WPA2 Encryption exploit discovered...all Wi-Fi protocols are vulnerable

Hood Critic

The Power Circle
Joined
May 2, 2012
Messages
24,875
Reputation
4,020
Daps
112,978
Reppin
דעת
Today a collection of severe security vulnerabilities in the WPA2 encryption protocol for Wi-Fi are being disclosed, along with a proof of concept exploit. The weaknesses center around the process used for negotiating the encryption keys used by the client and access point. These core vulnerabilities are part of the Wi-Fi Protected Access WPA standard itself, so even devices that correctly implement WPA2 according to spec are expected to be affected. Both personal and enterprise WPA modes are affected, and both the original WPA and WPA2 are affected. The primary mode of attack exploits vulnerabilities in client devices, but there are some variants that affect features used by some access points.

Multiple WiFi Encryption Vulnerabilities Disclosed, Affecting Almost Everything
 

Yapdatfool

Superstar
Joined
May 5, 2012
Messages
8,604
Reputation
1,266
Daps
22,682
Reppin
NULL
https://doublepulsar.com/regarding-krack-attacks-wpa2-flaw-bf1caa7ec7a0

Regarding Krack Attacks — WPA2 flaw
So there’s a new Wi-Fi attack. In the media it is being presented as a flaw in WPA protocol which isn’t fixable. This isn’t true.

Before we all burn the house down, however, and declare security problems not fixable, let’s get to some important things for organisations:

  • It is patchable, both client and server (Wi-Fi) side.
  • Linux patches are available now. Linux distributions should have it very shortly.
  • The attack realistically doesn’t work against Windows or iOS devices. The Group vuln is there, but it’s not near enough to actually do anything of interest.
  • There is currently no publicly available code out there to attack this in the real world — you would need an incredibly high skill set and to be at the Wi-Fi base station to attack this.
  • Android is the issue, which is why the research paper concentrates on it. The issue with Android is people largely don’t patch.

He's not lying, my Linux Mint distro just got a wpa security update patching this very fix...
 

winb83

52 Years Young
Supporter
Joined
May 28, 2012
Messages
47,532
Reputation
4,091
Daps
71,800
Reppin
Michigan
How do we protect our connection?
Client side patches. If your Android phone is more than a couple years older good luck. Some of the cheaper, older, and off brand stuff will never get patched.
 
Top