Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
1–10 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#2Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#3No, luckily implementations can be patched in a backwards-compatible manner.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#4Do we now need WPA3? No, luckily implementations can be patched in a backwards-compatible manner.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#5... if transmitted over plaintext http
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#6Anyone got any suggestions for options?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#7> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#8Do we now need WPA3? No, luckily implementations can be patched in a backwards-compatible manner.
The problem is that tons and tons of devices will not receive update until they die.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#9Why did OpenBSD silently release a patch before the embargo?
OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure deadline: "In the open source world, if a person writes a diff and has to sit on it for a month, that is very discouraging". Note that I wrote and included a suggested diff for OpenBSD already, and that at the time the tentative disclosure deadline was around the end of August. As a compromise, I allowed them to silently patch the vulnerability. In hindsight this was a bad decision, since others might rediscover the vulnerability by inspecting their silent patch. To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#10"Because Android uses wpa_supplicant, Android 6.0 and above also contains this vulnerability. This makes it trivial to intercept and manipulate traffic sent by these Linux and Android devices. Note that currently 41% of Android devices are vulnerable to this exceptionally devastating variant of our attack."