HomeinetSecure SOHO (SmallOffice, HomeOffice) Security

Secure SOHO (SmallOffice, HomeOffice) Security

SOHO Security. It all started in June 2004 as the IEEE 802.11TGi group validated 802.11i which supports CCMP/AES encryption. The only difference with WPA is the encryption algorithm. WPA and WPA2 use the PSK authentication method.
wi-fi SOHO SOHO SOHO SOHO
PSK has many names e.g. WPA/WPA-passphrase, WPA/WPA2-PSK, WPA/WPA2-Preshared key but the correct interpretation given by WiFi-Alliance is WPA/WPA2-Personal.

The PSK is 256bit or 64hex characters but since there is no way to remember 64 hex characters we use the so-called passphrases which range from 8~63 characters.
The PSK is very important in the whole process as it is used in the 4-Way Handshake to encrypt your data.

PTK=PRF(PMK(PSK)+ANNONCE+SNONCE+AA+SPA)

The formula that converts passphrases to PSK is as follows:

PSK=PBKDF2(Passphrase,ssid,ssidlength,4096,256)

Example
https://www.wireshark.org/tools/wpa-psk.html

SSID=pentestlibrary
passphrase=iguru1234
PSK=7c419f3316447a6da887db99f5bc43470ad4f312a0ebd45ca1aacd6aec0dd6eb

wpawpa2keygeneration

What does all this mean for our security?

WPA/WPA2-Personal uses weak PSK authentication that is vulnerable to brute-force dictionary-Attacks. This means that if someone knows the passphrase , they can decrypt all wireless traffic.
We finally arrived at the solution called Entropy.
Entropy in digital communication is the measure of uncertainty associated with the random variable.
How is it calculated?
2.5*n+12bit security
n=Characters
e.g. A coin has 2 sides with 1 bit of entropy.
The more bits, the more difficult it is for someone to discover our password with a brute-force attack.
(0-9)=>10 symbols=>3.32 bits
(az)=>26 symbols=>4.7bits
(az,0-9)=>36 symbols=>5.17bits
(az,AZ,0-9)->62 symbols=>5.95 bits
Mix Case=>92 symbols=>6.55 bits

e.g. passphrase=pent$tELzQq! (2.5 * 12+12bits security)=42 bits entropy and again I am not safe. Recommended is 20 characters and mixed case.

And as I told you in the PSK type above, because the SSID also plays a role, you would do well to set something more robust and avoid the Default and use WPA2/CCMP-AES!

pentestlibrary.blogspot.gr

iGuRu.gr will occasionally publish the articles of our friend Taso_X. The articles will be published only so that you can perform security tests on your network. So the purpose is anything but malicious. iGuRu.gr does not support the malicious use of its publications in any way.
Knowledge has never been a crime.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS