Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

121–130 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#122

Earlier quoted context omitted.

and force me to use some propietary-built webkit? Nah, thank you.

If you build it yourself, you can use whatever browser you want.

Can one install their own web rendering engine on iOS?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#123

> For ordinary home users, your priority should be updating clients such as laptops and smartphones. So even if you patch all the devices in your house/company/whetever you can't be safe... Then yours aunt's un-patched android connects into your wifi and put all your network in risk. Or maybe that not-so-old security camera or SmartTV that will never be patched. Time to move all those guys to an isolated vlan...

The WPA key is not recovered so it should only affect the unpatched client.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#125

Earlier quoted context omitted.

If you build it yourself, you can use whatever browser you want.

Can one install their own web rendering engine on iOS?

In principle yes (if it is not against the app store guidelines). But if submitted as an app, it cannot use JIT compiling for security reasons. This will make the speed of JavaScript execution very non-competitive to WebKit.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#126
post #16

Earlier quoted context omitted.

The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.

The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.

Also an embargo lasting months seems excessive.

You also can not guarantee me that no one who gets this information early is not working for a bad actor.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#127

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

This is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if…

I have a HTC 10, a flagship device that's barely a year old the fact that I now have to wait a couple a months for a patch to what is clearly a critical vulnerability is just ridiculous. The fact that anyone without a flagship device should now throw that phone away because it will probably never be patched is despicable.

I totally agree with your hope that this will kick both the manufacturers and Google in the butt enough to get something done about this. I don't like our chances though!

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#128
post #67

Earlier quoted context omitted.

This is why embargoes have deadlines. To make the necessary trade-off between "patch as soon as you can, potentially jeopardising the safety of users -- even users of non-proprietary projects" and "wait for everyone to be ready before you patch -- which also jeopardises users". The embargo system deals with this by forcing everyone to agree on a date, and if someone patches after that date then too bad. You may disag…

3 months is more of a joke than a reasonable time, but one can argue about that if he wants... > even users of non-proprietary projects Actually many FOSS projects get only notified on the disclosure date. Hiding the vulnerability for such a long time makes more harm good. The vulnerability can potentially be exploited by security agencies that necessarily know about them and could also be leaked to a bad actor by an…

The state actor should be least of your worries compared to the millions of script kiddies would could use the vulnerability once it is disclosed publicly.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#130
post #82
post #56

Earlier quoted context omitted.

I wonder when the NSA and CIA was responsibly informed about this vulnerability.

OpenBSD wifi maintainer here. I was informed on July 15. The first embargo period was already quite long, until end of August. Then CERT got involved, and the embargo was extended until today. You can connect the dots. I doubt that I knew something the NSA/CIA weren't aware of.

In other words, its malfeasance by the security community for holding out.

There's only a few courses of actions. One is to sit quietly and let everyone eventually do the solution. And that doesn't work. No fire under peoples' asses, and the work is delayed.

The other, is to release it promptly. Then, at least we can decide to triage by turning down X service (even if wifi), requiring another factor like tunnel-login or what have you.

But truthfully, defect in a Prisoners Game played out here was the best choice. The rest of the community is "agree".

Post reply on HN