<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WPA no longer considered reliable?</title>
	<atom:link href="http://blog.pfsense.org/?feed=rss2&#038;p=272" rel="self" type="application/rss+xml" />
	<link>http://blog.pfsense.org/?p=272</link>
	<description>News, reviews and more related to the pfSense firewall project</description>
	<lastBuildDate>Thu, 23 May 2013 04:13:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Chris Buechler</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2382</link>
		<dc:creator>Chris Buechler</dc:creator>
		<pubDate>Mon, 24 Nov 2008 05:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2382</guid>
		<description><![CDATA[Thanks hawk, I updated the post. That was from the first day when the details weren&#039;t so clear and I never went back and reviewed the content of the post.]]></description>
		<content:encoded><![CDATA[<p>Thanks hawk, I updated the post. That was from the first day when the details weren&#8217;t so clear and I never went back and reviewed the content of the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hawk</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2381</link>
		<dc:creator>hawk</dc:creator>
		<pubDate>Mon, 24 Nov 2008 05:10:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2381</guid>
		<description><![CDATA[It&#039;s not really true that &quot;WPA2 is not affected&quot;, TKIP (the thing that has started showing cracks) is part of the WPA2 spec as well as the WPA spec.

However CCMP (AES), only mandatory in WPA2, is unaffected, so it is not as bad as it sounds.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s not really true that &#8220;WPA2 is not affected&#8221;, TKIP (the thing that has started showing cracks) is part of the WPA2 spec as well as the WPA spec.</p>
<p>However CCMP (AES), only mandatory in WPA2, is unaffected, so it is not as bad as it sounds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Ullrich</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2327</link>
		<dc:creator>Scott Ullrich</dc:creator>
		<pubDate>Mon, 17 Nov 2008 18:26:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2327</guid>
		<description><![CDATA[Just because your paranoid does not mean they are not out to get you ;)]]></description>
		<content:encoded><![CDATA[<p>Just because your paranoid does not mean they are not out to get you <img src='http://blog.pfsense.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RasKal</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2326</link>
		<dc:creator>RasKal</dc:creator>
		<pubDate>Mon, 17 Nov 2008 08:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2326</guid>
		<description><![CDATA[Fully agree with p1nged and I&#039;d also use x509 user certificate if L2TP/IPSec is not an option.
Bgrds.]]></description>
		<content:encoded><![CDATA[<p>Fully agree with p1nged and I&#8217;d also use x509 user certificate if L2TP/IPSec is not an option.<br />
Bgrds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: p1nged</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2284</link>
		<dc:creator>p1nged</dc:creator>
		<pubDate>Sun, 09 Nov 2008 03:37:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2284</guid>
		<description><![CDATA[yea, what blak111 said is true... they broke TKIP

in any case, the most secure for now is WPA2-Enterprise with AES &amp; RADIUS authenication + using an L2TP/IPSec VPN on top of that... can all be done using pfsense

thats just being paranoid, but maybe required for certain applications]]></description>
		<content:encoded><![CDATA[<p>yea, what blak111 said is true&#8230; they broke TKIP</p>
<p>in any case, the most secure for now is WPA2-Enterprise with AES &amp; RADIUS authenication + using an L2TP/IPSec VPN on top of that&#8230; can all be done using pfsense</p>
<p>thats just being paranoid, but maybe required for certain applications</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: resmo</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2271</link>
		<dc:creator>resmo</dc:creator>
		<pubDate>Fri, 07 Nov 2008 07:34:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2271</guid>
		<description><![CDATA[I wonder why people are so surprised about this &quot;WPA cracked&quot; story. Anybody knows WPA is WEP improved and so this can&#039;t not be secure.

I think the reason is, that WPA and WPA2 looks almost like the same for common people. They only see WPA and remember they also used something called WPA, obviously WPA2 and start screaming.]]></description>
		<content:encoded><![CDATA[<p>I wonder why people are so surprised about this &#8220;WPA cracked&#8221; story. Anybody knows WPA is WEP improved and so this can&#8217;t not be secure.</p>
<p>I think the reason is, that WPA and WPA2 looks almost like the same for common people. They only see WPA and remember they also used something called WPA, obviously WPA2 and start screaming.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Buechler</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2266</link>
		<dc:creator>Chris Buechler</dc:creator>
		<pubDate>Fri, 07 Nov 2008 01:31:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2266</guid>
		<description><![CDATA[I updated Scott&#039;s post with some additional information.]]></description>
		<content:encoded><![CDATA[<p>I updated Scott&#8217;s post with some additional information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blak111</title>
		<link>http://blog.pfsense.org/?p=272&#038;cpage=1#comment-2265</link>
		<dc:creator>blak111</dc:creator>
		<pubDate>Thu, 06 Nov 2008 23:39:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=272#comment-2265</guid>
		<description><![CDATA[I believe this weakness is just with TKIP, which was just basically WEP on steroids. It&#039;s very similar to WEP to avoid conflicts with needing better drivers or better hardware to support anything better like AES.]]></description>
		<content:encoded><![CDATA[<p>I believe this weakness is just with TKIP, which was just basically WEP on steroids. It&#8217;s very similar to WEP to avoid conflicts with needing better drivers or better hardware to support anything better like AES.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
