WPA Encryption Explained


Recommended Posts

When you have a wireless network, it is your responsibility to make it as difficult as possible for someone else to gain access to it. After all, if someone does get in they can find out what your surfing, gain access to your computers and mess with router settings...or just use your internet connection.

Disabling SSID broadcasting and using MAC filtering is great, but can't stop someone from sniffing your traffic. WEP encryption provies a basic level of encryption, but can be cracked in under 10min.

So if you want a secure wireless network, there isn't a way around it, you need to use WPA.

Requirements

You need hardware and/or firmware/drivers that allow the use of WPA. Every wireless-G hardware out there has some form of WPA on it, but a firmware or driver update can get WPA on your older wireless-b equipment as well. Hardware that has been sold before 2003 generally need to be replaced.

Different Types

WPA Radius Authentication - Your typical home user wont use this, unless you want to setup a radius server. This server works with WPA to pass different keys to each user. I'm not going to go into how to set this up.

WPA PSK - PSK stands for Pre-Shared Key and is most commonly used by home users. The user must have a certain password to enter the network. PSK can be used with either AES or TKIP, depending on what your hardware can support. It is important that you choose a strong password to prevent against dictionary attacks.

AES - An algorithm that requires special hardware support to use. It is stronger, but a firmware/driver update won't get you AES.

TKIP - This system changes the key every specified amount of time to prevent cracking attempts. You can usually adjust how often it changes in the router/AP settings. This does not mean it changes your password, just the key.

WPA2 - The new WPA standard that uses a stronger algorithm, but is not backwards compatable with older hardware.

Making sure you got the software

Being that WinXP is the only OS that officially supports WPA2, you need to rely on 3rd party vendors for support, which is usually delivered.

Most of the time, when you install a driver for the wireless card, a special WPA driver will be installed with it. You can see it by going into the network/dialup connections in the control panel and looking at the properties of the card. It might be called something like "AEGIS WPA Protocol" or "WPA Security Protocol". Note that you cannot install updates to these protocols seperately from the drivers, your card requires specific WPA protocols to work.

post-38325-1117752184.jpg

Your router should have options for WPA in it's settings. If it does not, a firmware update could allow WPA to be enabled. Check the router's webpage to see if there is one.

If you do get a firmware update that enables WPA, I highly recommend that you restore your router's settings to factory default after upgrading the firmware. If I had known to do that I woulda saved myself a lot of trouble. :pinch:

Setting it up

First connect to the router with a patch cable rather than wirelessly. Setting up the router is easier that way. Login the router, go to the wireless security part. WPA-PSK is the type of encryption you want to use. After selecting PSK, you might get an option to either use AES or TKIP. If you had to upgrade any software to get WPA, then you probably have to use TKIP since AES requires hardware that natively supports WPA. After the selections have been made, you must choose a passphrase. Try to have it in the range of 10 to 25 characters. Once the passphrase is set, enter the same information in the wireless network card and you should be set.

post-38325-1117752250_thumb.jpg

Troubleshooting...

If WPA wont work:

1) Make sure that you have all the types and the passphrases matched exactly.

2) Try turning off/on the router or restarting.

3) If you are using the wireless config utility that comes with WinXP, try using the one that came with the card instead. You can set it by going into the properties of the network connection and unchecking "use windows to configure my wireless settings"

post-38325-1117752267.jpg

4) Sometimes using obscure characters like ąĈ??? can work against you in the passphrase.

5) If signal strength is lower than 9dB, then the connection is flaky with WPA.

6) Check to make sure the router is on fire. Fires usually interfere with the router's function.

7) If there are other wireless networks on the same channel in your area, change the channel to some different value.

8) Avoid generic drivers and firmware.

Link to comment
https://www.neowin.net/forum/topic/327471-wpa-encryption-explained/
Share on other sites

  Relativity_17 said:
Is there any software available for Windows that can tell whether you've successfully disabled SSID broadcasting on your router?

586007665[/snapback]

No, that requires the wireless utility that comes with your wireless card. All utilties come with a thing that views available wireless networks. Good adapters can show all the wireless networks in the area, if they have encryption, their signal strengh and their network name (or lack thereof). I think you can trust that SSID broadcasting is disabled and as long as you didn't leave it at "netgear" or "linksys", you're fine.

Considering that 3 of my neighbours have unencrypted networks, I'm not all too worried about someone getting into my network. The computers themselves are only open to each other, since their IPs are statically assigned from the router.

I'll look into it later on during the summer though... just for kicks.

Just a quick tip if your card does not support WPA look for the chipset that the card is and look on the internet for a company (like Dlink or Netgear) that uses the same chipset that does support WPA in there driver, install there driver over your card and you now have all there features.

My card an Asus 802.11G with only WEP 128bit encryption is convinced its a D-Link card and I now have WPA WPA-PSK WEP and so on.

  WinMacLin said:
Just a quick tip if your card does not support WPA look for the chipset that the card is and look on the internet for a company (like Dlink or Netgear) that uses the same chipset that does support WPA in there driver, install there driver over your card and you now have all there features.

My card an Asus 802.11G with only WEP 128bit encryption is convinced its a D-Link card and I now have WPA WPA-PSK WEP and so on.

586030693[/snapback]

Indeed :) Here's a link that might be useful to some. i.e. Toshiba Wireless LAN Adapter users can simply download the latest Agere driver.

  • 2 weeks later...
  kaffra said:
nice guide, i just got my netgear wireless router today. So wpa is better to have then wep?

586081494[/snapback]

Tons better. Wep can be cracked in like 15min tops. WPA is a lot stronger so long as you have a good password.

  Quote
Does the user have to always key in a password to access the network(if wpa is used?)

No.

Thanks for this guide, but I was wondering if you knew anything about steps to fix another (seemingly common) problem.

I recently set up a home wireless network in my fiance's parents' house, and set up with WPA-PSK. The router was a Linksys, I can't recall the exact model off the top of my head, but it was 802.11b only. (The notebook is capable of G, but for their purposes, that isn't really necessary, and the B router was $5 after rebate at Best Buy.)

The notebook is a Toshiba Satellite (don't remember the model either, sorry) with integrated B/G wireless, and was purchased in July of 2004. The notebook has successfully logged onto other WPA-PSK networks without having this problem. (There is a small coffee house with wi-fi that uses PSK we have connected in)

Logging in itself isn't the problem, however, every so often (probably when the key is reset), the connection is dropped, and we have to manually reconnect. Right now, the network is set to WEP, but they would really prefer to have WPA, and we cannot figure out how to correct this issue.

Just wondered if anyone had any ideas of how to start troubleshooting this, thanks!

Edit: Used TKIP when setting up

Edited by marshallbanana
  marshallbanana said:
Logging in itself isn't the problem, however, every so often (probably when the key is reset), the connection is dropped, and we have to manually reconnect. Right now, the network is set to WEP, but they would really prefer to have WPA, and we cannot figure out how to correct this issue.

586093189[/snapback]

Well your in luck because I had just about the exact same problem, with almost the same hardware (linksys router + toshiba satellite). After upgrading the firmware of the router itself, I switched to WPA, but the connection keeped dropping. I found out, after much difficulty, that it was caused by the router switching between WPA and WEP. Resetting the router settings fixed the problem. Hopefully it will fix it for you as well.

Well, WPA-PSK was available on the router without a firmware update, so I haven't done so. Would it be a good idea to try this first?

I'm not sure that resetting the router settings will do much, since the only settings changed out of the box were those concerning the SSID and setting up the encryption. I suppose it's worth a try :D

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • UK considers forcing Google to add competitor search options by David Uzondu Regulators are not playing around with Google this year. Just this April, we saw Japan take formal action against the company over Android phones, accusing the tech giant of forcing manufacturers to preinstall its search and browser apps. Now, the United Kingdom's antitrust watchdog is adding to the pressure with its own set of demands that could significantly alter how people use Google's products. The UK's Competition and Markets Authority, or CMA, wants to let users in the UK decide for themselves which search engine to use. This would come in the form of so-called "choice screens" that would appear when someone uses the Chrome browser or an Android device for the first time. In practice, this means offering a menu of different search providers, potentially even including AI assistants like ChatGPT, giving people a real opportunity to switch away from Google's default setting. To make this happen, the watchdog plans to slap Google with a special "strategic market status" designation, which means the agency gets new powers to impose very specific changes on how Google operates. The CMA is proposing this under new digital market rules designed specifically to rein in the power of large tech companies. A final decision on whether to officially give Google this label is expected by October 13. This fight over search and browser defaults is arguably more intense back home in the US, where the company is facing the possibility of having to sell off Chrome entirely after a landmark court ruling on monopoly grounds. You can bet OpenAI is very interested in that outcome, as its executives have said they would consider buying the browser if Google were ever forced to part with it. The CMA also has a few other changes in mind if its new status for Google goes through. The agency wants to ensure the company's search rankings are fair and do not unfairly penalize rivals. It also wants to give news publishers more transparency and control over how Google uses their articles and other content to train its AI models and generate those AI summaries you now see at the top of search results. Finally, the CMA is pushing for rules that would let people easily transfer their personal data, like their entire search history, to another company if they choose. According to AP News, Google sees the CMA's announcement as presenting "clear challenges" to its business in the UK. Oliver Bethell, a competition director at the company, also hinted that such strict regulations could even lead Google to delay the release of new products and features in the UK.
    • The Tick Tock of development, Hire, Fire, Rehire, Fire. Keeps the wages low and allows contract changes. I expect with AI here that will replace a tone of R&D with things like art concepts. Coding also will take a hit when the human will be the AI code checker and prompt basher. Instead of 100 programmers you can just have 2 overlooking generated code and tweaking if needed.
    • That will be an interesting comparison. My guess is that the B580 will be the more powerful card, but due to less mature game support, may be slower in some titles. Right now, the B580 is a great budget option, but when it is the same price as the RTX 5050, I suspect many users will opt for the NVidia option if it is their choice. However, a lot of OEM systems are using the B580, so users who barely understand what a dGPU is, are probably going to be using the B580.
    • Google Earth is now 20 years old, brings historical Street View imagery by Aditya Tiwari Google is no longer a young company, and many of its products have been in existence for over two decades. Its "not an April Fools joke" email service turned 21 earlier this year, and now, Google Earth is celebrating its 20th birthday. The search giant announced that Google Earth is getting historical Street View imagery to celebrate the milestone. "Now, you can access historical Street View imagery right from Google Earth — and if you use Google Earth in a professional capacity, you can easily access new datasets, like tree canopy coverage for cities, land temperatures and more," Google said in a blog post. Google Earth is well-known for offering many internet users an interactive bird's-eye view of the world at a time when mapping apps weren't as advanced. It was launched in June 2005 and features 3D buildings across major US cities, integrated local search, and 3D terrains showing mountains, valleys, and canyons around the world. Users could activate, tilt, and rotate 3D terrain for a different perspective of a location. It was an instant hit after launch, with over 100 million downloads in its first week. Just months later, Google worked with the National Oceanic and Atmospheric Administration (NOAA) to make updated imagery available to first responders battling Hurricane Katrina. However, the tech that powers Google Earth is a bit older than that. It was initially developed as Earth Viewer by Keyhole Inc., which Google acquired in 2004 and later rebranded. Now accessible via web browsers and mobile apps, Google Earth was initially available as free-to-download desktop software for Windows, Mac, and Linux. The company also offered Google Earth Pro for $399 per year, but it was later made available for free. Google Earth in 2005 Google Earth differs from Google Maps, which also debuted in 2005. While Google Earth is more focused on exploration and research, its sibling is inclined towards finding real-time information and navigation. Google Earth is known for the flying animation that appears when you go from one place to another. Not just the Earth's surface, you can also explore the ocean floor, the Moon, and Mars (via desktop app). The virtual globe app has been used to discover a rare type of coral reef off the west coast of Australia, often referred to as "the rainforest of the sea." The 2016 movie Lion told the story of a man who used Google Earth to reunite with his mother 25 years after he got separated from his family. Google Earth has seen several new features over the past two decades, including VR support, distance measuring support, the ability to create virtual tours, and Timelapse. In 2017, the 'new Google Earth' added the "I'm Feeling Lucky" button and a discovery-focused feature called Voyager. Another redesign introduced in 2023 allows professionals to evaluate building and solar design options. A feature introduced last year allows users to view historical aerial imagery of places dating back up to 80 years.
  • Recent Achievements

    • Week One Done
      Sharon dixon earned a badge
      Week One Done
    • Dedicated
      Parallax Abstraction earned a badge
      Dedicated
    • First Post
      956400 earned a badge
      First Post
    • Week One Done
      davidfegan earned a badge
      Week One Done
    • First Post
      Ainajohn earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      595
    2. 2
      ATLien_0
      223
    3. 3
      Michael Scrip
      169
    4. 4
      +FloatingFatMan
      151
    5. 5
      Som
      136
  • Tell a friend

    Love Neowin? Tell a friend!