Fair enough; "must-have" is a bit strong. But, when I'm responding to a freespace alert on one of 2000-300 servers I've never seen before, the "visualized" data layout is easier to digest than a list of numbers - plus ncdu can drill-down through a directory tree quite nicely.
Good point, but along the same lines: Namecheap existed as a registrar when I purchased my domains, and GD did not. The interface isn't enough to make me want to go through the hassle of switching.
Amazon's Simple Email Service (SES) works well for me. You can use it with any number of AWS tools, or via straight-up SMTP. Nothing fancy, and I've never had any problems with it.
WPS makes stealing the WPA PSK as trivially easy as WEP. Basically, WPS protects the WPA key with a 7-digit PIN - cracking that PIN is enough to authenticate with the router and have it provide the encryption key.
It seems like this should be easy to defend against, but everything I've ever read about WPS says no one seems to be putting any such protections in place.
Ah, you're right about only needing a single handshake. I don't make a habit of "security testing" wifi networks, but with WEP I seem to remember something about increasing the odds of your cracked key being correct based on the number of packets at your disposal. Anyway, I looked a little deeper and that's certainly not the case with WPA.
I didn't mean to imply that MitM is trivial, just that it's quicker than brute-force in many cases. And, I assumed the rogue AP was not doing true WPA encryption like the real AP, just enough to make it appear correct to get clients to connect so you can serve the fake control panel. If you need the passphrase to stand up the rogue AP, what is the point of this attack? You're not phishing for anything but the WPA key.
EDIT: just read your comment about how this actually works (that is, the "rogue" AP is just another unencrypted network.) That's actually really lame, and I withdraw my previous praise for this crack. ;)
This was my thought, too - and those that do would recognize the fake control panel.
I think it's becoming more and more common for the PSK to come on a sticker from the all-in-one router/modem your ISP sends you. So, the user never sets a passphrase, never sees the control panel, and has the key ready to hand out by just looking at their "internet box." This attack is perfect for that.
Your method sounds to me like a pretty standard PSK crack: deauth client, collect auth handshake, repeat until you have enough packets to crack the passphrase. But collecting enough packets to crack the PSK becomes more difficult as the number of clients disconnecting/reconnecting goes down and the complexity of the PSK goes up. If you're trying to connect to a home AP with a halfway-decent passphrase, it can take days (or weeks) to collect enough auth packets.
Man-in-the-middle, on the other hand, takes almost no time at all - just a gullible user with the passphrase. This method seems like it would be especially effective against most home APs, which is the same case that is less-than-ideal for the other method.
Interesting article, but I'm not entirely sure I agree with the author's attempt to explain the findings of the original study.
The paper upon which this article is based is really cool, because it scientifically confirms something that many people (myself included) already believed: mere participation in our financial industry leads to a certain degree of moral corruption. However, the author of this article goes on to make the case that the cause of such endemic dishonesty is the focus on money and number crunching required in banking.
The author's evidence seems reasonable, but doesn't match up with the original study: banking employees that work in industry "support units" (e.g., HR or risk management) showed the same tend towards dishonesty as those working in "core" units (private bankers, asset managers, etc.) This issue is directly addressed in the original study. The author's thesis suggests that working more directly with numbers/money would cause a higher degree of dishonesty, but the paper points out: "the treatment effect in core units is similar and statistically indistinguishable from the support units."
There's something more complex at work in our banking system.