Crack WPA on the cloud
cloudcracker.com
cloudcracker.com
Any simple password generator (say, Apple's Keychain, or pwgen) should be able to generate a non-dictionary key of length 12-16 characters in a few seconds that would withstand this and most similar techniques for the next few years.
"Nothing in this researcher's work is predicated on the use of Amazon EC2. As researchers often do, he used EC2 as a tool to show how the security of some network configurations can be improved," said Amazon spokesman Drew Herdener.
[1]: http://uk.reuters.com/article/2011/01/07/us-amazon-hacking-i...
I agree the convenience is attractive but I wouldn't want to put myself in that position.
The same is true for radio, and conversely 802.11. If you expose yourself to data leakage via loud APs / incorrect antenna then it should be well understood that that information is being placed in the public domain (i.e. WPA handshake). A would be malicious user is not bound by any of the restrictions mentioned, and so placing them on people that are knowingly auditing is highly counterproductive unless all the client is going for is a warm fuzzy. This particular way of thinking about pen testing and assessments needs to be at the forefront of the testing itself, because if the client is that misinformed/misled they probably need more help than an incorrectly scoped assessment.