Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

61–70 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#61

Earlier quoted context omitted.

As far as I understood, this attack has no client-side mitigation that could be employed other than treating every wifi as an open network. The attack might already be known to hostile actors or may have become known during the embargo, but full disclosure without an embargo would guarantee that clients are at risk without mitigation. An embargo at least gives time to prep patches and protect at least a portion of th…

Either there is a possibility for patches to be prepared during an embargo or there is “no client-side mitigation”, you can’t have both. From reading the rest of this thread, it appears that it is quite possible to patch this on clients such that, if you are using a patched client, you are safe. Disclosing earlier would have lead to more people having patched clients earlier and hence being safe.

Patching the client is a fix. Mitigation would bea config setting that makes me safer (disable some unused functionality,...). So yes, you can have both.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#62

"This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on." As much as this is a scare tactic to get people to demand vendor patches, it's been true for https for a while. Browsers don't have any trick (that I know of) to enforce https on first connection. HSTS is defeated by simply rejecting connections to https - the user will retry the site…

All major browsers implement a HSTS preload list[1] to get around the first connection problem. Manually deleting the HSTS pin for a site is quite involved and not something I'd expect most users to do.

[1]: https://hstspreload.org/

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#64
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

Author doesn't know what FreeBSD, Debian and OpenBSD people cooperate and share knowledge, so most probably OpenBSD developers will know about the issues, just not from an "official" email.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#65

Earlier quoted context omitted.

Either there is a possibility for patches to be prepared during an embargo or there is “no client-side mitigation”, you can’t have both. From reading the rest of this thread, it appears that it is quite possible to patch this on clients such that, if you are using a patched client, you are safe. Disclosing earlier would have lead to more people having patched clients earlier and hence being safe.

Patching the client is a fix. Mitigation would bea config setting that makes me safer (disable some unused functionality,...). So yes, you can have both.

That’s like saying that prior to introducing seatbelts, we should have allowed for a period of time to glue people to their seats because it is preferable to have a mitigation they can apply themselves than a fix the manufacturer has to put in.

If you don’t limit mitigation to "a config setting" (and why would you?!), a patch/new version is the best mitigation you can get.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#66

Earlier quoted context omitted.

A bunch of dudes on a linux mailing list lack the authority to prevent openbsd from fixing things.

True, they don't. However, this researcher has the authority to not notify the openbsd team in advance any more and he already announced that he'll keep his cards closer next time. What happens if sufficient researchers come to the same conclusion?

What happens if a vendor or researcher is in bed with the NSA and they use the exploit while embargoed?

The whole thing is a shit show and really I'm rather more behind OpenBSD's approach.

Edit just to expand on this as someone deleted a post ....

----

It's slightly more complicated than the prisoner's dilemma. The prisoner's dilemma doesn't account for a large facet of the problem which is being discussed here. If all the good parties participate and coordinate then we're better off. The problem is there are outlying circumstances which means that not everyone will be included:

1. If someone kicks someone out (OpenBSD) on political whim playing CYA, they no longer benefit.

2. If a party is not let in, they no longer benefit.

3. If someone is unaware of it, they don't benefit.

This turns it into a security monopoly where the big vendors get exclusive rights to embargo and exclude smaller vendors and control the disclosure process on their own schedule.

The first thing the people outside of the club find is they wake up on Monday morning and have to clear up a shitstorm of monumental proportions with less resources than the monopolised vendors who've had time to deal with it.

Then there's the assumption that the monopolised vendors are trustworthy which is 100% impossible to validate and therefore invalid.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#67
post #16

Earlier quoted context omitted.

The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.

You got everything wrong. If big vendors are unable to patch their proprietary products in an acceptable time, that shouldn't put others at risk. Users shouldn't choose their products... Think about it in a different way: What if a vulnerability was discovered in TLS and FOSS implementations patched it, but there is an embargo for supposedly protecting some banking software? What if NSA/CIA/other agencies find out ab…

This is why embargoes have deadlines. To make the necessary trade-off between "patch as soon as you can, potentially jeopardising the safety of users -- even users of non-proprietary projects" and "wait for everyone to be ready before you patch -- which also jeopardises users". The embargo system deals with this by forcing everyone to agree on a date, and if someone patches after that date then too bad. You may disagree that the deadline was so long, and that could be a fair criticism.

But pretending as though co-ordination of any kind is somehow bad (and then resorting to emotional arguments and so on) is pretty reckless.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#68
post #23

Earlier quoted context omitted.

As a user I am completely fine with that.

Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?

What about the vulnerabilities that OpenBSD notice? Works both ways. And they have an active interest in such things and have discovered as much as any famous-for-five-minutes security researcher.
Post reply on HN