Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
1–10 of 53 posts
Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#2Ref to the CVEs that will make a lot of network admins hate Monday: https://twitter.com/nick_lowe/status/919527451570638848
And some background: https://eprint.iacr.org/2016/475.pdf
Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#3Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#4"We also publish the system uptime in an unencrypted broadcast message to save you the effort of even bruteforcing it".
Does nobody do security reviews on this stuff, or are these weaknesses there deliberately?
The line between incompetence and malice really is thin here...
Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#5Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#6WPA2 is toast. Ref to the CVEs that will make a lot of network admins hate Monday: https://twitter.com/nick_lowe/status/919527451570638848 And some background: https://eprint.iacr.org/2016/475.pdf
Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#7Here's the CCC talk with the author of this white paper: https://www.youtube.com/watch?v=KJWd-_BDC_g
Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#8Re: Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys [pdf]
#9WPA2 is toast. Ref to the CVEs that will make a lot of network admins hate Monday: https://twitter.com/nick_lowe/status/919527451570638848 And some background: https://eprint.iacr.org/2016/475.pdf
Also worth nothing that the attack in the OP is on TKIP, but the KRACK attack that will be revealed tomorrow is based upon problems with the RNG (the example RNG, which apparently everyone used, is trivial to break and the protocol is also kind enough to provide you with a huge chunk of the entropy used in seeding the RNG. D'oh!)
I guess this implies not "only" passive eavesdropping but also network access in environments without a MAC address filter (not that these can't be spoofed regardless)?