Cracking WPA in 10 hours or less
devttys0.com
devttys0.com
It looks time there are two issues here. The first is that the pin is confirmed in two stages, each of which can be individually NAKed. That brings e complexity down from 10^7 to 11,000. It seems like this could be fixed by always ACKing the first stage and then ACKing/NAKing the second stage based on the result of both stages (unless doing so would somehow lead to leaking information about the PIN).
I think the first issue comes from an attempt at doing mutual authentication. Basically the device (like a wireless printer) wants to tell an access point (AP) that it knows the PIN. But, the device wants to make sure the AP also knows the pin. Otherwise, someone could spoof the AP and say for any connection attempt "yup, that's the PIN, now here's your (fake) configuration". I think they're also trying to cover the case where the HMAC they're using has a vulnerability, allowing a fake AP to discover the secret key by using nonces that expose a weakness in the HMAC.
Instead of just trusting HMACs to do their thing, they break the mutual authentication into stages. The AP and the device each prove they know the first half of the key. If either side fails that test, then the other side refuses to move on, supposedly protecting the second half of the key even if the HMAC is found to be broken. In reality of course, it leads to the attack described above. If both sides just always ACK the first stage, everything is fine as long as the HMAC is secure (which it most likely is). If you're worried about the HMAC being broken, you could use a dummy PIN for the second stage if the first stage fails.
The second issue is that most vendors don't implement lockouts after too many failed attempts. Even if they do, the issue above means a brute-force attack is still possible in a few months' time because of the greatly reduced complexity. Fixing both issues would probably make a brute force attack impractical.
Until both issues are fixed, the best solution is to disable pin-based WPS. Unfortunately many low-cost wireless printers and similar devices require WPS to connect to a secured wireless network. Turning off WPS may make such devices unusable.
It's possible that enabling MAC address filtering will also solve the issue(actually... not).
Spoofing MAC addresses is trivial, even under Windows.
When the PIN authentication fails the access point will send an EAP-NACK message back to the client. The EAP-NACK messages are sent in a way that an attacker is able to determine if the first half of the PIN is correct. Also, the last digit of the PIN is known because it is a checksum for the PIN. This design greatly reduces the number of attempts needed to brute force the PIN. The number of attempts goes from 108 to 104 + 103 which is 11,000 attempts in total.
I don't really care whether he does that or not, but I see it as part of a larger trend: open source software supported by a freemium business model.
Where I know of it working well, it's where there are separate legal entities to manage the open source code and the premium version.
WPA has known vulnerabilities that an attacker can use to cause a router to leak data over its WAN Ethernet port, so it should be considered unsafe at this point. But, that has nothing to do with this attack.
If you have something to hide, obviously, you should take additional precautions.