KRACK: The attack on WPA2-protected Wi-Fi networks

krack: Key Reinstallation Attack para redes wifi protegidas por WPA2

Honestly, these hackers just won’t let us live in peace! Do you remember the post about wifi network security where we said we should be using WPA2 as our encryption method? Well, this week a new vulnerability affecting WPA2 encryption in wifi networks has come to light. Not all the technical details have been revealed yet, since it will be officially presented on November 1st, but we already have some pretty worrying information:

– The attack, called Key Reinstallation Attacks (Krack), would allow a potential intruder within range of our wifi to capture packets traveling across the network (credit card numbers, emails, photos, etc.) and even inject new packets (like viruses).

– The vulnerability affects ALL devices that use Wifi, not just routers… meaning phones, access points, laptops…

– There’s no patch or update available yet, so we’ll have to wait…

The scariest part of all this is that the fix has to come from the manufacturer… meaning our phones and computers will soon get an update to fix this vulnerability, but what will happen with devices that can’t be updated? Last week we talked about the update lifecycle and how some phones can no longer be updated, but what about, say, the router in our home? It’ll need updating too… as long as the manufacturer releases said update. It’s entirely possible our router has been running perfectly fine on WPA2 for the past 5 years, only for the manufacturer to decide it’s obsolete and skip releasing the fix, forcing us to replace it if we want to keep our network private… or our smart TV… or our baby monitor… or the garage camera… or the hotel wifi we’re using on vacation… In other words, over the next few months we’re going to see a ton of updates for a ton of devices connected to wifi networks, but we’re also going to see attacks on devices that haven’t been updated, so once again I recommend updating as soon as the manufacturer makes the update available, and checking over the coming weeks whether your devices (especially your router) can be updated. Otherwise, it’s probably worth replacing the device… this is likely the perfect moment to finally swap out that iPhone 4S that no longer gets updates, that Samsung S4 stuck on Android 5.0, or that router your ISP installed 6 years ago that’s never given you any trouble but has also never once been updated.

What can we do in the meantime?

Obviously we could just go back to using good old cables so the vulnerability doesn’t affect us, but since that’s not very practical for everyday life, we should make sure all the sites we visit are available over https (yes, this blog is, don’t worry :D). Now more than ever we should double-check this so we can feel a bit more at ease until the manufacturer of our devices (Apple, Google, Microsoft, Cisco, Linksys…) releases the update and we get every single one of them patched.

This time around, changing your wifi password won’t help at all. Keep in mind that the attacker won’t be able to access our network to browse the internet, meaning they can’t «steal our wifi,» but they will be able to capture all the traffic flowing through it.

Carlos Sahuquillo

Carlos Sahuquillo

'Haga lo que haga en la vida, siempre compito' - Jacques Villeneuve Reserva una sesión →

Sigue leyendo

Entradas relacionadas

Ver todo el blog
13 abril, 2020 · General

Low-cost remote work

Lowcost remote work, Chernobyl, and the importance of not running security tests in a rush and under pressure.

Leer
Conversación

0 comentarios

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

Este sitio usa Akismet para reducir el spam. Aprende cómo se procesan los datos de tus comentarios.