WiFi vulnerability, needs quick fix to stop attacks.

WiFi vulnerability, needs quick fix to stop attacks.

General

Cookies help us deliver our Services. By using our Services or clicking I agree, you agree to our use of cookies. Learn More.

s
Fast and Curious

slatington, pa, usa

Joined
28 Dec 04
Moves
53223
16 Oct 17

https://phys.org/news/2017-10-flaw-compromise-wi-fi.html#nRlv

Über-Nerd

Joined
31 May 12
Moves
8320
16 Oct 17
1 edit

I never liked WiFi. The links go down when you least need them to. Now I like it even less, even when the links are up.

Here's a link to a tech site which explains in detail what is going on:

https://www.krackattacks.com

s
Fast and Curious

slatington, pa, usa

Joined
28 Dec 04
Moves
53223
17 Oct 17

Originally posted by @moonbus
I never liked WiFi. The links go down when you least need them to. Now I like it even less, even when the links are up.

Here's a link to a tech site which explains in detail what is going on:

https://www.krackattacks.com
There are certainly advantages to WIFI like not using cell phone data which you pay for, on phone calls and video games. Do you know if firmware upgrades takes care of this situation?

rain

Joined
08 Mar 11
Moves
12351
17 Oct 17

This, coming on the heels of the Equifax data breach, is pretty worrisome.

Joined
18 Jan 07
Moves
12466
18 Oct 17
1 edit

Originally posted by @vivify
This, coming on the heels of the Equifax data breach, is pretty worrisome.
This really has nothing at all to do with Equifax. It also isn't quite as worrisome as it's made out to be. Something to take note of, certainly, but not something that should make you panic. The Equifax breach should, if you're in the USA, and make you angry, too.

Krack is a technical error which only breaks WiFi encryption. If you're wired, you have no problem, if you visit an https-encrypted page, you're encrypted twice, and Krack still only breaks WPA and leaves you protected by TLS - like being able to read an envelope but not the letter inside.
Only if you visit plain http sites over WiFi are you vulnerable, or if you use newer and unpatched versions of Linux and Android. All the rest of us should just patch our systems when the patches are published, and not do anything stupid like unencrypted e-banking.

Equifax, by contrast, is a massive data breach at exactly the kind of company who should not have data breaches, even small ones. They did everything wrong, lied and delayed, and by some accounts still do. There are no precautions those affected can take, and Equifax are only trying to cover their own fundament. That is much more dangerous.

Über-Nerd

Joined
31 May 12
Moves
8320
18 Oct 17

Originally posted by @sonhouse
... Do you know if firmware upgrades takes care of this situation?
Firmware upgrades should do, but it will depend on each manufacturer to issue one and to ensure that the patch really closes the loophole. There are hundreds or maybe even thousands of equipment manufacturers out there affected by this, and, unfortunately, hardly any reliable way for the man on the Clapham bus to determine whether the particular device he owns has been fixed.

rain

Joined
08 Mar 11
Moves
12351
18 Oct 17

Originally posted by @shallow-blue
This really has nothing at all to do with Equifax. It also isn't quite as worrisome as it's made out to be. Something to take note of, certainly, but not something that should make you panic. The Equifax breach should, if you're in the USA, and make you angry, too.

Krack is a technical error which only breaks WiFi encryption. If you're wired, you ha ...[text shortened]... can take, and Equifax are only trying to cover their own fundament. That is much more dangerous.
I only mentioned Equifax, because there seem to be more and more troubles with data being breached or compromised. Thanks for the explanation, much appreciated.

Misfit Queen

Isle of Misfit Toys

Joined
08 Aug 03
Moves
36693
29 Oct 17

Originally posted by @moonbus
Firmware upgrades should do, but it will depend on each manufacturer to issue one and to ensure that the patch really closes the loophole. There are hundreds or maybe even thousands of equipment manufacturers out there affected by this, and, unfortunately, hardly any reliable way for the man on the Clapham bus to determine whether the particular device he owns has been fixed.
Netgear has finally released a firmware upgrade for my router. Not sure if it actually solves the problem, but my computers are wired into the network instead of WiFi, and I use 5G on my tablet, so hopefully I'm good.

Misfit Queen

Isle of Misfit Toys

Joined
08 Aug 03
Moves
36693
29 Oct 17

Originally posted by @shallow-blue
This really has nothing at all to do with Equifax. It also isn't quite as worrisome as it's made out to be. Something to take note of, certainly, but not something that should make you panic. The Equifax breach should, if you're in the USA, and make you angry, too.

Krack is a technical error which only breaks WiFi encryption. If you're wired, you ha ...[text shortened]... can take, and Equifax are only trying to cover their own fundament. That is much more dangerous.
The best precaution is a credit monitoring service, which should alert one to problems with unauthorized actions like new accounts.

Joined
18 Jan 07
Moves
12466
30 Oct 17

Originally posted by @suzianne
The best precaution is a credit monitoring service, which should alert one to problems with unauthorized actions like new accounts.
Yeah, except that's exactly what Equifax pretends ro provide for consumers...

s
Fast and Curious

slatington, pa, usa

Joined
28 Dec 04
Moves
53223
30 Oct 17

Originally posted by @suzianne
Netgear has finally released a firmware upgrade for my router. Not sure if it actually solves the problem, but my computers are wired into the network instead of WiFi, and I use 5G on my tablet, so hopefully I'm good.
You would be good for that vulnerability but I hope you have unlimited data, you will be using gigabytes of it on your tablet. I ran into my own 2 gig limit just playing chess on Lichess.

Über-Nerd

Joined
31 May 12
Moves
8320
31 Oct 17

Originally posted by @suzianne
Netgear has finally released a firmware upgrade for my router. Not sure if it actually solves the problem, but my computers are wired into the network instead of WiFi, and I use 5G on my tablet, so hopefully I'm good.
Cabled links are not affected by this issue. Stick to cable and you're invulnerable to this particular exploit.

There are other good reasons to go with cable anyway, such as full-duplex transmission (wireless is half-duplex).

Über-Nerd

Joined
31 May 12
Moves
8320
31 Oct 17

Originally posted by @sonhouse
... I ran into my own 2 gig limit just playing chess on Lichess.
That's only because your combinations were too deep. 😉