Live data from Hacker News

Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

krackattacks.com

91–100 of 424 posts

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#91
post #20

Earlier quoted context omitted.

This feels like some kind of prisoner's dilemma game theory problem. By defecting from the embargo, OpenBSD gained potential security for its users at the expense of all other users. Overall, this is a loss, unless you use OpenBSD. I have to agree with the researchers on this one; OpenBSD acted selfishly here.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Perhaps "defect" is the wrong word given the circumstances, but the result is the same. There's a good reason for the embargo: this all takes cooperation, as it's not a Nash equilibrium. I still agree with their decision not to include OpenBSD so early in further disclosures, given Theo's short-sighted statement.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#92

What's the practical impact here? What do I do with a normal house with routers, laptops, smartphones etc? Are manufacturers like linksys, d-link issuing patches now or will it be enough to have windows/os x/iOS/android updates enabled? Or do I need both?

Await your client to be patched. Routers are not so much the problem (unless in Range Externder modus).

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#93
post #46

Correct me if I am wrong but basically the attack is against clients, not access points which means simply patching the AP will not do, one would have to patch all of the clients. And the AP patches that are now coming in are probably for client mode, so they fix a certain scenario when the AP is a client which is far from the common one?

Correct for 98%. Clients are the weakest point in the scenario.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#94

Earlier quoted context omitted.

Patching the client is a fix. Mitigation would bea config setting that makes me safer (disable some unused functionality,...). So yes, you can have both.

That’s like saying that prior to introducing seatbelts, we should have allowed for a period of time to glue people to their seats because it is preferable to have a mitigation they can apply themselves than a fix the manufacturer has to put in. If you don’t limit mitigation to "a config setting" (and why would you?!), a patch/new version is the best mitigation you can get.

I limit mitigation to a config setting because that’s what affected clients can do in this case. Everyone patching wpa_supplicant on their android handset is just not going to happen and it takes time for vendors to roll out patches.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#95
post #36
post #5

> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http

Note that in the demo video they use SSLStrip to cancel attempts of websites to switch to https. The only protection here is HSTS (which is not enabled by most websites, but major ones like banks will usually have them) and manually typing https:// in your address.

I'm seeing HSTS on 0/3 of Australian banks (I'm even seeing RC4 on one of them).

https://www.ssllabs.com/ssltest/analyze.html?d=commbank.com.... https://www.ssllabs.com/ssltest/analyze.html?d=nab.com.au&s=... https://www.ssllabs.com/ssltest/analyze.html?d=westpac.com.a...

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#96
Stop panicking (unless you need your daily dose of the End of the World drama).

From the source: In general though, you can try to mitigate attacks against routers and access points by disabling client functionality (which is for example used in repeater modes) and disabling 802.11r (fast roaming).

For ordinary home users, your priority should be updating clients such as laptops and smartphones.

Source: https://www.krackattacks.com/

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#97
post #91

Earlier quoted context omitted.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Perhaps "defect" is the wrong word given the circumstances, but the result is the same. There's a good reason for the embargo: this all takes cooperation, as it's not a Nash equilibrium. I still agree with their decision not to include OpenBSD so early in further disclosures, given Theo's short-sighted statement.

Wellll to be fair, I'm sure if the researcher said no, he wouldn't have committed.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#98
post #37

Earlier quoted context omitted.

Sounds like a "we technically respected the embargo, just not in principle" sort of thing to me.

We're not mind readers. If he says it's ok, we think it's ok. If other vendors have fucked up months long patch cycles, that's their deal, not ours.

Now that it's more clear what role disclosure deadlines play in cooperating with security researchers, it probably makes more sense to just cooperate than point fingers.

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#99
post #91

Earlier quoted context omitted.

Read that again. We asked to commit without revealing details, he said yes, that's what happened. I guess he changed his mind about that after the fact, but nobody promised not to commit. We didn't "defect" from an embargo unilaterally.

Perhaps "defect" is the wrong word given the circumstances, but the result is the same. There's a good reason for the embargo: this all takes cooperation, as it's not a Nash equilibrium. I still agree with their decision not to include OpenBSD so early in further disclosures, given Theo's short-sighted statement.

> Perhaps "defect" is the wrong word

It's precisely the correct word. Prisoner's dilemma are simple, mathematically. This was one. OpenBSD defected. The joke's on the security researcher, though, since this doesn't appear to have been their first time [1][2].

Robert Axelrod outlined, in his 1984 classic The Evolution of Cooperation [3] four requirements for a successful iterative prisoner's dilemma strategy. One is retaliating. Security researchers are letting OpenBSD play an iterating game as if it's an N=1, i.e. they're not retaliating. Given the community is playing "always cooperate," OpenBSD's best move is actually "always defect".

[1] https://lwn.net/Articles/726585/ thank you 0x0 [a]

[2] https://lwn.net/Articles/726580/ thank you 0x0 [a]

[a] https://news.ycombinator.com/item?id=15481980

[1] https://en.wikipedia.org/wiki/The_Evolution_of_Cooperation

Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse

#100
post #37

Earlier quoted context omitted.

Sounds like a "we technically respected the embargo, just not in principle" sort of thing to me.

We're not mind readers. If he says it's ok, we think it's ok. If other vendors have fucked up months long patch cycles, that's their deal, not ours.

He said it's ok this time, but won't be so in the future (pretty clear from the future action). So your decision is still subject to the criticism.
Post reply on HN