Key reinstallation attack how does it work without a pre-shared key?

The author of the key reinstallation attack released scripts on Github to test AP and clients.
To test the clients, you have to connect to a fake AP but you still need to know the pre-shared key. Of course you know the password, because y… Continue reading Key reinstallation attack how does it work without a pre-shared key?

WPA2 Enterprise: no risks for preconfigured clients when it comes to Rogue APs?

We are using, as default, PEAP and MS-CHAPv2 as inner authentication.

I was concerned with security risks when it comes to rogue APs but a colleague told me that there are no risks for preconfigured clients.

He told me there are risks on… Continue reading WPA2 Enterprise: no risks for preconfigured clients when it comes to Rogue APs?