A city policy still allows WEP 'for old scanners' on a warehouse SSID. Why should assessors treat WEP as insecure?
Select an answer to reveal the explanation.
Short Explanation
WEP is the lock everyone learned to pick in training — not because the password was short, but because the lock design itself was flawed. Old scanners don't get a free pass on broken crypto.
Full Explanation
WEP relies on RC4 with short IVs and related design weaknesses that enable practical key recovery against real deployments. Lengthening a passphrase or hiding the SSID does not repair those cryptographic flaws. For municipal risk decisions, WEP should be classified as deprecated and insecure rather than tolerated as a permanent exception.