A reason to use https even for the most basic websites, including the ones embedded in IoT devices on local networks.
Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
71–80 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#72Earlier quoted context omitted.
Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/
Sounds like the researcher is at fault for putting OpenBSD on their list. If you cut a deal with someone who serially defects, at a certain point the onus shifts from them to your lack of foresight.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#73Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#74Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#75Earlier quoted context omitted.
As a user I am completely fine with that.
Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?
Which doesn't make a difference if OpenBSD still gets their patch out at the same time as everyone else. Unlike other vendors, it doesn't take OpenBSD four months to go from vulnerability notification to patch release, if you look at previous disclosure timelines they typically have a patch out in days.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#76Earlier quoted context omitted.
Sounds like the researcher is at fault for putting OpenBSD on their list. If you cut a deal with someone who serially defects, at a certain point the onus shifts from them to your lack of foresight.
The problem isn't a "fool me once shame on...fool me you don't get fooled again", because the problem is one unscrupulous party is unscrupulous to different parties and the different parties at different times are unaware of it.
Sure, but eventually you get called out on it in a public forum, like this one, and people stop giving you goodies going forward. I would consider it acceptable practice to, when considering dealing with OpenBSD (or people who are close to them), (a) withhold vulnerabilities until after the embargo date or (b) refuse to give any information unless they sign a binding non-disclosure agreement committing them to the deadline under pain of penalty. (The latter is an option because it appears, in this case, they broke the spirit if not letter of the agreement. The solution to that problem is legalese.)
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#77Earlier quoted context omitted.
> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought a…
and force me to use some propietary-built webkit? Nah, thank you.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#78Are manufacturers like linksys, d-link issuing patches now or will it be enough to have windows/os x/iOS/android updates enabled? Or do I need both?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#79Earlier quoted context omitted.
Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.
Sounds like a "we technically respected the embargo, just not in principle" sort of thing to me.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#80Earlier quoted context omitted.
True, they don't. However, this researcher has the authority to not notify the openbsd team in advance any more and he already announced that he'll keep his cards closer next time. What happens if sufficient researchers come to the same conclusion?
What happens if a vendor or researcher is in bed with the NSA and they use the exploit while embargoed? The whole thing is a shit show and really I'm rather more behind OpenBSD's approach. Edit just to expand on this as someone deleted a post .... ---- It's slightly more complicated than the prisoner's dilemma. The prisoner's dilemma doesn't account for a large facet of the problem which is being discussed here. If a…