$125 is all it would cost a hacker to crack your WPA3 password, researchers say

(Image credit: Pixabay via geralt (no attribution needed))

Security researchers say they have discovered several flaws in the Wi-Fi Protected Access 3 (WPA3) protocol that could allow an attacker to crack a user's password and ultimately access encrypted traffic. What's equally disturbing is that it can supposedly be done relatively fast and cheap.

WPA3 was designed in part to address a major vulnerability in WPA2 (and WPA) that had been widely used to protect wireless networks at home and in some workplaces. That specific flaw, dubbed KRACK—Key Reinstallation Attack—could allow an attacker to snoop on what is supposed to be encrypted traffic between computers and wireless access points.

The newer security protocol addressed that vulnerability and added a bunch of other protections, but it may not be as secure as we thought. In a research paper titled Dragonblood (PDF), researchers Mathy Vanhoef and Eyal Ronen say that WPA3's Simultaneous Authentication of Equals (SAE) handshake, commonly known as Dragonfly, is affected by password partitioning attacks.

"These attacks resemble [brute-force] dictionary attacks and allow an adversary to recover the password by abusing timing or cache-based side-channel leaks," the paper states.

Brute-force dictionary attacks work by attempting to guess all possible passwords and passphrases until the correct one is found, through specialized software. In this case, one of the flaws could allow an attacker to brute-force an eight-character, lowercase password.

That's worrying in and of itself, but according to the researchers, an attacker would only need $125 worth of Amazon EC2 cloud resources to pull this off. Depending on the target, that is a small price to pay.

It is just one of several flaws highlighted by the researchers.

"In light of our presented attacks, we believe that WPA3 does not meet the standards of a modern security protocol. Moreover, we believe that our attacks could have been avoided if the Wi-Fi Alliance created the WPA3 certification in a more open manner," the researchers say.

The Wi-Fi Alliance downplayed the paper's findings, saying the issues identified only exist in a "limited number of early implementations of WPA3" and "can all be mitigated through software updates." Furthermore, the Wi-Fi Alliance says there is no evidence that the vulnerabilities outlined in the research paper have actually been exploited.

What this means for you is that you should ensure your router is updated to the latest firmware, which is a good security practice regardless.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Hardware
A woman wearing a VR headset with dramatic, colourful lighting across the background
'World’s smallest LEDs' could lead to accurately lit screens with 127,000 pixels per inch and much more immersive VR
The NES themed 8BitDo Retro mechanical gaming keyboard on a blue background
I love the 8BitDo Retro C64 keyboard but I'd pick its cheaper NES-themed model near its lowest price ever during Amazon's Big Spring Sale
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node
Amazon box
Don't panic! The 'Do Not Send Voice Recordings' option Amazon just removed was only used by 0.03% of customers and they can still have it
Digital generated image of people surrounded by interactive transparent and glowing panels with data. Visualising smart technology, blockchain and artificial intelligence
Now I shall demand the cookies! Proposed new browsing agreement turns the tables and lets users dictate terms to websites
Latest in News
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened
Junah beginning a battle in Metaphor: ReFantazio.
Today's RPG fans are 'very sensitive to feeling like they wasted time' when they die, says Metaphor: ReFantazio battle planner—but Atlus still made combat hard anyway
Image of Cersei Lanniser from Game of Thrones: Kingsroad Steam early access trailer
A new Game of Thrones RPG is coming to Steam today with a cast of 'familiar faces,' which is good because it's really the only way to tell it's a GoT game at all
The new Prime Asset featured in the upcoming update for the Outlast Trials.
The Outlast Trials puts its already paranoid players under surveillance for a time-limited story event
A Viera looking confused in Final Fantasy 14.
Old armor continues to fall victim to Final Fantasy 14's bizarre two-channel dye system, unless you're super into changing the colour of teeny-tiny eyelets: 'Why even bother at this point?'
Starfield: Shattered Space
By the time Bethesda was on Starfield, you'd 'basically get in trouble' for breaking schedule, says former dev: 'A lot of the great stuff within Skyrim came from having the freedom to do what you want'