Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

131–140 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#131
post #91

Earlier quoted context omitted.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Perhaps "defect" is the wrong word given the circumstances, but the result is the same. There's a good reason for the embargo: this all takes cooperation, as it's not a Nash equilibrium. I still agree with their decision not to include OpenBSD so early in further disclosures, given Theo's short-sighted statement.

I mean, I agree too. I sleep better not worrying about bugs that can't be fixed.

I'm mostly here just to correct misstatements of facts. You're welcome to your own interpretation, game theory optimization, etc.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#132
post #105

Earlier quoted context omitted.

> the problem is one unscrupulous party is unscrupulous to different parties and the different parties at different times are unaware of it Sure, but eventually you get called out on it in a public forum, like this one, and people stop giving you goodies going forward. I would consider it acceptable practice to, when considering dealing with OpenBSD (or people who are close to them), (a) withhold vulnerabilities unti…

Hi, I am the person you are accusing of mischief. I didn't break any agreement. I agreed with Mathy on what to do, and that's what I did. The fact that Mathy decided to get CERT involved and subsequently had to extend the embargo has nothing to do with me. (edit: typo)

I support your decision.

If Mathy was concerned, why did he wait to notify CERT? Should that not have been the first priority?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#133
post #16
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.

But have the other OS makers released patches already?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#134
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought a…

Even for a more modern smartphone. I don't want to lose access to my 32bit apps by migrating to iOS 11. So I hope a patch for iOS 10 will be made available.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#135

„submitted for review on 19 May 2017“ ... „OpenBSD was notified of the vulnerability on 15 July 2017“ Can anyone explain the timeline of releasing such significant security findings? Why is it disclosed to the public 1/2 year after submitting to review? I'd guess the (publicly funded) research behind it is a lot older than that.

July => October.

It's 3 month. It's a reasonable delay if you have to alert lots of manufacturer and they need time to roll out critical patches to lots of devices.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#136
post #58
post #39

Earlier quoted context omitted.

Unfortunately, Google has given app developers a quite powerful tool to disable the use of their apps on non-official OS images, in the form of SafetyNet. So even if you can install an open source version of Android expect a bunch of stuff to no longer work afterwards.

Magisk (/system/less root) currently passes the SafetyNet checks and it, and it's MagiskManager App, are both FL/OSS and hosted on github [0] as well as pre-built images linked from XDA [1]. I'm using it successfully with LineageOS 14.1 (Android 7.1.2). [0] https://github.com/topjohnwu [1] https://forum.xda-developers.com/apps/magisk

Which is probably a game of cat and mouse at best.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#137
post #88
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

For reference, the OpenBSD patch in question released on August 30: https://ftp.openbsd.org/pub/OpenBSD/patches/6.1/common/027_n...

tedunangst: "We asked to commit without revealing details, he said yes" "I guess he changed his mind about that after the fact."

The patch has obviously an explicit description:

"State transition errors could cause reinstallation of old WPA keys."

It's true, however, that anybody who analyzes the diffs would eventually figure that out, as Theo de Raadt argued.

My conclusion is also that the real error was even wanting to give the details to him at that moment, as there's apparently a history of him not respecting embargoes.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#138
"This is achieved by manipulating and replaying cryptographic handshake messages." so that means that the mac address has been spoofed to make the AP think that he is always talking to the same mac address.

If I'm plugged into the router directly then i should be good because it eliminates the wifi handshake. So even though other devices on the wifi network could be affected, the node that is plugged in is safe against this?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#140
post #82
post #56

Earlier quoted context omitted.

I wonder when the NSA and CIA was responsibly informed about this vulnerability.

OpenBSD wifi maintainer here. I was informed on July 15. The first embargo period was already quite long, until end of August. Then CERT got involved, and the embargo was extended until today. You can connect the dots. I doubt that I knew something the NSA/CIA weren't aware of.

Really makes me wish you'd told the world. I know all the arguments against that, but this sort of thing is no good either.
Post reply on HN