Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Wireless Security » breaking 256 bit AES encryption
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
« (topic move) Beta versions of NIS 2009 and N360 v3 for Windows 7  
AuthorAll Replies


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to Matt26
Re: breaking 256 bit AES encryption

Let me try rewording my answer.

The only known method for breaking AES is trial and error - testing possible keys until you find one that works. Cryptography researchers have not found any weakness such as might allow an easier way of breaking it.

Testing all possible keys would take billions of years, so does not pose a plausible threat.

Trial and error can be a lot faster with a dictionary attack - testing only keys obtained in dictionaries, dictionaries of phrase, etc. Likewise, trial and error restricted to short keys is a lot faster. As long as you choose a key that is long enough (20 or more characters is recommended), and is not a common word or phrase, there is no reason for concern.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.8


caedmon

@cox.net

quote:
The only known method for breaking AES is trial and error
This is commonly called a "brute force attack". It is virtually impossible when using AES with a random 128 bit key at this time.

Important Note
The PSK key you configure has nothing to do with the keys used with the AES encryption. The PSK is used for authentication and as part of the algorithm used to setup the keys used by AES. The PSK is the only known weak point in WPA-PSK when using CCMP(AES encryption). If someone captures the initial 4 messages when a client first joins a network they can use a brute force attack on the PSK. If they crack the PSK they can decrypt those 4 messages and determine what the AES key is.

Each client negotiates a different AES key each time they join the network but knowing the PSK allows one to obtain the AES key used by that client if they capture the initial 4 messages when that client joins the network.

Matt26

join:2007-07-06

ok, just so i'm clear- there are two separate keys involved in WPA/WPA2- the PSK key (which would be the password/passphrase used to authenticate a user to the network) and an AES key used for the encryption of the data- and these AES keys change each time a client authenticates to the network. is this correct?

as far as a brute force attack is concerned- my understanding is that the more complex the passphrase the harder it will be to crack it, and i use a passphrase made of 63 random ASCII characters- so my guess is that this would be next to impossible for anyone to crack. would this be reasonable to assume?

thanks for all the replies.


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
Yes, that's a very reasonable assumption.


caedmon

@cox.net
reply to Matt26
Yes to both questions.

KodiacZiller

join:2008-09-04
73368

Brute forcing AES is simply out of the question and will likely always be out of the question, at least until quantum computing comes around (and even then it seems unlikely).

Someone above said it would take millions of years to brute force 128 bit AES. That is incorrect. It would take trillions of times longer than the age of the universe. And even then, the energy requirements would be so large that the energy of the sun would need to be harnessed.
-
Forums » Up and Running » Security » Wireless Security« (topic move) Beta versions of NIS 2009 and N360 v3 for Windows 7  


Tuesday, 01-Dec 14:56:20 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [76] Comcast Releasing Promised Usage Meter
· [62] Baltimore To Ban Lazy Cable Installs
· [54] Broadband Killed The Game Console
· [43] Rogers Unveils The ISP Dream Model
· [38] Rural Carriers Quickly Embracing Fiber
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [32] Charter Exits Chapter 11
· [24] Midcontinent Socked With Easement Lawsuit
· [21] Vivendi Agrees, Comcast/NBC Deal Soon
· [19] ACTA: Global Three Strikes
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· buying a one way ticket [General Questions]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [Rant] called out sick! [Rants, Raves, and Praise]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [Phish] email from CDC "personal vaccination profile" [Spam, Scam and Phishbusters]
· Data Usage Meter Launched [Comcast HSI]
· [Internet] Gaming problem for "Heroes of Newerth" ( New bell Upd [Bell Canada]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· FiOS TV Online [Verizon FIOS TV]