Wi-Fi has been hacked

So is this all devices that allow it or only some?

Seems to be more open to some devices than others.

Also it being “proof of concept” some of these are examples that have been already breached to show what data flows.

In real world as with current hacks it’s nowhere near as easy as they make it sound in article if someone applied a modicum or logic.

The easy targets are always the easy targets.
 
Will telkom release updates for their routers.

Also Tenda
 
No... any fix is a workaround at best
Per the vuln site Q&A, inter alia
Do we now need WPA3?
No, luckily implementations can be patched in a backwards-compatible manner. This means a patched client can still communicate with an unpatched access point, and vice versa. In other words, a patched client or access points sends exactly the same handshake messages as before, and at exactly the same moments in time. However, the security updates will assure a key is only installed once, preventing our attacks. So again, update all your devices once security updates are available.

Should I change my Wi-Fi password?
Changing the password of your Wi-Fi network does not prevent (or mitigate) the attack. So you do not have to update the password of your Wi-Fi network. Instead, you should make sure all your devices are updated, and you should also update the firmware of your router. After updating your router, you can optionally change the Wi-Fi password as an extra precaution.

I'm using WPA2 with only AES. That's also vulnerable?
Yes, that network configuration is also vulnerable. The attack works against both WPA1 and WPA2, against personal and enterprise networks, and against any cipher suite being used (WPA-TKIP, AES-CCMP, and GCMP). So everyone should update their devices to prevent the attack!
 
No... any fix is a workaround at best
It's a flaw in the implementation, not the standard. It will be fixed just like IPv4 a few years ago. It's also from the connection side and (theoretically) doesn't affect access points unless they are also repeaters.
 
It's a flaw in the implementation, not the standard. It will be fixed just like IPv4 a few years ago. It's also from the connection side and (theoretically) doesn't affect access points unless they are also repeaters.

Since you didn't read the authors' site, here's some quotes (emphasis mine).

https://www.krackattacks.com/

The weaknesses are in the Wi-Fi standard itself, and not in individual products or implementations. Therefore, any correct implementation of WPA2 is likely affected. To prevent the attack, users must update affected products as soon as security updates become available. Note that if your device supports Wi-Fi, it is most likely affected. During our initial research, we discovered ourselves that Android, Linux, Apple, Windows, OpenBSD, MediaTek, Linksys, and others, are all affected by some variant of the attacks. For more information about specific products, consult the database of CERT/CC, or contact your vendor.

Do we now need WPA3?

No, luckily implementations can be patched in a backwards-compatible manner. This means a patched client can still communicate with an unpatched access point (AP), and vice versa. In other words, a patched client or access point sends exactly the same handshake messages as before, and at exactly the same moment in time. However, the security updates will assure a key is only installed once, preventing our attack. So again, update all your devices once security updates are available. Finally, although an unpatched client can still connect to a patched AP, and vice versa, both the client and AP must be patched to defend against all attacks!
 

Design flaws - the spec itself
Implementation flaws - what wpa_supplicant 2.4 did.

From the paper:

There are some important lessons that can be learned from our
results. First, the specification of a protocol should be sufficiently
precise and explicit. For example, when attacking the
4-way
hand-
shake in Section 3.3, we observed that the 802.11 standard is am-
biguous as to which replay counter values should be accepted. A
more precise or formal specification would avoid any such potential
incorrect interpretations.

When EVERYONE implements a standard or spec wrong, it's hard to blame the implementers for the issue. Then the spec/standard wasn't clear or explicit enough.
 
This is huge. So many non technical people have routers at home nowadays that have no clue how to flash a router with a firmware update. Heck, I have not done such an update since I left varsity so it would take me some time to even pull this off and some serious research. If anyone here has the steps needed to re-secure everything please let us know. For now I am guessing the following:

Windows PC's/laptops: Accept latest MS security patches
Android: Not sure, does Android do security updates? If so how? Or is it just part of a play store update on one of the components?
Actual wifi router: would be specific to the manufacturer and would require flashing the router with new firmware via an ethernet cable.

I wonder what the implications of this are on things like internet banking and crypto currency mining/wallets. Are you more vulnerable now if you are on wifi?
 
I thought The Doctor had already sorted this out
 
Top
Sign up to the MyBroadband newsletter
X