WPA3 Vulnerable to Password-Stealing Attacks, Claim Researchers

Advertisement
By Gadgets 360 Staff | Updated: 12 April 2019 12:09 IST
Highlights
  • WPA3’s SAE handshake includes several design flaws
  • WPA3 was unveiled in early 2018, 14 years after WPA2
  • The affected devices are said to be already receiving patches

WPA3, which was released in 2018, was supposed to prevent password-stealing attacks

Wi-Fi Protected Access 3 (WPA3), the next generation wireless security protocol, is affected by several design flaws that make it vulnerable to attacks, researchers have claimed. Released in early 2018, over a decade after WPA2, the WPA3 was touted to be packing several security enhancements but the new revelations show that the security protocol is hardly invulnerable to password partitioning attacks. Wi-Fi Alliance, the industry body that oversees the wireless security protocols and security certification programs, has acknowledged the existence of these vulnerabilities and it says that the device manufacturers have already started releases patches for the problem.

According to a research paper published by Mathy Vanhoef of New York University, Abu Dhabi, and Eyal Ronen of Tel Aviv University, the WPA3's Simultaneous Authentication of Equals (SAE) handshake, commonly known as Dragonfly, is vulnerable to password partitioning attacks, which can be used to recover the password to a Wi-Fi network. The SAE handshake was introduced in WPA3 for the home networks to prevent dictionary attacks but it has been found having both timing and cache-based side-channel vulnerabilities in its password encoding method.

Advertisement

These vulnerabilities, referred to as Dragonblood, allowed the researchers to successfully guess the passwords of wireless networks protected with WPA3 security. The researchers blame the lack of transparency in the creation of the WPA3 standard for these vulnerabilities. To recall, Vanhoef was also credited with finding the KRACK security flaw. WPA2 security was found to be vulnerable to KRACK attacks in October 2017. Major operating system makers like Microsoft, Apple, and Google soon after developed patches for their systems. Notably, KRACK bug was one of reasons why WPA3 was developed. 

“In light of our presented attacks, we believe that WPA3 does not meet the standards of a modern security protocol. Moreover, we believe that our attacks could have been avoided if the Wi-Fi Alliance created the WPA3 certification in a more open manner,” Mathy Vanhoef of New York University, Abu Dhabi, and Eyal Ronen of Tel Aviv University and KU Leuven stated in the research paper.

Advertisement

Following the publication of the research paper, the Wi-Fi Alliance came out and accepted the findings. It also noted that affected device manufacturers are already releasing patches for the same.

“Recently published research identified vulnerabilities in a limited number of early implementations of WPA3-Personal, where those devices allow collection of side channel information on a device running an attacker's software, do not properly implement certain cryptographic operations, or use unsuitable cryptographic elements,” Wi-Fi Alliance said in a statement. “WPA3-Personal is in the early stages of deployment, and the small number of device manufacturers that are affected have already started deploying patches to resolve the issues. These issues can all be mitigated through software updates without any impact on devices' ability to work well together. There is no evidence that these vulnerabilities have been exploited.”

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Big Billion Days Sale: Oppo Find X9 Ultra, K14x, More Oppo Deals Revealed
  2. Google Fitbit Air With Continuous Heart Rate Tracking Debuts in India
  3. Apple Pay Finally Arrives in India With Axis Bank as Its First Partner
  4. Flipkart Big Billion Days Sale 2026: Galaxy S25 FE, Galaxy S25 and More to Get Discounts
  5. Jio Launches Anniversary Offer on JioBharat 4G Phones at Rs. 1,499
  1. Windows 11 Version 26H2 Released With Taskbar Improvements, File Explorer Features, More
  2. Fireflies.ai Launches Talk for Voice Dictation Across Email, Slack, Documents and More
  3. Bitget Hackers Transfer $4 Million to Zcash Privacy Pool to Hide Funds
  4. Samsung Galaxy Tab S12 Ultra, Galaxy Tab S12+ Launched With MediaTek Dimensity 9500 SoC: Price, Specifications
  5. Microsoft's Disc-to-Digital Program for Xbox Games Rolls Out to All Users
  6. OpenAI Launches ChatGPT Space to Create, Organise Pages and Collaborate on Documents
  7. Kalshi to Remove Volume Rewards as $5 Billion in Trading Faces Review
  8. Anthropic Warns AI May Pose 'Existential Risks to Humanity' in IPO Filing
  9. Oppo K15s, K15x Launched With Up to 8,000mAh Batteries, 120Hz Displays: Price, Features
  10. Jio Offers JioBharat 4G Phones for Rs. 1,499 With 6 Months of Unlimited Calls and Data as Part of 10th Anniversary Offer
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.