prev
next
ru.linux.redhat
FromAlexey Vissarionov2:5020/545.0Date Write2017-10-16 21:00:00
ToAll0:0/0.0Date Arrived2017-10-16 21:01:09
SubjKRACK: Key Reinstallation Attack
Attr
Доброго времени суток, All!

* Обнаружено в RSS.SLASHDOT.ORG

WPA2 Security Flaw Puts Almost Every Wi-Fi Device at Risk of Hijack, Eavesdroppi
g
https://it.slashdot.org/story/17/10/16/149251/

==== хрум ====
A security protocol at the heart of most modern Wi-Fi devices, including compute
s, phones, and routers, has been broken, putting almost every wireless-enabled d
vice at risk of attack. From a report: The bug, known as "KRACK" for Key Reinsta
lation Attack, exposes a fundamental flaw in WPA2, a common protocol used in sec
ring most modern wireless networks. Mathy Vanhoef, a computer security academic,
who found the flaw, said the weakness lies in the protocol's four-way handshake,
which securely allows new devices with a pre-shared password to join the network
That weakness can, at its worst, allow an attacker to decrypt network traffic f
om a WPA2-enabled device, hijack connections, and inject content into the traffi
stream. In other words: hackers can eavesdrop on your network traffic. The bug
epresents a complete breakdown of the WPA2 protocol, for both personal and enter
rise devices -- putting every supported device at risk. "If your device supports
Wi-Fi, it is most likely affected," said Vanhoef, on his website. News of the vu
nerability was later confirmed on Monday by US Homeland Security's cyber-emergen
y unit US-CERT, which about two months ago had confidentially warned vendors and
experts of the bug, ZDNet has learned.
==== тьфу ====

Вкратце: найдена критическая ошибка в протоколе WPA2.

Что делать?

Обновления для Linux-систем уже выпущены, для форточек скорее всего выйдут завтр
.

Точки доступа есть смысл перенести в отдельные VLANы специально для WiFi, и отту
а пускать только наружу (во внутренние сети только через OpenVPN).

Говнороутеры, которые умеют работать с OpenWRT, есть смысл перевести на эту сист
му (и обновить, как только это станет возможно). Остальные говнороутеры можно пе
еключить в режим точек доступа и применить предыдущую рекомендацию.

Обновления для ведроида ожидаются в начале ноября.

* Originally in RU.WARDRIVE
* Crossposted in RU.ANDROID
* Crossposted in RU.SECURITY
* Crossposted in RU.LINUX
* Crossposted in RU.LINUX.REDHAT


--
Alexey V. Vissarionov aka Gremlin from Kremlin
gremlin ПРИ gremlin ТЧК ru; +vii-cmiii-ccxxix-lxxix-xlii

... Рожденный ползать, уйдите со взлетной полосы!
--- /bin/vi
* Origin: http://openwall.com/Owl/ru (2:5020/545)