Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

21–30 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#21
post #12
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/

A bunch of dudes on a linux mailing list lack the authority to prevent openbsd from fixing things.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#22
post #11
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

LineageOS has a moderately large selection of supported phones for a custom ROM and it has weekly updates. My two and a half year old Moto E has the October 5th security patches for Android.

> My two and a half year old Moto E has the October 5th security patches for Android.

But it has very few kernel security patches: https://cve.lineageos.org/android_kernel_motorola_msm8610

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#23
post #12

Earlier quoted context omitted.

Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/

As a user I am completely fine with that.

Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#24
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

Depends on the phone. I'm using a ~ 4 year old phone with LineageOS. I also have a Russian phone whose userland source code was never released, and no open source ROM exists; this phone is swimming in vulnerabilities and languishing in Android 6.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#25
post #3

Do we now need WPA3? No, luckily implementations can be patched in a backwards-compatible manner.

It's a pity this didn't completely break WPA2 like how WEP was broken, now it will be years before there's any new security developments. Things like management frame authentication and dynamic client keys for open networks would be big improvements for the majority of use cases.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#26
post #20
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

This feels like some kind of prisoner's dilemma game theory problem. By defecting from the embargo, OpenBSD gained potential security for its users at the expense of all other users. Overall, this is a loss, unless you use OpenBSD. I have to agree with the researchers on this one; OpenBSD acted selfishly here.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#27
post #7
post #5

> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http

Or if combined with some other vulnerabilities...

Somewhat pointless remark as WPA only protects up to the access point. Any vulnerability after that has wider implications regardless of the WPA status.
Post reply on HN