“OFF-THE-SHELF” HACK BREAKS WIRELESS ENCRYPTION

August 17, 2001

SCIENCE AND ENGINEERING NEWS

Daniel Sieberg reported for CNN Sci-Tech: A group of researchers from Rice University and AT&T Labs have used off-the-shelf methods to carry out an attack on a known wireless encryption flaw — to prove that it “could work in the real world.”

The security protocol containing the vulnerability is called Wired Equivalent Privacy (WEP), and it’s used to protect local area networks (LANs) employing the 802.11 standard.

WEP contains an algorithm called RC4 that’s designed to shield transmissions between a mobile station (for example, a laptop with a wireless Ethernet card) and a base station system.

Several research groups have uncovered a variety of problems in WEP, which is deployed in wireless networks at numerous homes, offices, hospitals and airports.

The researchers from Rice University in Houston, Texas, and AT&T performed their recent attack after reading a detailed and highly scientific description of the vulnerability written several weeks ago by Scott Fluhrer from Cisco Systems, and Itsik Mantin and Adi Shamir from The Weizmann Institute of Science in Israel.

Fluhrer, Mantin and Shamir are expected to present certain aspects of their findings publicly at a cryptography symposium next week in Toronto, Canada.

“We show that RC4 is completely insecure in a common mode of operation, which is used in the widely deployed Wired Equivalent Privacy protocol,” reads the findings’ summation by Fluhrer, Mantin and Shamir — who is the “S” in the distinguished RSA cryptosystem.

The researchers from Rice and AT&T essentially then applied these technical findings to a “real world” implementation and released a paper with their conclusions on Monday.

“It is a complete and devastating break of the security of wireless networks,” said Avi Rubin of AT&T Labs in New Jersey. Rubin led one of the teams that administered the recent attack in only hours after taking a few days to prepare. Rice University’s Adam Stubblefield and John Ioannidis also participated.

“Given this attack, we believe that 802.11 networks should be viewed as insecure,” the statement reads.

“What we did is important because we proved that virtually all of the wireless networks used by companies and hospitals are completely open and offer no protection for the data on them,” said Rubin.

In fact, since the publication of the paper detailing the vulnerability, Rubin says both private companies and several United States government agencies have contacted his office.

Industry group downplays new findings

But the industry group that certifies and promotes the use of 802.11 networks says the Rice University and AT&T report doesn’t offer any new information, and that it’s already working to solve the problem.

“All the information that exposes the weakness . . . is outlined in the Fluhrer, Mantin and Shamir paper,” said Dennis Eaton, vice chairman of the Wireless Ethernet Compatibility Alliance, or WECA. “It (the action carried out by Rice and AT&T) is like somebody following instructions and saying, ‘Guess what? It worked.'”

Fluhrer, Mantin and Shamir were part of the development team for the RC4 algorithm, said Eaton, and WECA’s relationship with them is viewed as promoting scientific discovery in a cooperative manner.

But he did not have the same opinion of the efforts by Rice and AT&T.

“We’ve looked at their paper, and there is no new science here,” he said. “It’s not helpful at all.”

Denny Arar, senior editor at PC World

Eaton says WECA is “aggressively” working to upgrade the security of its networks. But he added that the group has long urged users, especially those who have sensitive information to transmit, to fortify security with measures such as password protections, firewalls, or virtual private networks.

The vulnerability affects only devices with the 802.11 card installed, not the average laptop, cell phone or PDA (personal digital assistant).

“Basically this has to do with people who are in range of the radio, of the antenna and its access point, being able to pick up the traffic that’s come to the wireless point and being able to decode it and read it,” said Denny Arar, senior editor at PC World.

“So for now . . . people who deal with sensitive data would probably be advised to avoid them as much as possible, especially if they are in public places where people can come within range and grab that stuff in the ether,” Arar told CNN.

Common sense required Both Arar and Rubin say it is important to publicize security flaws such as this as soon as they’re found, so users can be conscious of what may be a risky transmission.

Wireless transmissions, by their nature, are hard to secure. Radio signals have been intercepted for nearly a century for military and espionage purposes. Now there’s often great concern about the security of medical and financial information, as well as trade secrets.

Wireless technology was developed so workers could move about large corporations without constantly plugging and unplugging their laptops. Its success made the 802.11 technology — also known as Wi-Fi — popular for home networks, and later for public spaces such as airports, hotels and coffee shops.

While the security flaws are serious, wireless expert Arar says a measure of common sense isn’t too much to expect of users.

“This doesn’t invalidate for me the value of a wireless network,” she said. “It just means that you’ve got to be careful about some uses, that’s all.”

— CNN Sci-Tech’s Marsha Walton contributed to this report.

============================================================

Subscribe to HPCwire's Weekly Update!

Be the most informed person in the room! Stay ahead of the tech trends with industry updates delivered to you every week!

Stanford HAI AI Index Report: Science and Medicine

April 29, 2024

While AI tools are incredibly useful in a variety of industries, they truly shine when applied to solving problems in scientific and medical discovery. Researching both the world around us and the bodies we inhabit has c Read more…

Atos/Eviden Find a Strategic Path Forward

April 29, 2024

French IT giant Atos seems to have found a path forward. In recent years, Atos has been struggling financially and has not had much luck finding a buyer for some or all of its technology. Atos is the parent of the Read more…

IBM Delivers Qiskit 1.0 and Best Practices for Transitioning to It

April 29, 2024

After spending much of its December Quantum Summit discussing forthcoming quantum software development kit Qiskit 1.0 — the first full version — IBM quietly debuted the latest version (February 15) and recently provi Read more…

Edge-to-Cloud: Exploring an HPC Expedition in Self-Driving Learning

April 25, 2024

The journey begins as Kate Keahey's wandering path unfolds, leading to improbable events. Keahey, Senior Scientist at Argonne National Laboratory and the University of Chicago, leads Chameleon. This innovative projec Read more…

Quantum Internet: Tsinghua Researchers’ New Memory Framework could be Game-Changer

April 25, 2024

Researchers from the Center for Quantum Information (CQI), Tsinghua University, Beijing, have reported successful development and testing of a new programmable quantum memory framework. “This work provides a promising Read more…

Intel’s Silicon Brain System a Blueprint for Future AI Computing Architectures

April 24, 2024

Intel is releasing a whole arsenal of AI chips and systems hoping something will stick in the market. Its latest entry is a neuromorphic system called Hala Point. The system includes Intel's research chip called Loihi 2, Read more…

Stanford HAI AI Index Report: Science and Medicine

April 29, 2024

While AI tools are incredibly useful in a variety of industries, they truly shine when applied to solving problems in scientific and medical discovery. Research Read more…

IBM Delivers Qiskit 1.0 and Best Practices for Transitioning to It

April 29, 2024

After spending much of its December Quantum Summit discussing forthcoming quantum software development kit Qiskit 1.0 — the first full version — IBM quietly Read more…

Shutterstock 1748437547

Edge-to-Cloud: Exploring an HPC Expedition in Self-Driving Learning

April 25, 2024

The journey begins as Kate Keahey's wandering path unfolds, leading to improbable events. Keahey, Senior Scientist at Argonne National Laboratory and the Uni Read more…

Quantum Internet: Tsinghua Researchers’ New Memory Framework could be Game-Changer

April 25, 2024

Researchers from the Center for Quantum Information (CQI), Tsinghua University, Beijing, have reported successful development and testing of a new programmable Read more…

Intel’s Silicon Brain System a Blueprint for Future AI Computing Architectures

April 24, 2024

Intel is releasing a whole arsenal of AI chips and systems hoping something will stick in the market. Its latest entry is a neuromorphic system called Hala Poin Read more…

Anders Dam Jensen on HPC Sovereignty, Sustainability, and JU Progress

April 23, 2024

The recent 2024 EuroHPC Summit meeting took place in Antwerp, with attendance substantially up since 2023 to 750 participants. HPCwire asked Intersect360 Resear Read more…

AI Saves the Planet this Earth Day

April 22, 2024

Earth Day was originally conceived as a day of reflection. Our planet’s life-sustaining properties are unlike any other celestial body that we’ve observed, Read more…

Kathy Yelick on Post-Exascale Challenges

April 18, 2024

With the exascale era underway, the HPC community is already turning its attention to zettascale computing, the next of the 1,000-fold performance leaps that ha Read more…

Nvidia H100: Are 550,000 GPUs Enough for This Year?

August 17, 2023

The GPU Squeeze continues to place a premium on Nvidia H100 GPUs. In a recent Financial Times article, Nvidia reports that it expects to ship 550,000 of its lat Read more…

Synopsys Eats Ansys: Does HPC Get Indigestion?

February 8, 2024

Recently, it was announced that Synopsys is buying HPC tool developer Ansys. Started in Pittsburgh, Pa., in 1970 as Swanson Analysis Systems, Inc. (SASI) by John Swanson (and eventually renamed), Ansys serves the CAE (Computer Aided Engineering)/multiphysics engineering simulation market. Read more…

Intel’s Server and PC Chip Development Will Blur After 2025

January 15, 2024

Intel's dealing with much more than chip rivals breathing down its neck; it is simultaneously integrating a bevy of new technologies such as chiplets, artificia Read more…

Comparing NVIDIA A100 and NVIDIA L40S: Which GPU is Ideal for AI and Graphics-Intensive Workloads?

October 30, 2023

With long lead times for the NVIDIA H100 and A100 GPUs, many organizations are looking at the new NVIDIA L40S GPU, which it’s a new GPU optimized for AI and g Read more…

Choosing the Right GPU for LLM Inference and Training

December 11, 2023

Accelerating the training and inference processes of deep learning models is crucial for unleashing their true potential and NVIDIA GPUs have emerged as a game- Read more…

Baidu Exits Quantum, Closely Following Alibaba’s Earlier Move

January 5, 2024

Reuters reported this week that Baidu, China’s giant e-commerce and services provider, is exiting the quantum computing development arena. Reuters reported � Read more…

AMD MI3000A

How AMD May Get Across the CUDA Moat

October 5, 2023

When discussing GenAI, the term "GPU" almost always enters the conversation and the topic often moves toward performance and access. Interestingly, the word "GPU" is assumed to mean "Nvidia" products. (As an aside, the popular Nvidia hardware used in GenAI are not technically... Read more…

Shutterstock 1606064203

Meta’s Zuckerberg Puts Its AI Future in the Hands of 600,000 GPUs

January 25, 2024

In under two minutes, Meta's CEO, Mark Zuckerberg, laid out the company's AI plans, which included a plan to build an artificial intelligence system with the eq Read more…

Leading Solution Providers

Contributors

China Is All In on a RISC-V Future

January 8, 2024

The state of RISC-V in China was discussed in a recent report released by the Jamestown Foundation, a Washington, D.C.-based think tank. The report, entitled "E Read more…

Nvidia’s New Blackwell GPU Can Train AI Models with Trillions of Parameters

March 18, 2024

Nvidia's latest and fastest GPU, codenamed Blackwell, is here and will underpin the company's AI plans this year. The chip offers performance improvements from Read more…

Shutterstock 1285747942

AMD’s Horsepower-packed MI300X GPU Beats Nvidia’s Upcoming H200

December 7, 2023

AMD and Nvidia are locked in an AI performance battle – much like the gaming GPU performance clash the companies have waged for decades. AMD has claimed it Read more…

Eyes on the Quantum Prize – D-Wave Says its Time is Now

January 30, 2024

Early quantum computing pioneer D-Wave again asserted – that at least for D-Wave – the commercial quantum era has begun. Speaking at its first in-person Ana Read more…

The GenAI Datacenter Squeeze Is Here

February 1, 2024

The immediate effect of the GenAI GPU Squeeze was to reduce availability, either direct purchase or cloud access, increase cost, and push demand through the roof. A secondary issue has been developing over the last several years. Even though your organization secured several racks... Read more…

GenAI Having Major Impact on Data Culture, Survey Says

February 21, 2024

While 2023 was the year of GenAI, the adoption rates for GenAI did not match expectations. Most organizations are continuing to invest in GenAI but are yet to Read more…

Intel Plans Falcon Shores 2 GPU Supercomputing Chip for 2026  

August 8, 2023

Intel is planning to onboard a new version of the Falcon Shores chip in 2026, which is code-named Falcon Shores 2. The new product was announced by CEO Pat Gel Read more…

Intel’s Xeon General Manager Talks about Server Chips 

January 2, 2024

Intel is talking data-center growth and is done digging graves for its dead enterprise products, including GPUs, storage, and networking products, which fell to Read more…

  • arrow
  • Click Here for More Headlines
  • arrow
HPCwire