Dat WEP gehacked is, klopt.
===
citaat
Volgens mij was het probleem bij web 128bit toch dat het effectief maar 40bits is.
einde citaat
====
Maar dat een 128 bit versleuteling maar 40 bits effectief zou zijn lijkt me wat overtrokken.
Je haalt 2 zaken door elkaar. nl. WEP kent zowel een 40 bit ALSOOK een 128 bit versie
Executive Summary
We have discovered a number of flaws in the WEP algorithm, which seriously undermine the security claims of the system. In particular, we found the following types of attacks:
Passive attacks to decrypt traffic based on statistical analysis.
Active attack to inject new traffic from unauthorized mobile stations, based on known plaintext.
Active attacks to decrypt traffic, based on tricking the access point.
Dictionary-building attack that, after analysis of about a day's worth of traffic, allows real-time automated decryption of all traffic.
Our analysis suggests that all of these attacks are practical to mount using only inexpensive off-the-shelf equipment. We recommend that anyone using an 802.11 wireless network not rely on WEP for security, and employ other security measures to protect their wireless network.
Note that our attacks apply to both 40-bit and the so-called 128-bit versions of WEP equally well. They also apply to networks that use 802.11b standard (802.11b is an extension to 802.11 to support higher data rates; it leaves the WEP algorithm unchanged).
https://www.isaac.cs.berkeley.edu/isaac/wep-faq.html
===
Bij DES wordt een 8 byte (64bit) sleutel gebruikt die, door weglaten van het 7de bit, dus effectief 56 bit is.
RSA werkt o.a. met public keys
cittaat:
mac adres te spoofen, moet bijna elke router bezitter met chello doen.
einde citaat.
Dit is ook niet waar, spoofen is het over laten lopen van buffers met gegevens.
Bij chello KLOON je het MAC van je router, dus 100% kopieren