HomeinetDo you think your network's WPA2 encryption is secure?

Do you think your network's WPA2 encryption is secure?

Think your wireless network is secure because you're using WPA2 instead of WEP? Think again.
Almost everyone who's into technology has read one or more articles about how hackers are able to gain access to wireless networks that use Wired Equivalent Privacy (WEP) encryption. That's old news. If you're still using WEP, you might be better off giving hackers a key to your home, or even better yet, opening up your Wi-Fi and leaving it open to everyone. Most people know that WEP encryption can be cracked in seconds.

wpa2 lock

Most of you have read or heard advice from security geeks about using Wi-Fi Protected Access 2 (WPA2) encryption as a means of protecting your wireless network. WPA2 is the latest and strongest wireless network encryption method available today.

It would be good to know that hackers who have tried to breach the WPA2 shell have succeeded (to some extent).

To be clear, hackers have been able to crack WPA2-PSK (Pre Shared Key), which is used by most people at home and in small businesses. WPA2-Enterprise, which is used by large businesses, has much more complex settings that include the use of a RADIUS authentication server. This protection is still the most secure wireless protection. WPA2-Enterprise has not been cracked yet.

But if WPA2 was the best way to protect a wireless network at home, what happens now?

Don't panic, there are still ways to protect your network that uses WPA2-PSK. This will prevent most hackers from breaking your encryption and gaining access to your network.
But before we get there, let's look at some explanations.

Hackers have been able to break WPA2-PSK encryption for two reasons:

1. Many users create weak Pre-Shared Keys (wireless network access codes)

On the setup web page, there is a section where you configure wireless access and use WPA2-PSK encryption. There you will need to create a Pre-Shared Key. Many people use an easy Pre-Shared Key, because they will have to type it into every device that uses Wi-Fi to connect to their wireless network. They may also choose to have a simple password, because friends usually ask what the password is to connect to one of their devices. If your password is something like “Mywifirocks” but is not complicated, it is very easy to crack.

Hackers can crack weak Pre-Shared Keys using brute-force tools or Rainbow Tables in a very short time. All they have to do is capture the SSID (wireless network name) handshake between the authorized wireless client and the router, and then get all the information they need to process it with their tools.

2. Most people use the default or common wireless network names (SSID)

In your router's web setup, you can change your network name. Many people leave their router's default SSID, which is what the manufacturer has set.

Hackers have lists of the most common SSIDs to create password cracking Rainbow Tables. This way they can crack the Pre-Shared Keys of networks that use common SSIDs quickly and easily.

Note: Even if your network name is not on the list, they can still create  password cracking Rainbow Tables for a specific network name, but it will take much more time and system resources.

What can you do to make your wireless network that uses WPA2-PSK more secure?

Create a Pre-Shared Key with over 25 random characters

Brute-force tools and Rainbow Table have their limits. The larger the Pre-Shared Key, the harder it is to crack. The computing power and hard drive capacity required to crack large Pre-Shared Keys is enormous and almost impossible to generate on common machines, (we always say almost because no one knows what machines the hacker is using)

As difficult as it is to enter a 30-character password on every wireless device you want to use on your network, you usually only have to do it once.

WPA2-PSK encryption supports Pre-Shared Keys of up to 63 characters.

Make sure the SSID (wireless network name) is as random as possible

You can make sure that your SSID is not in the top 1000 most common SSIDs as we mentioned earlier. This will prevent you from becoming an easy target for hackers who already have pre-built Rainbow Tables for cracking networks with common SSIDs. Use a random and long network name, just like you did with the password. The maximum length for an SSID is 32 characters.
Combining the two changes above will make your wireless network a much harder target for hackers. Hopefully, most hackers will leave and look for something easier, like your neighbor's wireless network, which is still using WEP.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS