Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

171–180 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#171
post #82

Earlier quoted context omitted.

OpenBSD wifi maintainer here. I was informed on July 15. The first embargo period was already quite long, until end of August. Then CERT got involved, and the embargo was extended until today. You can connect the dots. I doubt that I knew something the NSA/CIA weren't aware of.

Really makes me wish you'd told the world. I know all the arguments against that, but this sort of thing is no good either.

Yes, but that would result in them not getting notified for any other vulnerability.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#172

This is not an end-of-the-world type vulnerability. 1. Does not affect long-term credentials - certs, wifi passwords are still safe. Rather, confidentiality (secrecy) from client --> AP is affected, and in some cases packet forgery is possible (integrity). 2. Actually accomplishing this attack, for now, requires special and expensive hardware (med to high range SDR gear). Its also not that reliable outside of a lab e…

Also doesn't it require the attacker to have access to your wifi already? If that's the case, it's a hazard for connecting in a Starbucks or on your mobile service wifi, but you would be safe on your home or corporate wifi (unless the attacker is a colleague or relative!).

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#173

Does anyone know if Apple release security fixes for Airport? I know it isn’t actively developed, but you’d hope they’d release critical security fixes as they still sell them.

The main attack targets 4-way handshakes, so doesn't target access points. You should worry about updating your clients, not your AP. Source: https://www.krackattacks.com/

Fortunately most access points will be fine, but those performing client functions (eg repeaters) will need updating.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#175
post #134

Earlier quoted context omitted.

Even for a more modern smartphone. I don't want to lose access to my 32bit apps by migrating to iOS 11. So I hope a patch for iOS 10 will be made available.

Out of interest, what apps are you using that are still 32bit only?

Tetris. And I use it probably more (in term of time spent) than Facebook, safari and emails together!

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#176

Earlier quoted context omitted.

3 months is more of a joke than a reasonable time, but one can argue about that if he wants... > even users of non-proprietary projects Actually many FOSS projects get only notified on the disclosure date. Hiding the vulnerability for such a long time makes more harm good. The vulnerability can potentially be exploited by security agencies that necessarily know about them and could also be leaked to a bad actor by an…

The state actor should be least of your worries compared to the millions of script kiddies would could use the vulnerability once it is disclosed publicly.

No as I would know about it by following security news?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#177

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

or waiting (hopelessly) for a patch from my vendor If this is an actual in the wild exploitable issue, there will be patches very quickly for handsets in the support period, as quickly as there is for iOS. This has been the case repeatedly before as well. What a weird post in general. Maybe wait to complain about this a month down the line or so? Instead it's just effectively noisy rhetoric.

The support period for an iPhone is at least 3 years of regular patches and feature updates. Most Android phones on the market will have a 'support period' of 12 months if you're lucky. My point is that the roll-out of updates to Android is unacceptably poor and inconsistent and relies on optimism on the part of the user.

The use of the word hopelessly was probably unnecessarily dramatic I agree but I'll leave it there so your comment makes sense.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#178

I'm not sure I understand the concern with breaking WiFi. Okay, so you're vulnerable to snooping and injection by people in the same coffee shop or your neighborhood. But you're already vulnerable to that from anybody on the Internet between you and the site. HTTPS solves both of these. Am I missing something?

How encrypted is your average home network, really?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#180
post #172

This is not an end-of-the-world type vulnerability. 1. Does not affect long-term credentials - certs, wifi passwords are still safe. Rather, confidentiality (secrecy) from client --> AP is affected, and in some cases packet forgery is possible (integrity). 2. Actually accomplishing this attack, for now, requires special and expensive hardware (med to high range SDR gear). Its also not that reliable outside of a lab e…

Also doesn't it require the attacker to have access to your wifi already? If that's the case, it's a hazard for connecting in a Starbucks or on your mobile service wifi, but you would be safe on your home or corporate wifi (unless the attacker is a colleague or relative!).

Totally safe, until your local war-driver sniffs out your insecure device and comes back at two in the morning to upload illegal content via your ISP.
Post reply on HN