Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

141–150 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#141

"This is achieved by manipulating and replaying cryptographic handshake messages." so that means that the mac address has been spoofed to make the AP think that he is always talking to the same mac address. If I'm plugged into the router directly then i should be good because it eliminates the wifi handshake. So even though other devices on the wifi network could be affected, the node that is plugged in is safe again…

Well yeah, you'd always be safe against these types of attacks if you're wired in. Even on Ethernet.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#142

Earlier quoted context omitted.

> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought a…

and force me to use some propietary-built webkit? Nah, thank you.

Seems like a fair trade for timely security updates?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#143

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

Currently the only mitigation is to constrain your browsing to properly configured https (SSL) web sites.

Or using a VPN.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#144

"This is achieved by manipulating and replaying cryptographic handshake messages." so that means that the mac address has been spoofed to make the AP think that he is always talking to the same mac address. If I'm plugged into the router directly then i should be good because it eliminates the wifi handshake. So even though other devices on the wifi network could be affected, the node that is plugged in is safe again…

Well yeah, you'd always be safe against these types of attacks if you're wired in. Even on Ethernet.

*even on WEP Is what I meant to say. Haven't had coffee yet, sorry.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#145

Does anyone know if Apple release security fixes for Airport? I know it isn’t actively developed, but you’d hope they’d release critical security fixes as they still sell them.

The main attack targets 4-way handshakes, so doesn't target access points. You should worry about updating your clients, not your AP.

Source: https://www.krackattacks.com/

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#146
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought a…

Having switched to an iPhone recently it does bother me that you can't download iOS updates via 4G. When this gets fixed I need to turn on wifi first (or install iTunes).

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#147

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

As others suggested ensure that all communication uses TLS (be it https et al or tunnel traffic through a VPN).

Also you could install a better version of Android on your phone rather than an outdated vendor version. That will probably fix more security related issues than just this one :)

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#148

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

or waiting (hopelessly) for a patch from my vendor

If this is an actual in the wild exploitable issue, there will be patches very quickly for handsets in the support period, as quickly as there is for iOS. This has been the case repeatedly before as well.

What a weird post in general. Maybe wait to complain about this a month down the line or so? Instead it's just effectively noisy rhetoric.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#149
I'm not sure I understand the concern with breaking WiFi. Okay, so you're vulnerable to snooping and injection by people in the same coffee shop or your neighborhood. But you're already vulnerable to that from anybody on the Internet between you and the site. HTTPS solves both of these.

Am I missing something?

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#150

As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor. This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.

Currently the only mitigation is to constrain your browsing to properly configured https (SSL) web sites.

You can (try) to restrict your browsing to HTTPS sites only.

But it's very difficult to ensure that all the communications your device is making (background services, vendor apps...) go through that channel.

Post reply on HN