Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
311–320 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#312As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
Pray for a vendor patch. The fix landed today in the hostap repository: https://w1.fi/cgit/hostap/commit/?id=a00e946c1c9a1f9cc65c729...
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#313The research talks a lot about how it somewhat depends on the implementation of the wireless client, but only in regards to Linux and OpenBSD, anybody know what the status on the Windows implementation is?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#314Earlier quoted context omitted.
Install one of the major ROMs like AOSP or LineageOS. Relying on your vendor for software or purchasing a device that forces you to isn't the best idea these days.
> Relying on your vendor for software or purchasing a device that forces you to isn't the best idea these days. Relying on the efforts of unpaid volunteers doing their best to hack together binary blobs is also not the best idea... Not all devices are supported by major ROM distributors, nor is the support guaranteed to be endless or current... (even some devices as major as the Galaxy S6 for example)
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#315Earlier quoted context omitted.
There has always been a rule for bug-fix and security updates: Apply the minimum necessary change to solve the problem. This means cherry-picking the mainline patches where possible, or back-porting them where modification is required for them to apply (and work as intended) on older releases. Especially with older versions it often isn't possible to update to a later upstream release because that depends on later ve…
where do i go to get the patch? i looked here and i don't know where to pick up the patch also ran update manager in my ubuntu distro but no dice :( https://bugs.launchpad.net/ubuntu/+source/wpa/+bug/1723909 http://people.canonical.com/~ubuntu-security/cve/pkg/wpa.htm...
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#316As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#317Earlier quoted context omitted.
This is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if…
I have a HTC 10, a flagship device that's barely a year old the fact that I now have to wait a couple a months for a patch to what is clearly a critical vulnerability is just ridiculous. The fact that anyone without a flagship device should now throw that phone away because it will probably never be patched is despicable. I totally agree with your hope that this will kick both the manufacturers and Google in the butt…
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#318I'm not sure I understand the concern with breaking WiFi. Okay, so you're vulnerable to snooping and injection by people in the same coffee shop or your neighborhood. But you're already vulnerable to that from anybody on the Internet between you and the site. HTTPS solves both of these. Am I missing something?
In practice, the points where you're most susceptible to MITM/interception are the initiation and termination endpoints. Most of these connections terminate in a data center/hosting providers, which should generally have decent security and plenty of disincentives for snooping. However, homes, coffee shops, airports, etc -- those are places where someone could execute this attack successfully. You're right that any t…
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#319Earlier quoted context omitted.
Agreed. Not specialized equipment. Just something that lets you shoot raw frames and run as a WiFi AP. I have 2 such USB WiFi dongles in my bag for setting up such environments. Give: http://www.tp-link.com/us/products/details/cat-5520_TL-WN722... a shot. It will let you setup an AP in a VM easily, etc. It is our currently anointed dongle for VM hosted MiTM setups. I haven't tested it, but it should work fine if they…
Note that there are two versions of that dongle. The version 1 has Atheros Chip[1] with the best wi-fi support but version 2 has a Realtek chip[2] with subpar support. AFAIK it isn't possible to get version 1 of the dongle today. My suggestion is Alfa AWUS036NHA (The last three letters are important!) which has AR9271 chip with great support with the ath9k driver. [1]: https://wikidevi.com/wiki/TP-LINK_TL-WN722N [2]:…
Thanks for the info... I am a little disappointed, the ones we have been using are all very reliable and worked out of the box, so we must have the Atheros ones. It also seems impossible to order the older version specifically.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#320Earlier quoted context omitted.
Note that there are two versions of that dongle. The version 1 has Atheros Chip[1] with the best wi-fi support but version 2 has a Realtek chip[2] with subpar support. AFAIK it isn't possible to get version 1 of the dongle today. My suggestion is Alfa AWUS036NHA (The last three letters are important!) which has AR9271 chip with great support with the ath9k driver. [1]: https://wikidevi.com/wiki/TP-LINK_TL-WN722N [2]:…
Hmmn, I wasn't aware. I will have to check and see, but it is probably I have a v1, since I have had it for a while. It has always taken a bit of effort and hunting to find WiFi cards with good chipsets that support monitor mode and AP modes painlessly (for WiFi frame capture, etc.). Thanks for the info... I am a little disappointed, the ones we have been using are all very reliable and worked out of the box, so we m…
Yep. I've been trying for a while, but couldn't be sure if what I was looking at was version 1. Especially since the Alfa alternative is bulkier.