Huh? Anyone who has that hash can still connect to your Wi-Fi network, which kind of defeats what is being claimed. At that point you can also bruteforce the plaintext password (offline, at your leisure), or worse...
Huh? Anyone who has that hash can still connect to your Wi-Fi network, which kind of defeats what is being claimed. At that point you can also bruteforce the plaintext password (offline, at your leisure), or worse...
They then up the goofyness in that it doesn't provide any mechanism in the UI to actually see the password, but you can screenshot the "share QR" code, read the QR in an app, and finally extract the password phrase that way (at least in all the Android versions I've tried). I have to do this dance regularly b/c scanning a QR code from a laptop is a pain
Loosing all my wifi passwords when I get a new phone always kinda sucks...
Apple used to play that security-by-obscurity game too in their implementation of password sharing with nearby devices, and by not allowing users to view passwords in the Wi-Fi settings (even passwords they hand-entered themselves, as if they can't also make a copy of that in a much less secure place at that point). Fortunately, they've come around in the newer iOS versions.
But which Android feature are you referring to? On my Pixel, I can share the PSK as a QR code – not just the hash as far as I can tell.
Well, it turns out getting the name of the current WiFi network is near impossible. There are four different ways for four different ranges of Android versions, the most recent of which plain doesn't work on my phone.
Somewhere down the line the greedy tracking on mobile apps has gotten so bad that even Google wants to make sure their users know they're being tracked. Without a permanent notification and a permission you can't grant in a popup, you're just not getting the WiFi name.
I completely understand why they changed the API and I'll even agree with the most recent incantation, but the state of mobile app development has become truly deplorabele because of tracking companies and everyone must now suffer the consequences.
https://micahflee.com/2013/07/use-android-youre-probably-giv...
The only way was turning on some enterprise mode most home routers don't have, I think because they didn't want to get sued for leaking company passwords.
The only thing you can't get from the hash (without reversing it) is the password itself, so if you use the same high-entropy one for a different SSID or non-WPA-PSK purpose (but why would you?), it helps a bit in that specific scenario.
Apple has annoyingly decided to share the password hash using the "share Wi-Fi password with nearby devices" at least in some versions, which makes it impossible to actually manually copy-paste over a password received in such a way. I consider that pretty poor security-by-obscurity as well.
If you need your network to be resilient against such attacks, you need WPA-EAP ("enterprise"). PSK was never designed for that threat model. That said, it's a shame WPA-EAP is as complicated to set up and poorly supported by most routers as it is.
Note that deriving keys in a passive fashion only works with WPA2. With WPA3 SAE you must do an active Man in the Middle attack, which means also that you need to possess the key at the time of the handshake. With WPA2 you can decrypt any historic traffic you have recorded.
You dislike this feature? It’s pretty amazing compared to explaining which letters are uppercase and what an ‘&’ is called.
On exception are those originally received via nearby sharing, potentially also those afterwards synced to other devices via Keychain, as the iPhone does not have the preimage to display.
https://unix.stackexchange.com/questions/40/use-wpa-supplica...
From the PMK, all other per-connection keys are then derived at association time, but everybody that captures that conversation can derive all further keys since that exchange uses only symmetric functions with all secret inputs derived from the PMK, not something like Diffie-Hellman.
It's unfortunately not easy to do anything more resistant against compromised clients without storage on the APs (or at least a stable encryption key available to all access points of an SSID), so WPA-PSK doesn't – for anything more robust than that, you need WPA-EAP. (Some networks support a per-station/MAC address PSK as a proprietary feature, but that's only possible because they do have some management plane that allows the APs to share the required state.)
Because, if a device has all of the information needed to connect to a network on it, then.. well, it has all of the information needed to connect to a network on it. Could be passwords, hashes, or whatever -- doesn't really matter.