Is WPA2 security broken due to Defcon MS-CHAPv2 cracking?
revolutionwifi.blogspot.com
revolutionwifi.blogspot.com
Since the Defcon talk, I've gotten a ton of emails from people thanking me for making this available as a service, so that they can easily demonstrate why relying on MS-CHAPv2 for WPA2 mutual authentication is a bad idea to their organizations.
The article is correct, but the solution they outline is only "simple" in theory. Most organizations do not have a BYOD enforcement or onboarding process for their enterprise wireless networks, and they used to think MS-CHAPv2 made that OK.
For almost all private individuals your WPA2 connection is still just as secure as it has ever been. For most businesses it is likely secure unless you're using a Microsoft RADIUS server for authentication (and even then as the article says the impact is almost nil).
Which isn't to say that the MS-CHAPv2 thing isn't a big deal: because it really is. It just doesn't have much to do with WIFI.
This means that your client will have to have the certificate installed on it prior to authentication. So a random person connecting to your AP may be subject to an untrusted certificate, or require manual installation before connecting.
So.... in 2015, we might be fucked.
I haven't heard about these Baseline Requirements before your post, but http://www.cabforum.org/Baseline_Requirements_V1.pdf mentions 2015 but only in the context of reserved IPs and "Internal Server Names", which is defined as "A Server Name that is not resolvable using the public DNS". That makes more sense, because there is no way to say who owns such a domain.
Am I missing something?