Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Severe WiFi security flaw puts millions of devices at risk (WPA2 cracked, but there's a patch)
Engadget ^ | Oct 16, 2017 | Steve Dent

Posted on 10/16/2017 6:24:52 AM PDT by dayglored

"Krack Attack" allows hackers to steal credit cards, bank info and more.

Researchers have discovered a key flaw in the WPA2 WiFi encryption protocol that could allow hackers to intercept your credit card numbers, passwords, photos and other sensitive information. The flaws, dubbed "Key Reinstallation Attacks," or "Krack Attacks," are in the WiFi standard and not specific products. That means that just about every router, smartphone and PC out there could be impacted, though attacks against Linux and Android 6.0 or greater devices may be "particularly devastating," according to KU Leuven University's Mathy Vanhoef and Frank Piessens, who found the flaw.

Here's how it works. Attackers find a vulnerable WPA2 network, then make a carbon copy of it and impersonate the MAC address, then change the WiFi channel. This new, fake network acts as a "man in the middle," so when a device attempts to connect to the original network, it can be forced to bypass it and connect to the rogue one.

Normally, WPA2 encryption requires a unique key to encrypt each block of plain text. However, the hack described in the Krack Attack paper forces certain implementations of WPA2 to reuse the same key combination multiple times.

...

(Excerpt) Read more at engadget.com ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: krack; krackattack; wifi; windowspinglist; wpa2
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last
Really bad. But there's apparently a mitigation, and you can patch it on your CLIENT SIDE.

https://www.reddit.com/r/programming/comments/76ohly/severe_flaw_in_wpa2_protocol_leaves_wifi_traffic/dofqjmn/

1 posted on 10/16/2017 6:24:53 AM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
WPA@ cracked, Wifi vulnerable ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 10/16/2017 6:25:36 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Oops, “WPA2” not “WPA@”.


3 posted on 10/16/2017 6:26:03 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Ethernet cable is my simple solution to these problems. Faster, too.


4 posted on 10/16/2017 6:30:27 AM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

This is what some techie geniuses are spending there time on because there are just so many fantastic techie real jobs out there - NOT. (AI is already into processes to replace average tech workers, analysts of all types - including financial and legal, and general computer programmers).


5 posted on 10/16/2017 6:32:05 AM PDT by Wuli
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

I didn’t see if disabling WIFI administrator affected it. I always leave that off.


6 posted on 10/16/2017 6:33:28 AM PDT by ImJustAnotherOkie
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wuli

Better off with a career as an aircraft or robot mechanic.


7 posted on 10/16/2017 6:35:08 AM PDT by captain_dave
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

My router cannot be seen outside my house due to the fact I have stone walls. I can’t even use it in the garage. I can see my neighbor’s router(they live through the woods) but not mine.


8 posted on 10/16/2017 6:37:04 AM PDT by AppyPappy (Don't mistake your dorm political discussions with the desires of the nation)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wuli

Self programming computers are only the beginning...............

9 posted on 10/16/2017 6:39:34 AM PDT by Red Badger (Road Rage lasts 5 minutes. Road Rash lasts 5 months!.....................)
[ Post Reply | Private Reply | To 5 | View Replies]

To: proxy_user

Remember, WIFI’s not a question....it’s a thing.


10 posted on 10/16/2017 6:43:59 AM PDT by Puppage (You may disagree with what I have to say, but I shall defend to your death my right to say it.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

A WPA2 WiFi access point can be configured with a hidden SSID instead of a public one to make it harder to hijack.


11 posted on 10/16/2017 6:45:05 AM PDT by Gideon7
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

From the comments on the article at engadget:

“Windows 10 isn’t vulnerable (because Windows breaks the spec in exactly the proposed way to avoid the attack), and iOS isn’t vulnerable either (for the same reason), and AFAIK it shares its networking stack with macOS so macOS is likely not vulnerable either.”

This means if you use Windows 10 or a Mac as a WiFi client you should be safe.

Linux clients are still vulnerable (Android).


12 posted on 10/16/2017 6:52:19 AM PDT by Gideon7
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
From the article:

And of course, the attack won't work unless the attacker is nearby and can physically access your network.

13 posted on 10/16/2017 6:56:09 AM PDT by SanchoP
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

It’s an Android thing and someone has to be close by to Krack you ,LOL


14 posted on 10/16/2017 6:58:08 AM PDT by butlerweave (it's the children are)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ImJustAnotherOkie
I didn’t see if disabling WIFI administrator affected it. I always leave that off.

That would have no effect on this.
15 posted on 10/16/2017 7:03:33 AM PDT by TexasGunLover ("Either you're with us or you're with the terrorists."-- President George W. Bush)
[ Post Reply | Private Reply | To 6 | View Replies]

To: dayglored

if you have wi-fi enabled on your IPhone while you’re out and about, a hacker can grab your info?


16 posted on 10/16/2017 7:12:30 AM PDT by bitt (The press takes him literally, but not seriously; his supporters take him seriously, but not literal)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TexasGunLover

Didn’t sound like it.


17 posted on 10/16/2017 7:15:18 AM PDT by ImJustAnotherOkie
[ Post Reply | Private Reply | To 15 | View Replies]

To: Gideon7

Don’t we all have our SSIDs set to “Free Republic” or “Pig in a Pantsuit” or such?


18 posted on 10/16/2017 7:20:30 AM PDT by bigbob (People say believe half of what you see son and none of what you hear - M. Gaye)
[ Post Reply | Private Reply | To 11 | View Replies]

To: SanchoP
> And of course, the attack won't work unless the attacker is nearby and can physically access your network.

Ummm, like your local coffee shop's "Free WIFI"?

What would you guess the likelihood is that public WIFI hotspots are gonna get patched quickly?

19 posted on 10/16/2017 7:28:38 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 13 | View Replies]

To: bitt
> if you have wi-fi enabled on your IPhone while you’re out and about, a hacker can grab your info?

I'm not exactly sure precisely which clients are vulnerable, because there's a lot of crap/fake info floating around, and some folks are desperate to convince themselves (and others) that their preferred device or OS is "safe".

I created this thread mainly to raise FReepers' consciousness about the problem, but I don't claim to have a definitive list of the exact info -- yet. Data is still emerging, and one has to be careful about what one takes as gospel, at least early on in the discussion.

20 posted on 10/16/2017 7:36:07 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson