Hacker News new | past | comments | ask | show | jobs | submit login
Holes in the WiFi (lwn.net)
93 points by signa11 on May 21, 2021 | hide | past | favorite | 9 comments




yes

[dupe]


I'm glad they did not outright killed fragmentation.

That would've been a tragedy for WiFi MCUs with few hundred kilobytes of memory.


Why the big trouble anyway. Does not the client device send the password to every AP just with the same Name?


No. In Wi-Fi protocols, the client never sends the password to the AP at all. See https://en.wikipedia.org/wiki/IEEE_802.11i-2004#Four-way_han...


Only an encrypted version of the password right ?


The password is never 'shared', encrypted or not. Instead, both the client (Station) and the AP have to prove to each other that they already know the password (shared key).

From the Wikipedia article:

> The four-way handshake is designed so that the access point (or authenticator) and wireless client (or supplicant) can independently prove to each other that they know the PSK/PMK, without ever disclosing the key.


In WPA2 if the key is weak it's irrelevant, since anyone capturing one handshake can brute force it offline (without communicating with the AP).


Every reconnect.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: