Earlier quoted context omitted.
This is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if…
I have a HTC 10, a flagship device that's barely a year old the fact that I now have to wait a couple a months for a patch to what is clearly a critical vulnerability is just ridiculous. The fact that anyone without a flagship device should now throw that phone away because it will probably never be patched is despicable. I totally agree with your hope that this will kick both the manufacturers and Google in the butt…
Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
321–330 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#322https://www.reddit.com/r/KRaCK/comments/76pjf8/krack_megathr...
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#323Earlier quoted context omitted.
Well yeah, you'd always be safe against these types of attacks if you're wired in. Even on Ethernet.
So if i use my wired in node as an ssh tunnel out to the "internets" to tunnel all traffic from my wifi connected nodes then this mitigates the issue till updates come through?
Edit: also at that time this was at least subjectively significantly easier to setup than wpa_supplicant ;)
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#324Finally a way to get all IoT devices connected to WiFi! Remember, 'S' in IoT is for Security.
One of the best quotes I've heard in a while.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#325Earlier quoted context omitted.
> Relying on your vendor for software or purchasing a device that forces you to isn't the best idea these days. Relying on the efforts of unpaid volunteers doing their best to hack together binary blobs is also not the best idea... Not all devices are supported by major ROM distributors, nor is the support guaranteed to be endless or current... (even some devices as major as the Galaxy S6 for example)
Only so much depends on those binary blobs though and changes to, for example, wpa_supplicant, happen at a much higher level.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#326Earlier quoted context omitted.
How can you state that it probably hasn't been exploited in the wild with any degree of confidence? It's possible that the same flaw was found and exploited years ago by black hat hackers and/or state security services. We have no way to know whether this actually happened, or even estimate the probability.
Because it hasn't been seen before, it's not likely that it has been exploited. Even after knowing about the flaw for a while, the Wi-Fi Alliance says there is no evidence that this was used maliciously before. https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-se... We can't know absolutely but with all the attention wifi has gotten since the days of war driving, there's a good chance it would have been caugh…
Is this attack likely to generate log evidence on affected APs in their default configuration, or is it so far down the stack that no evidence is generated and nobody could refute this claim?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#327Earlier quoted context omitted.
This is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if…
I have a HTC 10, a flagship device that's barely a year old the fact that I now have to wait a couple a months for a patch to what is clearly a critical vulnerability is just ridiculous. The fact that anyone without a flagship device should now throw that phone away because it will probably never be patched is despicable. I totally agree with your hope that this will kick both the manufacturers and Google in the butt…
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#328As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
This is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if…
That's still truly terrible compared to Apple's legacy device support. iOS 11 and future patches still support even the iPhone 5s, a phone from 2013.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#329Some resources for those who want to keep updated on vendor patch status: https://www.reddit.com/r/KRaCK/comments/76pjf8/krack_megathr... https://github.com/kristate/krackinfo
It seems like vendors need to eventually come to some consensus on how to change the protocol instead of each fixing it in their own way.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#330Earlier quoted context omitted.
Hmmn, I wasn't aware. I will have to check and see, but it is probably I have a v1, since I have had it for a while. It has always taken a bit of effort and hunting to find WiFi cards with good chipsets that support monitor mode and AP modes painlessly (for WiFi frame capture, etc.). Thanks for the info... I am a little disappointed, the ones we have been using are all very reliable and worked out of the box, so we m…
>It also seems impossible to order the older version specifically. Yep. I've been trying for a while, but couldn't be sure if what I was looking at was version 1. Especially since the Alfa alternative is bulkier.
Also, confirming, everyone even as recent as a few months back seems to have gotten a 1.0 or 1.1 version, but newer ones are now 2.0
https://imgur.com/a/jcnbE (one from my bag).