It seems like it might be time to configure my mobile devices (e.g. phones and laptops) to use my newly configured Wireguard VPN even when using my own WPA2-PSK (AES) wifi at home.
back
3 comments
Deploying WPA2-Enterprise is also an option, which is what I've done myself at home. There's plenty of affordable ways to do this - white box pfSense (install the FreeRADIUS package) + AP that supports WPA2-Ent, going full Ubiquiti with a UniFi Security Gateway + UniFi AP (you can just run the controller on your machine, a raspberry pi or a $5/mo VPS).
I have a small server rack at home so I've got a significantly more complicated (and expensive) setup that I wouldn't recommend to even the average reader on HN unless they were interested in the whole homelab thing.
You can't eavesdrop on other wifi users with this attack. This just gets you the wifi password.
Edit: There is another kind of attack that could extend this though. An attacker sets up an AP with the same SSID, and the same password (using the new attack). Then they kick you off the real network with a deauth attack and hope your device reconnects to theirs.
WPA2 doesn't have forward secrecy [1]
[1] https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#Lack_of...
I'm not an expert, but wouldn't they have to sniff the four-way handshake for that to work? This new attack specifically doesn't do that.
Am I correct that the attack your describing is what's commonly called an Evil Twin Attack?
Not trusting the network is especially helpful because routers tend to have security issues at an alarming rate and poor update cycles. Forget WPA2 being crackable; the router itself is in a botnet.