Presentation is loading. Please wait.

Presentation is loading. Please wait.

Usability vs. Security: The Everlasting Trade-Off in the Context of Apple iOS Mobile Hotspots Andreas Kurtz, Felix Freiling, Daniel Metz Technical Report.

Similar presentations


Presentation on theme: "Usability vs. Security: The Everlasting Trade-Off in the Context of Apple iOS Mobile Hotspots Andreas Kurtz, Felix Freiling, Daniel Metz Technical Report."— Presentation transcript:

1 Usability vs. Security: The Everlasting Trade-Off in the Context of Apple iOS Mobile Hotspots Andreas Kurtz, Felix Freiling, Daniel Metz Technical Report CS-2013-02, June 2013

2 EASE OF USE v/s LEVELS OF SECURITY

3 Summary Random password generated by iOS are weak. Security can be compromised by capturing the 4-way handshake. Brech can be made in less then 49 mins.

4 Supported Devices iPhone 3GS or later iPad (3 rd Gen) WiFi + Cellular or later. iPad Mini Wifi + Cellular No. Of Connected users ?

5 Password Properties Atleast 8 characters composing of letters and numbers. Randomly generated Pre-shared key by system.

6 “alpine” Root password Jailbroken devices Access using Secure Shell(SSH)

7 How Passwords are generated ? Dictionary words + series of random numbers 8 character Limit List of 52,500 entries

8 The Attack ! WiFi connection handshake is captured. High Power GPU to brute force the Password Takes less than 49 minutes.

9 Surprising Facts Only 1,842 different entries of the Dictionary are taken. High power hardware can be available on the cloud. Same problem affects Android and Windows.

10 Criticism Can Apple handle 390,000 login attempts/ minute ? Sign of Connected Users Use of non-ASCII characters

11 Appreciation Spreading Awareness to change your Default Password.

12 Discussion Is this Apple’s problem to look after or the WiFi Alliance who set the protocols ?

13 THANK YOU ! THANK YOU !


Download ppt "Usability vs. Security: The Everlasting Trade-Off in the Context of Apple iOS Mobile Hotspots Andreas Kurtz, Felix Freiling, Daniel Metz Technical Report."

Similar presentations


Ads by Google