Tkip+aes?

John Connor

Lifer
Nov 30, 2012
22,757
617
121
I use an old WRT54GL with DD-WRT and I currently use TKIP+AES WPA2 for WIFI security with a 64 digit key. After reading this I wonder if I'm vulnerable to an attack. I do have a program that can brute force a WPA key, but I thought that only WPA could be brute forced.

Question: Am I vulnerable?
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,487
392
126
Is it verbally correct to say Men can go to the Moon?

Of course Men did it decades ago.

Given the resources that are needed to go there is it really Not an option at large?

Same with WPA2, a while ago a research group with unique scientific computing power claim that they mange to brake once a WPA2 key.

Quote: "AES permits the use of 256-bit keys. Breaking a symmetric 256-bit key by brute force requires 2128 times more computational power than a 128-bit key. 50 supercomputers that could check a billion billion (1018) AES keys per second (if such a device could ever be made) would, in theory, require about 3×1051 years to exhaust the 256-bit key space".

http://en.wikipedia.org/wiki/Brute-force_attack

 

JoeMcJoe

Senior member
May 10, 2011
327
0
0
I use an old WRT54GL with DD-WRT and I currently use TKIP+AES WPA2 for WIFI security with a 64 digit key. After reading this I wonder if I'm vulnerable to an attack. I do have a program that can brute force a WPA key, but I thought that only WPA could be brute forced.

Question: Am I vulnerable?

Yes, don't sleep at night....

Change it to AES only.

Now you can sleep.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,554
10,171
126
Yes, don't sleep at night....

Change it to AES only.

Now you can sleep.

Yes, TKIP has a cryptographic weakness. AES (so far) does not, to my knowledge.

You should be using AES ONLY. TKIP + AES leaves you open to attack.
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
I use an old WRT54GL with DD-WRT and I currently use TKIP+AES WPA2 for WIFI security with a 64 digit key.

The purpose of TKIP was to find a way that old 802.11 hardware that only supported RC4 crypto hardware acceleration could have some improved security without the need to replace everything. That is, it's WPA/TKIP is a security improvement over WEP that can run fast on the same old hardware as WEP could.

Pretty much all 802.11g and newer generation hardware supports AES crypto hardware acceleration. Once you have that, you don't want or need TKIP. Also, WPA2 has some security improvements over WPA.

I'm a little confused by your description of "TKIP+AES WPA2" - I didn't think such a thing existed, I thought TKIP was obsolete as of WPA2. Either way, don't use TKIP anymore. Do use AES, do use WPA2.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,487
392
126
I'm a little confused by your description of "TKIP+AES WPA2" - I didn't think such a thing existed, I thought TKIP was obsolete as of WPA2. Either way, don't use TKIP anymore. Do use AES, do use WPA2.

Yeah, some Wireless Routers has bizarre variety of choices.

Unfortunately marketing has more bearing on End-Users' Devices than real Technology and Security issues.

If New Wireless Router has No starlight configuration to pure WPA2, do not buy it.

If One has an older Router that does not have a pure configuration to Pure WPA+AES (WPA + AES is the WPA2 version in pre IEEE Standard devices) rid of it.

--------------
P.S. Many Routers have a WPA2 Personal or and WPA2 Enterprise.

Both are WPA2 secured. The Enterprise level has to be used when a Radius Server or similar Enterprise concoctions are involved.



 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
This is my current setup.




Here are the security modes available.




And this is the algorithms.

 

s44

Diamond Member
Oct 13, 2006
9,427
16
81
Regular WPA2 personal is two modes up. That will be AES only.
 

cubby1223

Lifer
May 24, 2004
13,518
42
86
I'd turn off tkip for the reason that routers often are unreliable with getting devices connected and staying connected with both encryption options enabled.

The added security is just a bonus.

It is 2014, chances of having a device that does not support aes is just too small to even care.
 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
Well, my netbook a Dell mini 910 can use the WIFI with TKIP-AES.

So is the consensus is to just use AES? As TKIP adds a security risk?
 

ch33zw1z

Lifer
Nov 4, 2004
38,209
18,679
146
Yes, AES only if possible. Some older devices may not support AES....but those are oooooold.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,487
392
126
If your Dell mini 910 can not support pure WPA2 you can find on eBay a New Wireless card for $10 that will do it.


 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
Just changed the WIFI to AES and changed the key. Haven't tried the mini 9 yet, but I do have a WIFI USB adapter.
 

AD5MB

Member
Nov 1, 2011
81
0
61
the point of TKIP+AES was to make the router available to people who had old technology and people who have new technology. If you don't have 1996 laptops in use it serves no purpose.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |