DEF CON 33 - Breaking Wi-Fi Easy Connect: A Security Analysis of DPP - George Chatzisofroniou

DEF CON 33 - Breaking Wi-Fi Easy Connect: A Security Analysis of DPP - George Chatzisofroniou

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 40:50

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation reveals multiple critical vulnerabilities in Wi-Fi Easy Connect (DPP), a protocol designed to replace WPS, showing it introduces significant security risks while prioritizing usability 1:49.

Key Takeaways:
• Wi-Fi Easy Connect allows attackers to downgrade the private introduction protocol, revealing connecting devices that should remain hidden 14:05
• Group downgrade attacks during PKEX bootstrapping force devices to use weaker cryptographic groups, making brute force attacks easier 17:17
• QR code authentication lacks mutual verification, creating an "open door" allowing unlimited device enrollment with just the QR code 21:00
• A malicious device can impersonate a configurator to obtain the privacy protection key (PPK), enabling complete network compromise through offline brute force 32:00

The migration from WPS to Wi-Fi Easy Connect shifts security responsibility to network operators while introducing new vulnerabilities 37:41.

Sources:

  • 1:49 Introduction to Wi-Fi Easy Connect protocol and purpose
  • 14:05 Private introduction protocol downgrade attack
  • 17:17 Group downgrade vulnerability in cryptographic negotiation
  • 21:00 QR code authentication lacks mutual verification
  • 32:00 Configurator impersonation attack for complete network compromise
  • 37:41 Conclusion on security issues and burden on n

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Suffren's here to talk to us a little bit about uh hacking Wi-Fi. >> Yeah. >> All right. Hello everyone. Hope you are having fun at Defcon so far. Uh I am Soprron George Sophron. Uh the presentation is about breaking Wi-Fi easy connect. It's a quite theoretical topic. I should say right so we don't have a lot of implementations here it's about attacking an abstract protocol right a popular protocol uh and a lot of uh theoretical ideas around it um so a few things about me I have conducted manual security tests penetration tests for multiple Fortune 500 companies across the world I've been focusing on Wi-Fi security for more than 10 years now um I have published novel association techniques. These are, you know, Wi-Fi association techniques. These are usually techniques that uh enable an at…