Tales from the Certified Hacker Trainer: And we thought WPA2 PSK or Enterprise was safe enough!

18 Oct 2017

I’m in the U.K. at the moment on holidays, but some things need to be announced on our DDLS blog. For those who may have missed it, there is a bug in Wi-Fi which has been given the name Key Reinstallation Attacks (aka. KRACK), which makes it possible to inject and manipulate data as well as eavesdrop on communications over the air. The only main limitation is that an attacker needs to be within range of a victim to exploit these weaknesses.

It affects WPA2 Personal and Enterprise, regardless of the encryption ciphers used by a network. It mostly affects Linux and Android 6.0 and above, as well as macOS and OpenBSD. Windows and iOS are more or less unaffected due to the way they implement WPA2.

Patches will need to be applied to your particular O/S when available.

More information can be obtained from the websites below:

https://www.krackattacks.com/

https://www.theregister.co.uk/2017/10/16/wpa2_krack_attack_security_wifi_wireless/

Stay safe,
Terry Griffin, Principal Technologist: Security