still be going through tightly controlled FCC certification and testing for their devices, and one imagines the NAB will be watching very closely as well.

The FCC also voted 5-0 to approve a WiMax merger/spinoff that allows Sprint Nextel to reorganize its Xohm broadband operation into a new firm that would be merged with Clearwire’s assets and be named Clearwire. The new operation already has billions lined up from Google, Intel, and cable operators to invest. The Justice Department already gave its general go-ahead, too.

This move sets the stage for a real battle among all broadband providers: it will force AT&T and Verizon to move quite aggressively to use the new 700 MHz bandwidth they acquired (and plan to deploy GSM-based LTE over, even though LTE is still officially in the lab, not in production); and for wireline provides like AT&T and Verizon, as well as Comcast, Cablevision, Qwest, and all the rest, to rethink pricing, speed, and services that Clearwire enters. If WiMax pans out as a viable third or even fourth pipe into the home, other broadband options in the same markets will be cheaper and faster.

Finally, in the least-interesting part of the news, the FCC voted to approve, with Dems partially dissenting—procedural thing, it appears—to allow Alltel to be acquired by Verizon to create the biggest U.S. cell carrier. Alltel was the largest of the smaller carriers, as it were, providing service in areas that the major carriers often overlooked. The Alltel acquisition is partially an infrastructure play that reduces Verizon’s roaming costs while expanding its customer base.




Cousin: Nate Dogg Was On Life Support
(E! Online)

Wee-Fi: Bidding for Wireless Service; BT Disperses Cloud
R. Kelly says he was betrayed during porn probe
(Reuters)

Monday, November 3, 2008

UWB Retreats?

Ultrawideband’s future as personal area networking technology seems dim: With leading UWB chipmaker WiQuest going out of business last week, with very few devices on the market two years after UWB was supposed to have its big introduction, and with apparent little interest in that changing, it’s hard to see how UWB winds up in printers, cameras, laptops, desktops, and hard drives. It’s not that UWB will disappear (likely): the technology has other uses, some niche, and some as mainstream as being one of the options for wireless high-definition streaming as an HDMI cable replacement.

Alereon, another chipmaker, announced today that it would acquire Certified Wireless USB assets of Stonestreet One, a firm involved in tests of UWB in mobile devices, like smartphones. Alereon’s CEO Eric Broockman would like to spin the story, as he writes in his blog, that there’s a very long timeframe for most new technology adoption, and that market leaders are rarely the first to capitalize on the advantages.

Right. But with Intel, a leading UWB backer, seemingly having shifted its interests; with a leading UWB chipmaker gone; with just Lenovo and Toshiba offering any kind of UWB option; with no word on any UWB-enabled peripherals going into Christmas; well, I could go on.

Broockman is certainly correct that there’s always a shakeout, but I’m surprised how long UWB has been under development without any deep niche adoption. Early flavors of Wi-Fi were in devices sometimes years before standards were ratified. Airgo, for instance, had its MIMO flavor of 802.11 on the market long before competitors, and it was acquired by Qualcomm (disappearing from sight, but not unsuccessfully in terms of the investors’ interest or in spreading MIMO as an essentially mandatory element of 802.11n).

I wrote more about this at Ars Technica along with the historical background.




Quantenna: Radical New Design or Great PR?
Norway consumer body challenges Apple over iTunes
(Reuters)