„submitted for review on 19 May 2017“ ... „OpenBSD was notified of the vulnerability on 15 July 2017“ Can anyone explain the timeline of releasing such significant security findings? Why is it disclosed to the public 1/2 year after submitting to review? I'd guess the (publicly funded) research behind it is a lot older than that.
Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
101–110 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#102This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#103https://git.lede-project.org/?p=source.git;a=commit;h=bbda81...
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#104As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#105Earlier quoted context omitted.
The problem isn't a "fool me once shame on...fool me you don't get fooled again", because the problem is one unscrupulous party is unscrupulous to different parties and the different parties at different times are unaware of it.
> the problem is one unscrupulous party is unscrupulous to different parties and the different parties at different times are unaware of it Sure, but eventually you get called out on it in a public forum, like this one, and people stop giving you goodies going forward. I would consider it acceptable practice to, when considering dealing with OpenBSD (or people who are close to them), (a) withhold vulnerabilities unti…
I didn't break any agreement. I agreed with Mathy on what to do, and that's what I did.
The fact that Mathy decided to get CERT involved and subsequently had to extend the embargo has nothing to do with me.
(edit: typo)
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#106Earlier quoted context omitted.
Perhaps "defect" is the wrong word given the circumstances, but the result is the same. There's a good reason for the embargo: this all takes cooperation, as it's not a Nash equilibrium. I still agree with their decision not to include OpenBSD so early in further disclosures, given Theo's short-sighted statement.
> Perhaps "defect" is the wrong word It's precisely the correct word. Prisoner's dilemma are simple, mathematically. This was one. OpenBSD defected. The joke's on the security researcher, though, since this doesn't appear to have been their first time [1][2]. Robert Axelrod outlined, in his 1984 classic The Evolution of Cooperation [3] four requirements for a successful iterative prisoner's dilemma strategy. One is r…
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#107Earlier quoted context omitted.
True, they don't. However, this researcher has the authority to not notify the openbsd team in advance any more and he already announced that he'll keep his cards closer next time. What happens if sufficient researchers come to the same conclusion?
What happens if a vendor or researcher is in bed with the NSA and they use the exploit while embargoed? The whole thing is a shit show and really I'm rather more behind OpenBSD's approach. Edit just to expand on this as someone deleted a post .... ---- It's slightly more complicated than the prisoner's dilemma. The prisoner's dilemma doesn't account for a large facet of the problem which is being discussed here. If a…
> This turns it into a security monopoly where the big vendors get exclusive rights to embargo and exclude smaller vendors and control the disclosure process on their own schedule.
Not necessarily. It turns into a monopoly of those who can show themselves to be credible partners. This exhibits incumbency bias which in social context we call track record. It's not nearly as exclusionary as you're making it out to be.
> Then there's the assumption that the monopolised vendors are trustworthy which is 100% impossible to validate and therefore invalid
This is common in trust problems. You don't need to be 100% sure everyone you're dealing with is trustworthy to work with them because we don't live in a single-iteration game. Again, iterations of retaliation and forgiveness remove the need to have 100% certainty about a player's intentions.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#108Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#109As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if I remember correctly. Hopefully a big exploit like this will be enough of a kick in the butt to get manufacturers releasing security updates faster.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#110As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
You get updates every week.