Live data from Hacker News

Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

eset.com

21–30 of 31 posts

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#21
post #18

What I gathered from my quick scan of their PDF: An attacker can trigger a dissociation between the device and the access point. The dissociation causes the device to zero its temporary encryption key called the TK (transient key), which is the key used to encrypt traffic between the device and the access point. Unfortunately, some data frames still on the device could then be encrypted with this zero key and sent an…

The fact that attacker can cause dissociation is separate vulnerability slash wifi design decision. Detecting active attackers doing exactly that is in fact (literal) text book example of what statistical IDS does. The question of what exactly you are going to do if you detect such an attacker is unfortunately another matter.

Edit to add: this vulnerability essentially upgrades a class of well-known DoS attacks against WiFi networks to potential data exfiltration. On the other hand I feel like that intentionally exploiting this combination for data exfiltration by actively causing disassociations is not exactly practical attack, because you are going to cause significant disruption to operation of the network, ie. the target users are just going to give up and complain that the network is broken.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#22
post #7

Is there a proof of concept out there yet? Also, does this require a firmware patch, or can it be mitigated via software? edit: I can't reply to the comment below about iOS updates because the comment is dead, but I just would like to interject that iOS and macOS updates can, and sometimes do, contain firmware updates for hardware. The release notes for the macOS update that contains the fix doesn't specify if the fi…

Since the bug is apparently in FullMAC devices, it would be a firmware fix in most cases (unless someone is running a FullMAC device as SoftMAC for whatever reason). Also, the boundaries between firmware, hardware and (driver) software are pretty murky as far as Wi-Fi drivers are concerned: I remember reading that many FullMAC devices contain their own firmware in a ROM and have some room in on-chip RAM for patches (…

https://www.youtube.com/watch?v=4_nI9ok7iQg broadcom BT chip has limited number of patch slots, and apparently even in the newest shipping iphones they are all fully taken with bugfixes. Since BT and Wifi live on the same chip I wonder if those slots are shared.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#23
post #6

Less sensationalist and more informative link: https://nvd.nist.gov/vuln/detail/CVE-2019-15126 (CVSS Severity Base Score: 3.1 Low) Eh yeah, you shouldn't use WPA2 as your sole defence against data exfiltration. Nice way to drive traffic to your website though..

Not that I think this an especially scary vulnerability, but I wouldn't use CVSS scores as a basis for evaluating any kind of bug. CVSS is a ouija metric without any real merit.

The underlying work here is good and interesting. If companies are going to hype bugs, let it be for stuff like this!

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#24
post #4

The next time I update (wifi) routers I'm responsible for, I think I'm going to go fully Internet Only DMZ, and Wireguard 'VPN' for entry to the LAN.

How about 802.1x? It's still safe and I can do many fancy networking tricks (VLAN, etc) with it. But it's not compatible with a lot of "IOT" stuff including Chromecast.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#25
post #23
post #6

Less sensationalist and more informative link: https://nvd.nist.gov/vuln/detail/CVE-2019-15126 (CVSS Severity Base Score: 3.1 Low) Eh yeah, you shouldn't use WPA2 as your sole defence against data exfiltration. Nice way to drive traffic to your website though..

Not that I think this an especially scary vulnerability, but I wouldn't use CVSS scores as a basis for evaluating any kind of bug. CVSS is a ouija metric without any real merit. The underlying work here is good and interesting. If companies are going to hype bugs, let it be for stuff like this!

I never see Temporal Score and Environmental Score being used. I wonder if it could add nuance where needed.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#26
post #24
post #4

The next time I update (wifi) routers I'm responsible for, I think I'm going to go fully Internet Only DMZ, and Wireguard 'VPN' for entry to the LAN.

How about 802.1x? It's still safe and I can do many fancy networking tricks (VLAN, etc) with it. But it's not compatible with a lot of "IOT" stuff including Chromecast.

You might wanna hang IoT stuff in a DMZ anyway, or just not use it (especially if its a proprietary standard, like Chromecast).

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#27

Earlier quoted context omitted.

Yea makes you wonder about the bozos at Wi-Fi Alliance who designed that shit... How can you make a blunder like that?

All the way back to WEP, it's been clear that the WiFi people are much more interested in the radio-technical aspects than safety.

>WiFi people are much more interested in the radio-technical aspects than safety.

History shows us we should expect folks to build the thing then improve later.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#28
post #23
post #6

Less sensationalist and more informative link: https://nvd.nist.gov/vuln/detail/CVE-2019-15126 (CVSS Severity Base Score: 3.1 Low) Eh yeah, you shouldn't use WPA2 as your sole defence against data exfiltration. Nice way to drive traffic to your website though..

Not that I think this an especially scary vulnerability, but I wouldn't use CVSS scores as a basis for evaluating any kind of bug. CVSS is a ouija metric without any real merit. The underlying work here is good and interesting. If companies are going to hype bugs, let it be for stuff like this!

> CVSS is a ouija metric without any real merit.

Tell that to the hard working folks that define the standard, I'm sure they'll appreciate it..

Like any such metric, CVSS is far from perfect, however, in the real world you are sometimes called upon to express things in a quantitative manner even if they are better expressed in a qualitative manner, for instance when you need to justify security spending in a corporate environment, or in the context of compliance reporting. Do you know of a better tool/standard?

> If companies are going to hype bugs, let it be for stuff like this!

That's a bit like crying wolf though, isn't it? It desensitises people to actual issues and takes focus and funds away from them. This kind of fear based marketing might be useful if your goal is to suck a naive client dry for a year or so, if you are actually trying to make the world a safer place it does more harm then good.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#29
post #28
post #23

Earlier quoted context omitted.

Not that I think this an especially scary vulnerability, but I wouldn't use CVSS scores as a basis for evaluating any kind of bug. CVSS is a ouija metric without any real merit. The underlying work here is good and interesting. If companies are going to hype bugs, let it be for stuff like this!

> CVSS is a ouija metric without any real merit. Tell that to the hard working folks that define the standard, I'm sure they'll appreciate it.. Like any such metric, CVSS is far from perfect, however, in the real world you are sometimes called upon to express things in a quantitative manner even if they are better expressed in a qualitative manner, for instance when you need to justify security spending in a corporat…

Steve Christey? I have. Many times. He's fine with it. (I assume he disagrees! He's wrong!) Sorry, you'll have to find someone else to take vicarious offense for.

CVSS doesn't work, for the reasons I gave, and have given other times on HN; the search bar will help you if you want to dig in.

Re: Kr00k vuln in WiFi chips that allows unauthorized decryption of traffic

#30
post #29
post #28

Earlier quoted context omitted.

> CVSS is a ouija metric without any real merit. Tell that to the hard working folks that define the standard, I'm sure they'll appreciate it.. Like any such metric, CVSS is far from perfect, however, in the real world you are sometimes called upon to express things in a quantitative manner even if they are better expressed in a qualitative manner, for instance when you need to justify security spending in a corporat…

Steve Christey? I have. Many times. He's fine with it. (I assume he disagrees! He's wrong!) Sorry, you'll have to find someone else to take vicarious offense for. CVSS doesn't work, for the reasons I gave, and have given other times on HN; the search bar will help you if you want to dig in.

> CVSS doesn't work, for the reasons I gave

You didn't give any reasons. If you want to have a civil discourse, at least try to justify your opinions.

Post reply on HN