When it comes to sharing our WiFi password, two things usually happen: we either waste time explaining to the guest of the moment the subtleties between capitals, lowercase letters, and symbols, or we leave it written and stuck on a sticky note on the router, destroying its original purpose. The WPS standard presented by Cisco in 2006 became an alternative to easily create secure home networks and simplify access at the same time… but it never gained the expected traction. Why does the WPS button remain almost forgotten?

WPS Button: Why Is It on Our Routers?
WPS Button

WPS Button: Good Intentions...

Except for a few exceptions (shops or public establishments come to mind), every wireless network needs some kind of protection. This need gave rise to protocols such as WEP and WPA, but they also created a new problem: many inexperienced users found (and still find) difficulties with their configuration, and in the most extreme cases, they simply left their networks open.

Add to that other details, such as the idea of sharing access without giving the password, or enabling an “emergency route” to get into WiFi if we ever forget it. In 2006, Cisco introduced the WPS standard, Wi-Fi Protected Setup which essentially aims to solve all these issues with the press of a button. The main manufacturers in the market did not take long to adopt WPS, and we can already see this “router button” even in the modems provided by connectivity providers.

Some Technical Details

WPS Button: Why Is It on Our Routers?
This WPS button has seen a little action... (bytesin.com)

From a technical point of view, WPS enables four modes to add a new device to the WiFi network: PIN number, “Push-Button”, NFC, or USB. USB mode requires a direct physical transfer between the new client and the access point, but today it is considered obsolete. NFC is completely optional and generally not part of the specifications. “Push-Button” (that is, pressing a button on the client and on the router) and PIN number are the fundamental basis for WPS support, and by extension, the most common.

In essence, the WPS protocol works with three well-defined types of devices: the “registrar” that authorizes or rejects access to the network (it can be integrated into the access point or be independent), the “enrollee” client that seeks to join the network itself, and the access point that acts as a bridge. In the specific case of the “Push-Button” connection, the discovery process between registrar and client is automatically disabled once the connection is established, or depending on the manufacturer, after an additional delay (around 120 seconds).

WPS Button: … Bad Implementation

WPS Button: Why Is It on Our Routers?
Test of our WPS hack with WiFiSlax

Now, WPS sounds pretty good on paper… however, everything changed in December 2011, when researcher Stefan Viehböck reported a fundamental flaw in WPS PIN mode that makes it vulnerable to brute-force attacks. The hypothesis indicates that an attacker must solve 10 million combinations, but in reality, the PIN validation process splits the number in half, so the 10 million combinations become barely 11,000.

Three years later, Dominique Bongard created the Pixie Dust attack, which exploits a deficit of randomness in the main chips on the market. Today we have open, free, and easy-to-use tools that reduce the Pixie Dust attack and other similar variants to a couple of clicks. In our WiFiSlax tutorial we explore the weaknesses of WPS and share an example of a router with an already documented vulnerability.

Conclusion

WPS Button: Why Is It on Our Routers?
Some routers include the WPS PIN on their label. In certain environments, this can be interpreted as a security flaw.

Over the years, different manufacturers have developed additional mechanisms to protect WPS from external attacks. Artificial delays between requests and automatic locks after multiple failures are the order of the day, but the number one recommendation remains turning off the WPS button completely (emphasis on “recommendation”). Many routers have their security information printed on their labels (!), and as if that were not enough, we have seen routers that do not even allow WPS to be disabled. If you think your hardware falls into that category, you will need to find out if there is a firmware update that fixes it.