US-CERT advisory on the WPA attacks here: https://www.kb.cert.org/vuls/id/228519
-
-
Show this thread
-
Updated full list of vendors affected: https://www.kb.cert.org/vuls/byvendor?searchview&Query=FIELD+Reference=228519&SearchOrder=4 …
Show this thread
End of conversation
New conversation -
-
-
Is this another WPA2-TKIP thing? -.-
-
flaw in the 4-way handshake. As I understand it, in many cases, this will be: "Throw your router away and buy a new one."
-
Or "wait for a firmware update". Bait much?
-
assuming your crappy home router gets a patch at all.
-
The router isn't even the core problem here. It is the STAs that are the problem. So I guess throw away all your electronics and buy new?
End of conversation
New conversation -
-
-
Well shit. It sure sucks that I can't lock down my network by mac. What a great privacy "win"
-
risk is dramatically mitigated by strong https (and ssh) integrity
-
Somehow that doesn't make me feel much better..
-
so you're in need of new
@PupSunTzu pics then?
End of conversation
New conversation -
-
-
As far as I understand it this depends on the vendor/OS so not related to the protocol itself just the implementation of it?
-
public disclosure is tomorrow, but “most or all correct implementations” of WPA2 are affected.
-
On the WPA2 wi-fi flaw, probably a good time to review abuse resistance, particularly nonce-disrespecting attacks: https://eprint.iacr.org/2016/475.pdf
-
Is this the Predictable GTK RNG bug?
- 1 more reply
New conversation -
-
-
Uhm, more details? Where will this be announced? When will a paper be up? I like music as much as anyone, but come on.
-
you're asking the wrong person. Read the quoted tweet again closely.
-
but here's some good background: https://www.blackhat.com/docs/webcast/08242017-securely-implementing-network2.pdf …
-
Thanks! I did look at
@vanhoefm's twitter, but I am lazy and did not feel like a scavenger hunt. It wasn't at the top. - End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.