View Single Post
  #58   Report Post  
Posted to alt.comp.os.windows-10,alt.os.linux,sci.electronics.repair
harry newton harry newton is offline
external usenet poster
 
Posts: 173
Default Did you update your router for the WPA2/PSK KRACK nonce re-use attack yet?

How does this colloquial summary for my family look - in case you want to
send one to YOUR family?
========
People are asking what to do about the KRACK Attack vulnerability (note the
pleonasm), so I figured I'd let everyone know what it is & I figured I'd
give folks the opportunity to ask question if they're concerned.

The canonical site for the attack is written by the white hat who found it:
https://www.krackattacks.com/

Here's my ad-hoc summary, written with respect to what you and I need to
know & do.

1. In May, the white hat notified the government & vendors he found a bug
in all WPA WiFi (e.g., WPA2) where someone who is *close* enough to
intercept the signals can see everything you do.

2. It affects all WiFi but the worst affected is Android at or over version
6, macOS, Linux, and really fast (i.e., 802.11r fast roaming) routers set
up as repeaters (i.e., as a second router).

Far less affected are iPhones, WiFi iPads, WiFi iPods, older Android
devices, Windows computers, and normal routers (e.g., 802.11n or 802.11ac),
especially if they're set up as the main router (and not as a repeater).

3. There is only one viable solution, which is to *update* your device
firmware or software, whether that be a mobile phone, a laptop, a desktop,
a router working as a repeater, or the main router.

The order of priority should be:
a. If you have Android 6+, then you *should* update soon.
b. If you have MacOS or Linux, then you should update soon.
c. If you have an 802.11r router, then you should update soon.

You can take your sweet time on everything else, but everything needs to be
updated.

4. The problem, of course, is *how* to update each device.
a. First look for your device to see if there is an update
https://www.kb.cert.org/vuls/id/228519
b. Then try to find the update
http://www.zdnet.com/article/here-is-every-patch-for-krack-wi-fi-attack-available-right-now/
c. Then update.

What a pain. Let me know if you have questions.
========