Earlier quoted context omitted.
The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.
The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.
Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
51–60 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#52Earlier quoted context omitted.
Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/
" As a compromise, I allowed them to silently patch the vulnerability. " The way I read that they broke no embargo
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#53As much as this is a scare tactic to get people to demand vendor patches, it's been true for https for a while.
Browsers don't have any trick (that I know of) to enforce https on first connection. HSTS is defeated by simply rejecting connections to https - the user will retry the site from different devices and destroy their hsts cache in order to reach the site. Assuming the site used hsts.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#54Earlier quoted context omitted.
They agreed, but now they regret the decision and wouldn't make it again. To prevent themselves from doing so, they will not speak with OpenBSD until later in the process.
What's the word for pressuring a person until they make a decision they immediately regret?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#55> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http
Note that in the demo video they use SSLStrip to cancel attempts of websites to switch to https. The only protection here is HSTS (which is not enabled by most websites, but major ones like banks will usually have them) and manually typing https:// in your address.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#56Earlier quoted context omitted.
The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.
The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#57Earlier quoted context omitted.
The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.
As far as I understood, this attack has no client-side mitigation that could be employed other than treating every wifi as an open network. The attack might already be known to hostile actors or may have become known during the embargo, but full disclosure without an embargo would guarantee that clients are at risk without mitigation. An embargo at least gives time to prep patches and protect at least a portion of th…
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#58Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?
Unfortunately, Google has given app developers a quite powerful tool to disable the use of their apps on non-official OS images, in the form of SafetyNet. So even if you can install an open source version of Android expect a bunch of stuff to no longer work afterwards.
I'm using it successfully with LineageOS 14.1 (Android 7.1.2).
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#59It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…
Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#60It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…
The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.
Think about it in a different way: What if a vulnerability was discovered in TLS and FOSS implementations patched it, but there is an embargo for supposedly protecting some banking software? What if NSA/CIA/other agencies find out about it (they would know immediately) and use it to target users/activists?