Am I missing something, or is the Android/wpa_supplicant "all zero key" KRACK bug mostly FUD? Surely wrong key = traffic can't flow.
That makes the impact negligible. This affects mostly private LANs. You're already owned if you trust the internet.
-
-
I mean, sure, you could spoof a LAN and recover some auth credentials, but not MITM properly. And you need to know what to expect.
-
Mh? At this point you emulate an AP with a negotiated all-zero key. It's full MITM, just not through orig AP. At least how I understood it.
- Show replies
New conversation -
-
-
Well. Client connects to trusted AP, all looks fine, browsing internet. But attacker hijacked the connection. Powerful MITM. But yeah, FUD?
-
I mean, sure but you're already exposing yourself to that every time you use public WiFi. Internet apps should all use TLS these days.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.