Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

31–40 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#31
post #12
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/

"As a compromise, I allowed them to silently patch the vulnerability." The way I read that they broke no embargo

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#32
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought a…

and force me to use some propietary-built webkit? Nah, thank you.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#33
post #16
post #9

It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…

The researcher's reaction is correct. OpenBSD maintainers' lack of patience may have led to this vulnerability being discovered and exploited by other people.

The researcher’s lack of full disclosure may have lead to this vulnerability being discovered and exploited by other people.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#34
post #27
post #7

Earlier quoted context omitted.

Or if combined with some other vulnerabilities...

Somewhat pointless remark as WPA only protects up to the access point. Any vulnerability after that has wider implications regardless of the WPA status.

It's not really pointless. MiTM attacks become much easier to accomplish with something like sslstrip once access to the network is gained.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#35
post #5

> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http

Exactly, this particular sentence seems to overly dramatise the situation.

Is this issue any different to using open wifi at a cafe, which many many people do, relying on HTTPS for their security? (This is an honest question)

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#36
post #5

> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http

Note that in the demo video they use SSLStrip to cancel attempts of websites to switch to https.

The only protection here is HSTS (which is not enabled by most websites, but major ones like banks will usually have them) and manually typing https:// in your address.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#37
post #20

Earlier quoted context omitted.

This feels like some kind of prisoner's dilemma game theory problem. By defecting from the embargo, OpenBSD gained potential security for its users at the expense of all other users. Overall, this is a loss, unless you use OpenBSD. I have to agree with the researchers on this one; OpenBSD acted selfishly here.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Sounds like a "we technically respected the embargo, just not in principle" sort of thing to me.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#39
post #6

Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?

Unfortunately, Google has given app developers a quite powerful tool to disable the use of their apps on non-official OS images, in the form of SafetyNet. So even if you can install an open source version of Android expect a bunch of stuff to no longer work afterwards.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#40

„submitted for review on 19 May 2017“ ... „OpenBSD was notified of the vulnerability on 15 July 2017“ Can anyone explain the timeline of releasing such significant security findings? Why is it disclosed to the public 1/2 year after submitting to review? I'd guess the (publicly funded) research behind it is a lot older than that.

For a vulnerability of this magnitude, it's not unusual for a responsible disclosure to have a five month review window.

e.g. Dan Kaminsky's discovery of DNS cache poisoning had a 5 month responsible disclosure embargo.

Post reply on HN