As Amazon.com launches two new cloud services, a security researcher has shown that the company’s cloud computing can be harnessed to break passwords. The Germany-based researcher, Thomas Roth, has demonstrated a program that runs on Amazon’s Elastic Cloud Computing (EC2) platform to crack wireless network security commonly found in homes and small businesses.
EC2, as with other cloud platforms, offers enormous computing power on demand, and Roth used this capability to test more than 400,000 possible passwords per second. The feat previously would have required supercomputing power.
Under $2
Brute-force computing has always been a possible way to crack some kinds of security systems, but until now that kind of computing power was very expensive. According to Roth, his software running on EC2 can find the average wireless password in about six minutes. At the EC2 price of 28 cents per minute, his cost for processing power was under $2 per password.
Roth has said he will make his program public, and Amazon has noted for the record that a program such as his is against its terms of use, although his test version running on EC2 is acceptable.
Amazon spokesperson Drew Herdener told news media that Roth’s work was not specific to Amazon’s environment, but that, “as researchers often do, he used EC2 as a tool to show how the security of some network configurations can be improved.”
The kinds of wireless security systems that Roth can hack use pre-shared passwords, such as the WPA-PSK system. An alphanumeric string of up to 63 characters is set up by the user as the password, and a longer password is generally considered stronger. This kind of security has counted on the fact that breaking it would require huge computing power — which, until now, didn’t seem worth the investment by the hacker.
According to some industry…