Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

81–90 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#81
post #68
post #23

Earlier quoted context omitted.

Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?

What about the vulnerabilities that OpenBSD notice? Works both ways. And they have an active interest in such things and have discovered as much as any famous-for-five-minutes security researcher.

> [OpenBSD] have discovered as much as any famous-for-five-minutes security researcher

TL; DR OpenBSD acted rationally if they'd prefer to go it alone, which seems to be their culture. To their credit, it's worked pretty well so far. But you can't have your cake and eat it too. If they prefer a mad scramble after public disclosure, they'll get it. But they shouldn't get early notice from responsible researchers.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#82
post #56

Earlier quoted context omitted.

The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.

I wonder when the NSA and CIA was responsibly informed about this vulnerability.

OpenBSD wifi maintainer here.

I was informed on July 15.

The first embargo period was already quite long, until end of August. Then CERT got involved, and the embargo was extended until today.

You can connect the dots.

I doubt that I knew something the NSA/CIA weren't aware of.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#83

Earlier quoted context omitted.

A bunch of dudes on a linux mailing list lack the authority to prevent openbsd from fixing things.

True, they don't. However, this researcher has the authority to not notify the openbsd team in advance any more and he already announced that he'll keep his cards closer next time. What happens if sufficient researchers come to the same conclusion?

I am generally ok with that. Embargoes are retarded.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#84
post #66

Earlier quoted context omitted.

True, they don't. However, this researcher has the authority to not notify the openbsd team in advance any more and he already announced that he'll keep his cards closer next time. What happens if sufficient researchers come to the same conclusion?

What happens if a vendor or researcher is in bed with the NSA and they use the exploit while embargoed? The whole thing is a shit show and really I'm rather more behind OpenBSD's approach. Edit just to expand on this as someone deleted a post .... ---- It's slightly more complicated than the prisoner's dilemma. The prisoner's dilemma doesn't account for a large facet of the problem which is being discussed here. If a…

Yeah, the hysterical part is how people think distros is leak proof. It just doesn't leak in nice public ways to allow "responsible white hats" to wag their fingers. Raise your hand if you can say you confidently know the full back channel distribution of a notification to distros.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#85
Quick googling found out that at least one guy did come very close to realizing that 4-way handshake should have hard replay protection: http://slideplayer.com/slide/5762070/

On page 30 of the presentation: "Authenticator may (or may not) re-use ANonce"

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#86
post #62

"This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on." As much as this is a scare tactic to get people to demand vendor patches, it's been true for https for a while. Browsers don't have any trick (that I know of) to enforce https on first connection. HSTS is defeated by simply rejecting connections to https - the user will retry the site…

All major browsers implement a HSTS preload list[1] to get around the first connection problem. Manually deleting the HSTS pin for a site is quite involved and not something I'd expect most users to do. [1]: https://hstspreload.org/

Preload lists are not a realistic solution (you can't preload the whole internet) and a sufficiently complicated site will be subverted due to 3rd party dependencies. And does uninstalling a browser not clear the hsts cache?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#87

Earlier quoted context omitted.

The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.

As far as I understood, this attack has no client-side mitigation that could be employed other than treating every wifi as an open network. The attack might already be known to hostile actors or may have become known during the embargo, but full disclosure without an embargo would guarantee that clients are at risk without mitigation. An embargo at least gives time to prep patches and protect at least a portion of th…

> As far as I understood, this attack has no client-side mitigation that could be employed other than treating every wifi as an open network.

I've been doing that for years and recommend others do so as well.

The rise of HTTPS nearly everywhere helps mitigate things a bit. This same type of exploit 5 years ago would wreak havoc exploited at the local Starbucks WiFI.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#88
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

For reference, the OpenBSD patch in question released on August 30: https://ftp.openbsd.org/pub/OpenBSD/patches/6.1/common/027_n...

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#89
post #66

Earlier quoted context omitted.

What happens if a vendor or researcher is in bed with the NSA and they use the exploit while embargoed? The whole thing is a shit show and really I'm rather more behind OpenBSD's approach. Edit just to expand on this as someone deleted a post .... ---- It's slightly more complicated than the prisoner's dilemma. The prisoner's dilemma doesn't account for a large facet of the problem which is being discussed here. If a…

Yeah, the hysterical part is how people think distros is leak proof. It just doesn't leak in nice public ways to allow "responsible white hats" to wag their fingers. Raise your hand if you can say you confidently know the full back channel distribution of a notification to distros.

Exactly that!

No bullshit please - you guys do a wonderful job of avoiding it and stamping on it when it does turn up. Keep up the good work :)

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#90
post #68

Earlier quoted context omitted.

What about the vulnerabilities that OpenBSD notice? Works both ways. And they have an active interest in such things and have discovered as much as any famous-for-five-minutes security researcher.

> [OpenBSD] have discovered as much as any famous-for-five-minutes security researcher TL; DR OpenBSD acted rationally if they'd prefer to go it alone, which seems to be their culture. To their credit, it's worked pretty well so far. But you can't have your cake and eat it too. If they prefer a mad scramble after public disclosure, they'll get it. But they shouldn't get early notice from responsible researchers.

See my comment here. It sort of replies to this anyway: https://news.ycombinator.com/item?id=15482285

I don't believe that embargo is healthy or responsible! If anything its a monopolising factor.

Post reply on HN