Wi-Fi has been hacked

This is huge. So many non technical people have routers at home nowadays that have no clue how to flash a router with a firmware update. Heck, I have not done such an update since I left varsity so it would take me some time to even pull this off and some serious research. If anyone here has the steps needed to re-secure everything please let us know. For now I am guessing the following:

Windows PC's/laptops: Accept latest MS security patches
Android: Not sure, does Android do security updates? If so how? Or is it just part of a play store update on one of the components?
Actual wifi router: would be specific to the manufacturer and would require flashing the router with new firmware via an ethernet cable.

I wonder what the implications of this are on things like internet banking and crypto currency mining/wallets. Are you more vulnerable now if you are on wifi?

My CAT S60 gets security updates. None of my Samsungs ever have had such updates.
 
My Home Wifi Is fully secured, uses private/public key manually with AES Encryption. Pain in the ass to setup but I expected this day to come. Time to send emails 'I TOLD YOU SO'.

For connections using AES and the Counter with CBC-MAC Protocol ((AES)-CCMP), an attacker can decrypt network packets, making it possible to read their contents and to inject malicious content into TCP packet streams. But the key itself cannot be broken or forged, so the attacker can't forge a key and join the network—instead, they have to use a "cloned" access point that uses the same MAC address as the access point of the targeted network, on a different Wi-Fi channel.

https://arstechnica.com/information...ck-attack-destroys-nearly-all-wi-fi-security/
 
Is anyone going to actively do anything on their routers? I wouldnt even know where to start, well firmware update I guess.
 
Is anyone going to actively do anything on their routers? I wouldnt even know where to start, well firmware update I guess.
Update the version of dd-wrt/OpenWrt/lede-project/etcetera you already have on it*

*actually have a router on which this is available. Or, apparently a Mikrotik one (which is its own special hell (not an aficionado)).
 
Is anyone going to actively do anything on their routers? I wouldnt even know where to start, well firmware update I guess.

As a home user I wouldn’t be too worried.

Someone would literally need to be camping in your garden in most home setups to manage a successful hack.

It’s the public stuff and corporate which you should be worried about, which has always been the case really.

It will be a while before most router manufacturers respond anyway.

Clients can just be updated OTA.
 
Since you didn't read the authors' site, here's some quotes (emphasis mine).

https://www.krackattacks.com/
I have, but it's clear you didn't. The flaw is in the spec, not the standard. The spec is a piece of paper that describes the standard and up till now everyone has just implemented what's described there but it wasn't explicit enough in what should and shouldn't be allowed. Patching it will fix the issue that's at fault while still leaving it compliant with the standard.

This is huge. So many non technical people have routers at home nowadays that have no clue how to flash a router with a firmware update. Heck, I have not done such an update since I left varsity so it would take me some time to even pull this off and some serious research. If anyone here has the steps needed to re-secure everything please let us know. For now I am guessing the following:

Windows PC's/laptops: Accept latest MS security patches
Android: Not sure, does Android do security updates? If so how? Or is it just part of a play store update on one of the components?
Actual wifi router: would be specific to the manufacturer and would require flashing the router with new firmware via an ethernet cable.

I wonder what the implications of this are on things like internet banking and crypto currency mining/wallets. Are you more vulnerable now if you are on wifi?
Most should be easy and have the option in the router itself. My Huawei I just click on search for updates and install if there are any. TP-link dongle I would go to the site and install new driver.

Banking is still safe as your communication is already encrypted and assumed to be monitored. Mining can't be affected and any good wallet will never send your private key over any network.
 
I have, but it's clear you didn't. The flaw is in the spec, not the standard. The spec is a piece of paper that describes the standard and up till now everyone has just implemented what's described there but it wasn't explicit enough in what should and shouldn't be allowed. Patching it will fix the issue that's at fault while still leaving it compliant with the standard.


Most should be easy and have the option in the router itself. My Huawei I just click on search for updates and install if there are any. TP-link dongle I would go to the site and install new driver.

Banking is still safe as your communication is already encrypted and assumed to be monitored. Mining can't be affected and any good wallet will never send your private key over any network.

You may have an issue with comprehension then...

From the second paragraph on the site
The weaknesses are in the Wi-Fi standard itself, and not in individual products or implementations. Therefore, any correct implementation of WPA2 is likely affected.
 
You may have an issue with comprehension then...

From the second paragraph on the site
The spec isn't explicit enough and should be updated. An implementation which incorporates the extra security is still compliant with the standard so there's nothing wrong with it. We don't need a new standard.
 
The spec isn't explicit enough and should be updated. An implementation which incorporates the extra security is still compliant with the standard so there's nothing wrong with it. We don't need a new standard.

Are you blind?

Its the STANDARD that has the issue, not the spec.
 
My AP has been patched

e47a43a5f28b3f0973fc2ad083a3990b.heic
 
Are you blind?

Its the STANDARD that has the issue, not the spec.

Aruba wrote a very nice document detailing the issue and their response.

Q: Some people are saying this is a protocol flaw, and some people are saying it’s an implementation flaw. Which is it?
A: It is both. However, the fix is in the implementation; we do not require a new protocol.
Specifically:
• The 802.11r FT handshake vulnerability is a protocol-level flaw. The protocol was not designed to resist this attack. Vendors can retroactively patch the flaw, however, in a way that does not affect interoperability. This is what Aruba and other vendors have done.
• The 4-way handshake, group handshake, and other keying vulnerabilities result from the 802.11i standard (the description and specification of the protocol) being insufficiently detailed. That has been compounded by certain Android/Linux implementations that make the flaw worse than it otherwise would have been. Vendors can add logic to patch the flaw.

http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007_FAQ_Rev-1.pdf
 
It is unclear to me why a AP would need to be patched.

Perhaps someone can explain what exactly you would "patch" on the AP.

I've read the attack and I realize the author knows the vulnerability better than I do, but I couldn't see a way it could be used against an AP.

(And before someone brings up that an "AP" can be a client, let me be clear, not an AP hardware device connecting to other devices as a client. I'm talking about an actual wifi access point providing connectivity. Any client connectivity from a hardware device makes it a client, regardless of what you call it when you sell it)
 
Last edited:
Anyone here anything about the Huawei routers and patch updates?
 
It is unclear to me why a AP would need to be patched.

Perhaps someone can explain what exactly you would "patch" on the AP.

I've read the attack and I realize the author knows the vulnerability better than I do, but I couldn't see a way it could be used against an AP.

Yes this is in agreement with the statement below from TP-Link:
WPA2 Security (KRACKs) Vulnerability Statement


Description

TP-Link is aware of vulnerabilities in the WPA2 security protocol that affect some TP-Link products. An attacker within wireless range of a Wi-Fi network can exploit these vulnerabilities using key reinstallation attacks (KRACKs). According to the research paper on KRACKs by Mathy Vanhoef that brought this vulnerability to the attention of vendors, the attack targets the WPA2 handshake and does not exploit access points, but instead targets clients. All vulnerabilities can be fixed through software updates since the issues are related to implementation flaws.

TP-Link has been working to solve this problem and will continue to post software updates at: www.tp-link.com/support.html. Products with TP-Link Cloud enabled will receive update notifications in the web management interface, Tether App or Deco App automatically.

More information about KRACK can be found through the link: https://www.krackattacks.com.

Conditions under which devices are vulnerable:
•Physical proximity: An attack can only happen when an attacker is in physical proximity to and within wireless range of your network.
•Time window: An attack can only happen when a client is connecting or reconnecting to a Wi-Fi network.

Unaffected TP-Link products:

All powerline adapters

All mobile Wi-Fi products

Routers and gateways working in their default mode (Router Mode) and AP Mode

Range extenders working in AP Mode

Business Wi-Fi EAP series access points working on AP mode

Affected TP-Link products:

Routers working in Repeater Mode/WISP Mode/Client Mode:

See:http://www.tp-link.com/en/faq-1970.html
 
As a home user I wouldn’t be too worried.

Someone would literally need to be camping in your garden in most home setups to manage a successful hack.

It’s the public stuff and corporate which you should be worried about, which has always been the case really.

It will be a while before most router manufacturers respond anyway.

Clients can just be updated OTA.

Now this is value added :).

I was going to ask how this affected me. With having a router, connected to an ADSL line, feeding only my my TV and console etc at home. Any concerns over this?
 
Yes this is in agreement with the statement below from TP-Link:
WPA2 Security (KRACKs) Vulnerability Statement


Description

TP-Link is aware of vulnerabilities in the WPA2 security protocol that affect some TP-Link products. An attacker within wireless range of a Wi-Fi network can exploit these vulnerabilities using key reinstallation attacks (KRACKs). According to the research paper on KRACKs by Mathy Vanhoef that brought this vulnerability to the attention of vendors, the attack targets the WPA2 handshake and does not exploit access points, but instead targets clients.

But then the author claims otherwise:
Finally, although an unpatched client can still connect to a patched AP, and vice versa, both the client and AP must be patched to defend against all attacks!

So again, what would you patch on AP?

IMO the writer got a little too over enthusiastic writing this page and made a mistake in that paragraph. Further down on his site he claims APs are not affected. Doh.

In his mind he is probably taking about devices sold as "access point" that can act as clients to repeat a signal. Rather than a pure wifi access point that serves a connection
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X