Usability vs. Security in the Context of Apple iOS Mobile Hotspots
www1.cs.fau.de
www1.cs.fau.de
[1]: http://xkcd.com/936/ [2]: http://imgur.com/nAKkPe3
I wrote a scrabble / boggle solver web app and used the built-in dictionary provided with my Linux distribution.
Check it out at http://words.gumyum.com [source-code]
The hotspot cracker appears to use a similar algorithm.
>A GPU cluster composed of four AMD Radeon™ HD 7970 can cycle through around 390.000 guesses per second. As the hotspot wordlist consists of only 1.842 entries followed by a four-digit number, there are only around 18.5 million possible combinations. This means, that a GPU cluster will crack an arbitrary password in less than 50 seconds.
Being in range of a hotspot in with that kind of hardware reliably and for any length of time is going to be difficult. Yes it's insecure but not to someone on the street attacking it with just their phone.
I guess this will still change.
[1] https://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf