Jump to content

 From: http://www.zdnet.com/researchers-able-to-predict-apple-ios-generated-hotspot-passwords-7000016937/

 

...

 

"Only 1,842 different entries of that dictionary are taken into consideration. Consequently, any default password used within an arbitrary iOS mobile hotspot is based on one of these 1,842 different words."

 

This, combined with an increase in cracking hardware — a GPU cluster consisting of four AMD Radeon HD 7970s — allowed the researchers to crack any iOS hotspot with an OS-generated password within 50 seconds. Although such hardware is physically out of the reach of most users, the researchers said that similar resources are easily available through today's cloud computing technologies.

 

...

 

 

 

 

It is interesting that Apple took the approach of using a very limited set of words to generate the hotspot password.  Personally I haven't used an iPhone device, so I don't really know how the password generation works, but this is the reason I try avoid as much wireless as possible.

 

As a side note, this is the reason why I try using 16 letter/number/symbol passwords.

0b10111010 10101101 11110000 00001101

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/
Share on other sites

Link to post
Share on other sites

Yeah, this is a user issue, not Apple's.

Laptop Lenovo Thinkpad X220 - CPU: i5 2420m - RAM: 8gb - SSD: Samsung 830 - IPS screen Peripherals Monitor: Dell U2713HM - KB: Ducky shine w/PBT (MX Blue) - Mouse: Corsair M60

Audio Beyerdynamic DT990pro headphones - Audioengine D1 DAC/AMP - Swan D1080-IV speakers

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-349688
Share on other sites

Link to post
Share on other sites

Yeah, this is a user issue, not Apple's.

Well it is partially Apples fault. The fact is most users I know who own iPhones are the types who use those built in generators thinking they are safe

0b10111010 10101101 11110000 00001101

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-349775
Share on other sites

Link to post
Share on other sites

does this even matter? if you can afford 4 x 7970s you can afford a cell phone/internet and won't have to mooth of someone else 5 feet away

Case: NZXT Phantom PSU: EVGA G2 650w Motherboard: Asus Z97-Pro (Wifi-AC) CPU: 4690K @4.2ghz/1.2V Cooler: Noctua NH-D15 Ram: Kingston HyperX FURY 16GB 1866mhz GPU: Gigabyte G1 GTX970 Storage: (2x) WD Caviar Blue 1TB, Crucial MX100 256GB SSD, Samsung 840 SSD Wifi: TP Link WDN4800

 

Donkeys are love, Donkeys are life.                    "No answer means no problem!" - Luke 2015

 

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-352253
Share on other sites

Link to post
Share on other sites

Well it is partially Apples fault. The fact is most users I know who own iPhones are the types who use those built in generators thinking they are safe

That is not the case, many that uses iPhones are stupid yes but I just want a phone that is up and running fast, easy to use and RELIABLE. You can't say anything about iPhone's reliability.

If you want to join a really cool Discord chatroom with some great guys here from LTT and outside this community then PM me!

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-359907
Share on other sites

Link to post
Share on other sites

does this even matter? if you can afford 4 x 7970s you can afford a cell phone/internet and won't have to mooth of someone else 5 feet away

 

Well they used 4 cards, but you could use 1 and still get it in under a few minutes...also it is within 24 seconds, the average case I would image is closer to 12 seconds.  The issue isn't about getting free internet, but rather what you are capable of doing.  This particular article doesn't go into it, but you could perform things such as man in the middle attacks, or depending how the person setup their phone you could access certain files from the phone.

 

That is not the case, many that uses iPhones are stupid yes but I just want a phone that is up and running fast, easy to use and RELIABLE. You can't say anything about iPhone's reliability.

The issue I have with Apple in this case is generating passwords word passwords with a dictionary size of roughly 2000.  In terms of reliability of security, a company that decides to generate passwords using 2000 is irresponsible imo.  It is like making an hotspot that uses WEP encryption.  I wouldn't call iPhone users stupid just uninformed, and the fact many do use the default settings to create things like hotspots means Apple should take more care in the password generations.

0b10111010 10101101 11110000 00001101

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-361279
Share on other sites

Link to post
Share on other sites

Well they used 4 cards, but you could use 1 and still get it in under a few minutes...also it is within 24 seconds, the average case I would image is closer to 12 seconds.  The issue isn't about getting free internet, but rather what you are capable of doing.  This particular article doesn't go into it, but you could perform things such as man in the middle attacks, or depending how the person setup their phone you could access certain files from the phone.

 

The issue I have with Apple in this case is generating passwords word passwords with a dictionary size of roughly 2000.  In terms of reliability of security, a company that decides to generate passwords using 2000 is irresponsible imo.  It is like making an hotspot that uses WEP encryption.  I wouldn't call iPhone users stupid just uninformed, and the fact many do use the default settings to create things like hotspots means Apple should take more care in the password generations.

Apple slacked off there, I can see that.

If you want to join a really cool Discord chatroom with some great guys here from LTT and outside this community then PM me!

Link to comment
https://linustechtips.com/topic/27502-iphone-hotspots-vulnerable/#findComment-361469
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×