Hacker News new | ask | show | jobs
by icebraining 2636 days ago
"WPA and WPA2 don't provide forward secrecy, meaning that once an adverse person discovers the pre-shared key, they can potentially decrypt all packets encrypted using that PSK transmitted in the future and even past, which could be passively and silently collected by the attacker. This also means an attacker can silently capture and decrypt others' packets if a WPA-protected access point is provided free of charge at a public place, because its password is usually shared to anyone in that place. In other words, WPA only protects from attackers who don't have access to the password."

https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#Lack_of...

1 comments

Notably, this is only a problem for WPA2-PSK, not WPA2-Enterprise. But, fair enough -- this does render my first suggestion unsuitable.