12 karma · joined January 4, 2015
It seems like this should be easy to defend against, but everything I've ever read about WPS says no one seems to be putting any such protections in place.
http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup#Brute-for...
I didn't mean to imply that MitM is trivial, just that it's quicker than brute-force in many cases. And, I assumed the rogue AP was not doing true WPA encryption like the real AP, just enough to make it appear correct to get clients to connect so you can serve the fake control panel. If you need the passphrase to stand up the rogue AP, what is the point of this attack? You're not phishing for anything but the WPA key.
EDIT: just read your comment about how this actually works (that is, the "rogue" AP is just another unencrypted network.) That's actually really lame, and I withdraw my previous praise for this crack. ;)
I think it's becoming more and more common for the PSK to come on a sticker from the all-in-one router/modem your ISP sends you. So, the user never sets a passphrase, never sees the control panel, and has the key ready to hand out by just looking at their "internet box." This attack is perfect for that.
Man-in-the-middle, on the other hand, takes almost no time at all - just a gullible user with the passphrase. This method seems like it would be especially effective against most home APs, which is the same case that is less-than-ideal for the other method.
The paper upon which this article is based is really cool, because it scientifically confirms something that many people (myself included) already believed: mere participation in our financial industry leads to a certain degree of moral corruption. However, the author of this article goes on to make the case that the cause of such endemic dishonesty is the focus on money and number crunching required in banking.
The author's evidence seems reasonable, but doesn't match up with the original study: banking employees that work in industry "support units" (e.g., HR or risk management) showed the same tend towards dishonesty as those working in "core" units (private bankers, asset managers, etc.) This issue is directly addressed in the original study. The author's thesis suggests that working more directly with numbers/money would cause a higher degree of dishonesty, but the paper points out: "the treatment effect in core units is similar and statistically indistinguishable from the support units."
There's something more complex at work in our banking system.