Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Linguica
Jul 13, 2000
You're already dead



https://www.krackattacks.com

quote:

We discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. An attacker within range of a victim can exploit these weaknesses using key reinstallation attacks (KRACKs). Concretely, attackers can use this novel attack technique to read information that was previously assumed to be safely encrypted. This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. The attack works against all modern protected Wi-Fi networks. Depending on the network configuration, it is also possible to inject and manipulate data. For example, an attacker might be able to inject ransomware or other malware into websites.

If the victim uses either the WPA-TKIP or GCMP encryption protocol, instead of AES-CCMP, the impact is especially catastrophic. Against these encryption protocols, nonce reuse enables an adversary to not only decrypt, but also to forge and inject packets. Moreover, because GCMP uses the same authentication key in both communication directions, and this key can be recovered if nonces are reused, it is especially affected. Note that support for GCMP is currently being rolled out under the name Wireless Gigabit (WiGig), and is expected to be adopted at a high rate over the next few years.

https://www.youtube.com/watch?v=Oh4WURZoR98

hope you didn't throw away all those old cat5 cables!!!!

Linguica fucked around with this message at 21:56 on Oct 16, 2017

Adbot
ADBOT LOVES YOU

SmokaDustbowl
Feb 12, 2001

by vyelkin
Fun Shoe
I hope hackers like listening to last podcast on the left and the black tapes and poo poo cause that's all I ever use wireless for

Ciaphas
Nov 20, 2005

> BEWARE, COWARD :ovr:


but my chromecast :(

SmokaDustbowl
Feb 12, 2001

by vyelkin
Fun Shoe
I was playing video poker on my ipad and got 5 of a kind one time, and nobody would believe me. where were the hackers then?!

duTrieux.
Oct 9, 2003

my butt crack is very prepared right now. i have a soothing cream and everything. it's a little pricey but my quality of life has improved dramatically.

pram
Jun 10, 2001
who gives a god damned gently caress

Moo Cowabunga
Jun 15, 2009

[Office Worker.




Cool.

bobbilljim
May 29, 2013

this christmas feels like the very first christmas to me
:shittydog::shittydog::shittydog:
Hopefully i will get a patch for my open soruce router software in good time OP

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

:spidey:

Only registered members can see post attachments!

Linguica
Jul 13, 2000
You're already dead

holly poo poo! piss!! anroid lol!!!

https://www.youtube.com/watch?v=Oh4WURZoR98

Symbolic Butt
Mar 22, 2009

(_!_)
Buglord

duTrieux. posted:

my butt crack is very prepared right now. i have a soothing cream and everything. it's a little pricey but my quality of life has improved dramatically.

same

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

FAPPO!

Thanks Ants
May 21, 2004

#essereFerrari


lol that open source router software is getting patched quicker than *~enterprise~* kit

r u ready to WALK
Sep 29, 2001

People thought I was crazy when I cabled 48 ports of gigabit ethernet in my home, but look who's laughing now!

Maximum Leader
Dec 5, 2014
I don't think my polish tomato usb fork is being patched anytime soon

pram
Jun 10, 2001

r u ready to WALK posted:

People thought I was crazy when I cabled 48 ports of gigabit ethernet in my home, but look who's laughing now!

lol 1g nice future proofing idiot

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

welp time to stop using WiFi for sensitive poo poo again

they really need to break http and make everything go through https, it looks like the only thing that didn’t break in that demo was the sites certification and the secure notice from the browser

poty
Jun 21, 2008

虹はどこで終わるのですか? あなたの魂の中で、または地平線で?
honestly at this point i wouldnt mind giving up on wi-fi and going to lte tethering 24/7. i have a nice unlimited plan

maskenfreiheit
Dec 30, 2004
luckily i use wep

maskenfreiheit
Dec 30, 2004

My Linux Rig posted:

welp time to stop using WiFi for sensitive poo poo again

they really need to break http and make everything go through https, it looks like the only thing that didn’t break in that demo was the sites certification and the secure notice from the browser

apparently if you're using a VPN this isn't very serious, and you should be using a vpn when you're attaching yourself to dirty coffeeshop wifi

Shaggar
Apr 26, 2006

My Linux Rig posted:

welp time to stop using WiFi for sensitive poo poo again

they really need to break http and make everything go through https, it looks like the only thing that didn’t break in that demo was the sites certification and the secure notice from the browser

as long as you aren't using Linux you're ok

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad

maskenfreiheit posted:

luckily i use wep

same only WAP.

man, if ever there was a technology trying to do too much before its time... :o:

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Shaggar posted:

as long as you aren't using Linux you're ok

what

this seriously only affects linux based os’s?

I thought this was a core issue in wpa2

Linguica
Jul 13, 2000
You're already dead

the authors say they have more serious exploits they have since developed that can pwn macs at least

HoboMan
Nov 4, 2010

Shaggar posted:

as long as you aren't using Linux you're ok

shaggar was wrong

the wpa2 protocol has a venerability to replay attacks

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

HoboMan posted:

shaggar was wrong

the wpa2 protocol has a venerability to replay attacks

that’s what I thought. though it sounds like microsoft already sent out a patch but if your driver isn’t updated you still hosed potentially

Shaggar
Apr 26, 2006

My Linux Rig posted:

what

this seriously only affects linux based os’s?

I thought this was a core issue in wpa2

the most critical attacks only affect Linux because windows devs didn't implement the flawed parts of the spec except when it relates to broadcast/multicast and who really cares about that

Shaggar
Apr 26, 2006

HoboMan posted:

shaggar was wrong

the wpa2 protocol has a venerability to replay attacks

the spec has significant design flaws, but most aren't implemented in windows

Beast of Bourbon
Sep 25, 2013

Pillbug
i use a wifi i got at the compusa am i ok?

Thanks Ants
May 21, 2004

#essereFerrari


this is a good thread title

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Shaggar posted:

the most critical attacks only affect Linux because windows devs didn't implement the flawed parts of the spec except when it relates to broadcast/multicast and who really cares about that

lol yeah except they did; the article points out that they had to release a patch for this vulnerability

Shaggar
Apr 26, 2006
not for the most critical stuff. the parts that affected windows were relatively minor.

KOTEX GOD OF BLOOD
Jul 7, 2012

Shaggar posted:

not for the most critical stuff. the parts that affected windows were relatively minor.
:allears:

angry_keebler
Jul 16, 2006

In His presence the mountains quake and the hills melt away; the earth trembles and its people are destroyed. Who can stand before His fierce anger?
like, who cares?

wpa2 has always been a joke and like 99%+ of all routers in the real world are still vulnerable to deauth attacks(or are running important industrial machinery and are forced to be wep for some legacy hardware lol), and once you're on the network you can do basically whatever nefarious thing you want, esp if you do an evil twin

idk, i guess this is a little more efficient than brute forcing but in terms of real security against a determined adversary i guess i don't see a difference. i suppose for your neighborhood teen who wants to steal your wifi this is a lower barrier to entry

burning swine
May 26, 2004



pretend i posted a picture of the unchangeable WPS key stamped on the bottom of my actiontec modem/router/WAP that I got in space year 2016


it's 12345678 and you can't turn off WPS

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

angry_keebler posted:

like, who cares?

wpa2 has always been a joke and like 99%+ of all routers in the real world are still vulnerable to deauth attacks(or are running important industrial machinery and are forced to be wep for some legacy hardware lol), and once you're on the network you can do basically whatever nefarious thing you want, esp if you do an evil twin

idk, i guess this is a little more efficient than brute forcing but in terms of real security against a determined adversary i guess i don't see a difference. i suppose for your neighborhood teen who wants to steal your wifi this is a lower barrier to entry

does deauth actually let you get in or is it just denial-of-service?

angry_keebler
Jul 16, 2006

In His presence the mountains quake and the hills melt away; the earth trembles and its people are destroyed. Who can stand before His fierce anger?

Farmer Crack-rear end posted:

does deauth actually let you get in or is it just denial-of-service?

deauth forces a new handshake, which you can capture and then brute force the key

once you have the key, then you can do whatever, or use that information to do an evil twin and then really do whatever

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006

the worst case scenario for windows is someone might crack your group key eventually if they can keep it from changing long enough or if you have someone on your network that you kick off they could keep the key alive. either way they best they can do is get multicast + broadcast traffic. w/ Linux they just own all your traffic immediately.

  • Locked thread