![]() |
|
|
#1 |
|
Maximum Overclocker
Join Date: Nov 2006
Location: Ohio
Posts: 12,236 (5.15/day)
Thanks: 2,054
Thanked 2,039 Times in 1,549 Posts
|
TKIP vs AES
I currently use AES encryption, as it's the only one that hasn't been cracked (WEP and TKIP being the alternatives). Apparantly, WEP is generic and can be hacked into by just about anyone who cares to know how. TKIP has been recently cracked, but how easy is it to get in to?
This is for my home wireless network. I'm not too worried about getting hacked, even if I left it unsecured. *I do broadcast my SSID. I didn't for quite some time, but it always seemed to bring up connectivity issues. My mom has a laptop for work and she takes it all over the place and there's a list of previously accessed wireless networks in that thing about a mile long, but she does come here and use my network sometimes. For some reason, with SSID broadcasting disabled, I had to re-configure the settings for my network so she could get access. Nothing would change on my end. For this reason I leave SSID broadcasting on to avoid this issue. *I have a MAC address filter set up. Only my mom's desktop, which stays here, and my mom's laptop can access my network, regardless if someone knows the password or not. This leads me to believe that even if I left my network unsecured, I wouldn't actually get anyone accessing my network: the worst anyone could do is packet sniffing. Looking at AES and TKIP, it looks like TKIP is a lot less resource intensive than AES. I want to use the less resource intensive TKIP encryption so as to not swamp my router with the intensive AES encryption. As previously mentioned, I know TKIP has been hacked, but how easy is it to get in to? tl;dr I want to use TKIP instead of AES because it's less resource intensive, but should I be worried about the decreased security? |
|
|
|
|
|
#2 | |
![]() Join Date: Jul 2010
Location: Philly
Posts: 1,599 (1.55/day)
Thanks: 1,004
Thanked 765 Times in 539 Posts
|
Quote:
http://arstechnica.com/tech-policy/n...ure-on-wpa.ars I tend to think of wireless security on a more fundamental level: Are there a lot of people in range of your wireless network? Are you in an area likely to be wardriven? Do you transact a lot of sensitive and unencrypted data on the network? Do you like pistachios salted or not?
__________________
|
|
|
|
|
| The Following User Says Thank You to streetfighter 2 For This Useful Post: |
|
|
#3 | ||
|
Maximum Overclocker
Join Date: Nov 2006
Location: Ohio
Posts: 12,236 (5.15/day)
Thanks: 2,054
Thanked 2,039 Times in 1,549 Posts
|
Quote:
Folks is poor around here... and we're starting to see signs of the "creeping death"... that is, the ghetto is spilling over into this neighborhood. I guess people would be looking for free internet around here, but there's also tons of unsecured networks, so I reckon those people would target the unsecured networks rather than mine. Quote:
Definately salted when I get them, but I havn't had any in some time. |
||
|
|
|
| The Following User Says Thank You to hat For This Useful Post: |
|
|
#4 |
![]() Join Date: Aug 2007
Location: BY-S36
Posts: 422 (0.20/day)
Thanks: 137
Thanked 120 Times in 102 Posts
|
I wouldn't be worried about someone sniffing your credit card details as in most cases that connection is encrytped also, so even if someone manages to break into your wifi, they would only see an encrypted data stream.
One of the best counters is actually to refresh your wifi key on a weekly basis - a bit of a PITA to change the clients but worth the effort IMHO. Another suggestion would be to use some form or 3rd party authentication (if your router supports it) such as TACACS or RADIUS. http://freeradius.org/
__________________
|
|
|
|
| The Following User Says Thank You to IggSter For This Useful Post: |
|
|
#5 | |
![]() Join Date: Jan 2010
Location: I'm roomates with Corey Feldman
Posts: 1,252 (1.03/day)
Thanks: 926
Thanked 785 Times in 446 Posts
|
Quote:
|
|
|
|
|
| The Following User Says Thank You to garyinhere For This Useful Post: |
|
|
#6 |
![]() |
erm, i think that AES might not be as bad as you think, generally it uses hardware acceleration, it shouldn't be slower unless your hardware uses a purely software implementation, like if it didnt support it but support was later haxed in via a patch or something? maybe... thats why WPA2 is so much faster than WPA usually, WPA was more of a software thing and then WPA2 was a nice hardware change, am i wrong about that? im pretty sure i read it somewhere...
__________________
CPU-Z validation sig pics temporarily blocked |
|
|
|
| The Following User Says Thank You to mrhuggles For This Useful Post: |
|
|
#7 |
![]() Join Date: Jan 2009
Location: Brisbane, Australia
Posts: 2,515 (1.58/day)
Thanks: 57
Thanked 528 Times in 470 Posts
|
turning off SSID broadcast does nothing at all to stop hackers. it just stops it from being displayed on windows... a simple program will still see the SSID.
good luck breaking into a WPA network.... mac address blocking wont stop a hacker... he will just change his mac address to be the same as the laptop and bam.. he has internet.
__________________
“it's still EA.. they will F*** it up. F***ing up games is the only thing they do consistently.” -TRIPTEX_MTL
|
|
|
|
| The Following User Says Thank You to slyfox2151 For This Useful Post: |
|
|
#8 | ||
|
Maximum Overclocker
Join Date: Nov 2006
Location: Ohio
Posts: 12,236 (5.15/day)
Thanks: 2,054
Thanked 2,039 Times in 1,549 Posts
|
Quote:
Quote:
|
||
|
|
|
|
|
#9 |
![]() |
is it really resource intense? i cant notice a difference on my WHR-HP-GN, thats 400mhz tho, but also i couldn't tell any difference on my old WRT54G v2 and that was only 200mhz, generally on the WRT54G i used openWRT and on the WHR-HP-GN i use DD-WRT
__________________
CPU-Z validation sig pics temporarily blocked |
|
|
|
| The Following User Says Thank You to mrhuggles For This Useful Post: |
|
|
#10 |
![]() Join Date: Jan 2009
Location: Brisbane, Australia
Posts: 2,515 (1.58/day)
Thanks: 57
Thanked 528 Times in 470 Posts
|
the laptop would send out its mac address when its connected to the router.
__________________
“it's still EA.. they will F*** it up. F***ing up games is the only thing they do consistently.” -TRIPTEX_MTL
|
|
|
|
| The Following User Says Thank You to slyfox2151 For This Useful Post: |
|
|
#11 |
|
TPU addict
Join Date: Jun 2007
Location: US\ Uk Born
Posts: 8,794 (4.07/day)
Thanks: 1,675
Thanked 1,348 Times in 1,170 Posts
|
|
|
|
|
| The Following User Says Thank You to AsRock For This Useful Post: |
|
|
#12 |
|
TPU Janitor
Join Date: Nov 2009
Location: Science Museum, Londinium
Posts: 5,964 (4.70/day)
Thanks: 261
Thanked 1,460 Times in 1,210 Posts
|
From what I know, if you set a simple protection it will deter most from stealing your internets, if you set a strong protection it will prevent that bored kid over the corner from gaining access, and nothing will stop a determined hacker.
Bottom line: dont worry too much. |
|
|
|
| The Following User Says Thank You to Fourstaff For This Useful Post: |
|
|
#13 |
|
Overclocked quantum bit
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,648 (4.34/day)
Thanks: 4,178
Thanked 3,303 Times in 1,943 Posts
|
@hat: Why not use WPA2? This has not been hacked into AFAIK
@streetfighter 2: I like my pistachios salted. This is terribly important.
__________________
Siggie in the post. |
|
|
|
| The Following User Says Thank You to qubit For This Useful Post: |
|
|
#14 |
|
Doctor Moderator
Join Date: Oct 2004
Location: Bendigo, Australia (NOT THE USA)
Posts: 34,553 (10.97/day)
Thanks: 3,699
Thanked 8,689 Times in 6,389 Posts
|
pro tip: cut back the signal strength, and they cant hack it.
if router has no options to do that, use tinfoil over the routers aerial XD btw i see some confusion: the actual encryption methods available are: None: WEP: basically none :P WPA aka WPA1: tougher to crack, but can be done given time (days of packet sniffing/forced injection) WPA2 (tough) AES and TKIP are just sub settings for those. WPA2 with TKIP is the best, iirc. MAC addy blocks are worthless, as you can spoof the mac addy you see sending the data when you do the sniffing. it wont even slow a hacker down.
__________________
![]() Edumacational thread about PC Audio My external HDD's.5x samsung 1TB + 2x Seagate 1.5TB = 8 TB external storage 32 Bit OS vs 64 bit OS information How to get hardware accelerated H264 playback (DXVA) Netbook Owners United! |
|
|
|
|
|
#15 |
![]() Join Date: Oct 2004
Location: Europe/Slovenia
Posts: 3,963 (1.26/day)
Thanks: 39
Thanked 752 Times in 540 Posts
|
I can't think of any reason not to use AES. Routers are designed to use it and i can asure you you can't tell a difference between unencrypted router and a router using AES. So, just AES and live a peaceful life.
__________________
RejZoR's Little Secrets @ rejzor dot tk |
|
|
|
|
|
#16 | |
![]() Join Date: Jul 2010
Location: Philly
Posts: 1,599 (1.55/day)
Thanks: 1,004
Thanked 765 Times in 539 Posts
|
Quote:
AES RC4 Wi-Fi Alliance Certifications: WPA WPA2 The protocols: WEP -> Uses RC4 TKIP - Mandatory in WPA & WPA2 spec -> Uses RC4 (AES is not mandatory in the spec) CCMP - Mandatory in WPA2 spec -> Uses AES
__________________
|
|
|
|
|
|
|
#17 |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,748 (6.48/day)
Thanks: 780
Thanked 5,115 Times in 3,706 Posts
|
Use TKIP, hell use WEP. Yes they are both easily hackable but most won't even bother because they can just drive a few doors down and find an unsecured access point and get on that. You aren't a company so your wireless network is a low target.
And MAC filtering is probably the most useless protection ever. It is insanely easy to spoof a MAC address, and they don't even have to crack the encryption to figure out what MAC address the packets are coming from.
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
| The Following User Says Thank You to newtekie1 For This Useful Post: |
|
|
#18 |
![]() Join Date: Oct 2004
Location: Europe/Slovenia
Posts: 3,963 (1.26/day)
Thanks: 39
Thanked 752 Times in 540 Posts
|
That's not true. Even if you're just an individual, it's still smart to use max possible security.
Either you don't want anyone to sniff your online shopping info or worse, download for example child pr0n through your connection. In the end you'll be prosecuted. So don't take wireless security too easily. Just use WPA2 AES and just forget about any possible worries.
__________________
RejZoR's Little Secrets @ rejzor dot tk |
|
|
|
| The Following User Says Thank You to RejZoR For This Useful Post: |
|
|
#19 |
![]() Join Date: Jun 2008
Location: Japan
Posts: 290 (0.16/day)
Thanks: 42
Thanked 51 Times in 46 Posts
|
Rather related to this... im a bit perturbed at the amount of wireless devices that can connect to wireless network ONLY if the SSID is being broadcasted.
Why can't they work in the ability to connect to that network even if its not being broadcasted? ![]() Also granted that some of these encryptions are easy to break, for the most part having SOME type of security is enough of a deterient from most people who just want a quick easy access to the internet.
__________________
Being a ganker is like being a photographer, you have to wait for the right moment. Rift Miza - level 50: Ranger/Assasin/Marksman Haruna - level 32: Sentinal/Warden/Purifier Gankiskhan - level 22: Revear/Beastmaster/Paladin Briarcliff (Brocliff) server - 420 Shake Weights everyday! |
|
|
|
| The Following User Says Thank You to kuroikenshi For This Useful Post: |
|
|
#20 | |
|
Overclocked quantum bit
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,648 (4.34/day)
Thanks: 4,178
Thanked 3,303 Times in 1,943 Posts
|
Quote:
__________________
Siggie in the post. |
|
|
|
|
| The Following User Says Thank You to qubit For This Useful Post: |
|
|
#21 | |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,748 (6.48/day)
Thanks: 780
Thanked 5,115 Times in 3,706 Posts
|
Quote:
And TKIP will keep everyone off your network. Having maximum security at the expenense of a slower connection due to an overloaded router isn't smart for an individual. The kiddy porn people aren't wasting time cracking security, they are just using the free connections that are already available to them.
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
|
| The Following User Says Thank You to newtekie1 For This Useful Post: |
|
|
#22 |
![]() Join Date: Oct 2004
Location: Europe/Slovenia
Posts: 3,963 (1.26/day)
Thanks: 39
Thanked 752 Times in 540 Posts
|
What slowdown? I can't see any and i'm gaming online, downloading a lot and all. Maybe you'd notice it if you have many systems connected and you'd be using full LAN. But most of ppl use it to connect laptops wirelessly. AES is just a logical option and i really can't see a single reason not to use it. It's like deciding between a proper door lock (AES) and a wooden stick (TKIP) that's blocking it from the inside. What would you pick?
__________________
RejZoR's Little Secrets @ rejzor dot tk |
|
|
|
| The Following User Says Thank You to RejZoR For This Useful Post: |
|
|
#23 |
|
TPU Janitor
Join Date: Nov 2009
Location: Science Museum, Londinium
Posts: 5,964 (4.70/day)
Thanks: 261
Thanked 1,460 Times in 1,210 Posts
|
|
|
|
|
| The Following User Says Thank You to Fourstaff For This Useful Post: |
|
|
#24 | |
|
Semi-Retired Folder
Join Date: Nov 2005
Location: Indiana
Posts: 17,748 (6.48/day)
Thanks: 780
Thanked 5,115 Times in 3,706 Posts
|
Quote:
And your anology is a little exagerated. You make it sound like TKIP is easily broken, that is far from the case. In fact it is still extremely difficult to crack and needs some seriously powerful hardware to do it. I believe the people that did it had to use a cluster of high end computer to pull it off. It isn't something that some guy driving down the road with a laptop is going to be able to pull off. Or my connection is faster than his...
__________________
Rig1: System Specs. Rig2: A8-5600K@4.4GHz / AsRock FM2A75 Pro4 / 8GB Corsair DDR3-1600 9-9-9-24 / HD7560D / Samsung DVD-Burner / 1.5TB WD Green + 3x3TB WD RED in RAID5 Rig3: Athlon X2 4200+ / M4A79 Deluxe / 4GB G.Skill Pi DDR2-800 4-4-4-12 / GT430 / Sony DVD-Burner / 500GB WD Rig4: Phenom II x6 1605T @ 3.6GHz / Asus M5A99X Evo / 8GB PNY DDR3-1600 9-9-9 / GTX470 & GTX470 / Samsung DVD-Burner / 1.5TB Seagate |
|
|
|
|
| The Following User Says Thank You to newtekie1 For This Useful Post: |
|
|
#25 | ||
![]() Join Date: Jul 2010
Location: Philly
Posts: 1,599 (1.55/day)
Thanks: 1,004
Thanked 765 Times in 539 Posts
|
Quote:
![]() Have a look for yourself: http://arstechnica.com/tech-policy/n...ure-on-wpa.ars Quote:
__________________
Last edited by streetfighter 2; Dec 10, 2010 at 03:44 PM. |
||
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Apricorn Expands Aegis Padlock AES-Encrypted HDD Series with 750 GB Models | btarunr | News | 5 | Oct 29, 2010 09:38 AM |
| Buffalo Intros HDS-PXU2 Series Portable HDDs with Native AES Encryption | btarunr | News | 1 | Jul 16, 2010 09:05 AM |
| Patriot Readies Bolt USB Flash Drive With Native AES Encryption | btarunr | News | 2 | Mar 24, 2010 07:16 PM |
| Transcend Launches JetFlash 620 USB Flash Drive, Offer 256-bit AES Encryption | btarunr | News | 2 | Feb 16, 2010 10:30 PM |
| Fujitsu Launches New 320 GB 2.5-inch Hard Drive with AES 256-bit Encryption | malware | News | 2 | Apr 22, 2008 02:00 PM |