<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which security feature encrypts wireless data ? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265462#M22788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;your username will be passed in clear text.  I am not 100% which hashing technique is used for password with LEAP authentication(MS-CHAP,maybe) but it is not sent in clear text.  However, make a note this is one of the vulnerabilities of LEAP, Ciso released last year stating that the password was suceptible to dictionary attacks.  If you run some type of wired or wireless sniffer you will see the username passed in clear text.  After successful login, the data payload will be encrypted.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Feb 2004 07:12:40 GMT</pubDate>
    <dc:creator>pallette</dc:creator>
    <dc:date>2004-02-16T07:12:40Z</dc:date>
    <item>
      <title>Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265459#M22785</link>
      <description>&lt;P&gt;Among LEAP, MIC and TKIP, which one is responsible for encrypting wireless data ?&lt;/P&gt;&lt;P&gt;I think LEAP only authenticates users; MIC ensure no one alter the packets. TKIP makes it hard to figure out the keys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is wireless data (if someone sniffers each packet) encrypted or clear text ?&lt;/P&gt;&lt;P&gt;2. if Yes, which feature is doing this job ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks !&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265459#M22785</guid>
      <dc:creator>ewang</dc:creator>
      <dc:date>2021-07-04T16:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265460#M22786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leap does encryption . At end of leap process , wireless client and AP both independently generate &lt;/P&gt;&lt;P&gt;key based on challange and response they get .That &lt;/P&gt;&lt;P&gt;key is used to encrypt the unicast data . Beauty is &lt;/P&gt;&lt;P&gt;this key is not passed over wireless so no man in middle attack . Also after that Ap will generate broadcast key to encrypt broadcast traffic .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you sniff wireless leap encrypted data you will not able to read data portion . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2004 01:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265460#M22786</guid>
      <dc:creator>ndoshi</dc:creator>
      <dc:date>2004-02-11T01:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265461#M22787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the answer from ndoshi !&lt;/P&gt;&lt;P&gt;however, from what point, does data start to be encrypted ?&lt;/P&gt;&lt;P&gt;for example, we use NT domain login as LEAP login.&lt;/P&gt;&lt;P&gt;When I type my username &amp;amp; password from the laptop PC, do they get transmitted to AP as &lt;/P&gt;&lt;P&gt;1. clear text&lt;/P&gt;&lt;P&gt;2. or encrypted (by which key ? WEP is not revelant with leap) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2004 14:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265461#M22787</guid>
      <dc:creator>ewang</dc:creator>
      <dc:date>2004-02-11T14:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265462#M22788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;your username will be passed in clear text.  I am not 100% which hashing technique is used for password with LEAP authentication(MS-CHAP,maybe) but it is not sent in clear text.  However, make a note this is one of the vulnerabilities of LEAP, Ciso released last year stating that the password was suceptible to dictionary attacks.  If you run some type of wired or wireless sniffer you will see the username passed in clear text.  After successful login, the data payload will be encrypted.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2004 07:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265462#M22788</guid>
      <dc:creator>pallette</dc:creator>
      <dc:date>2004-02-16T07:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265463#M22789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LEAP, as with all EAP types is an authentication protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the successful conclusion of a LEAP authentication both the WLAN client and the RADIUS server dynamically derive an encryption key (the RADIUS server passes the key to the AP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until AES is ratified by the IEEE and inplemented, WEP is still the encryption protocol used on IEEE/WiFi compliant WLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WEP has several well-known cryptographic weaknesses which are fixed by TKIP and MIC.&lt;/P&gt;&lt;P&gt; -- TKIP fixes the WEP implementation of the RC4 algorithm by creating a per-packet key (by hashing the derived key and a per-packet Initialization vector). TKIP provides immunity from the "airsnort" attack amoungst others.&lt;/P&gt;&lt;P&gt; -- MIC provides message integrity Checking and provides a cryptographically strong method of ensuring that the encrypted frame has not been altered between transmission and reception.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As another poster has noted, LEAP *authentication* has proven to be vulnerable to an offline dictionary attack. To mitigate against this it is necessary to be able to enforce a strong windows password policy (one that ensures a &amp;gt;=10 character password with a mix of alphanumeric and special characters etc...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Detai;ed information of Cisco WLAN security is available at the following URL;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/go/aironet/security" target="_blank"&gt;www.cisco.com/go/aironet/security&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2004 07:55:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265463#M22789</guid>
      <dc:creator>bmcmurdo</dc:creator>
      <dc:date>2004-02-16T07:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Which security feature encrypts wireless data ?</title>
      <link>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265464#M22790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LEAP authenticates users and RADIUS server (mutual authentication) and provides dynamic WEP keys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're essentially right on TKIP and MIC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If WEP encryption is enabled, packets going through RF are encrypted by the WEP-key. TKIP provides additional security against cracking the base WEP key and if enabled ensures each packet is encrypted with a different encryption key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2004 13:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-security-feature-encrypts-wireless-data/m-p/265464#M22790</guid>
      <dc:creator>straman</dc:creator>
      <dc:date>2004-03-12T13:36:35Z</dc:date>
    </item>
  </channel>
</rss>

