• Did you order new AirTags? We've opened a dedicated AirTags forum.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
52,496
14,184



Mathy Vanhoef, a postdoctoral researcher at Belgian university KU Leuven, has discovered and disclosed major vulnerabilities in the WPA2 protocol that secures all modern protected Wi-Fi networks.

wi-fi-mac-800x288.jpg

Vanhoef said an attacker within range of a victim can exploit these weaknesses using so-called KRACKs, or key reinstallation attacks, which can result in any data or information that the victim transmits being decrypted. Attackers can eavesdrop on network traffic on both private and public networks.

As explained by Ars Technica, the primary attack exploits a four-way handshake that is used to establish a key for encrypting traffic. During the third step, the key can be resent multiple times. When it's resent in certain ways, a cryptographic nonce can be reused in a way that completely undermines the encryption.

As a result, attackers can potentially intercept sensitive information, such as credit card numbers, passwords, emails, and photos. Depending on the network configuration, it is also possible to inject and manipulate data. For example, an attacker might be able to inject ransomware or other malware into websites.

Note that the attacks do not recover the password of any Wi-Fi network, according to Vanhoef. They also do not recover any parts of the fresh encryption key that is negotiated during the four-way handshake.

Websites properly configured with HTTPS have an additional layer of protection, but an improperly configured site can be exploited to drop this encryption, so Vanhoef warned that it is not reliable protection.

Since the vulnerabilities exist in the Wi-Fi standard itself, nearly any router and device that supports Wi-Fi is likely affected, including Macs and iOS devices. Android and Linux devices are particularly vulnerable since they can be tricked into installing an all-zero encryption key instead of reinstalling the real key.
This vulnerability appears to be caused by a remark in the Wi-Fi standard that suggests to clear the encryption key from memory once it has been installed for the first time. When the client now receives a retransmitted message 3 of the 4-way handshake, it will reinstall the now-cleared encryption key, effectively installing an all-zero key.
As a proof-of-concept, Vanhoef executed a key reinstallation attack against an Android smartphone. In the video demonstration below, the attacker is able to decrypt all data that the victim transmits.


iOS devices are vulnerable to attacks against the group key handshake, but they are not vulnerable to the key reinstallation attack.

Fortunately, the vulnerabilities can be patched, and in a backwards-compatible manner. In other words, a patched client like a smartphone can still communicate with an un-patched access point like a router.

Vanhoef said he began disclosing the vulnerabilities to vendors in July. US-CERT, short for the United States Computer Emergency Readiness Team, sent out a broad notification to vendors in late August. It is now up to device and router manufacturers to release any necessary security or firmware updates.

Despite the vulnerabilities, Vanhoef says the public should still use WPA2 while waiting for patches. In the meantime, steps users can take to mitigate their threat level in the meantime include using a VPN, using a wired Ethernet connection where possible, and avoiding public Wi-Fi networks.

Vanhoef is presenting his research behind the attack at both the Black Hat Europe and Computer and Communications Security conferences in early November. His detailed research paper (PDF) is available today.

Article Link: Major Wi-Fi Vulnerabilities Uncovered Put Millions of Devices at Risk, Including Macs and iPhones
 

Quu

macrumors 68040
Apr 2, 2007
3,065
5,375
Some providers have already released router side patches to fix this (Mikrotek's RouterOS for example). I'm hopeful most good providers (Asus, Unifi etc) will have patches out within the next two weeks.
 
Comment

Chupa Chupa

macrumors G5
Jul 16, 2002
14,834
7,394
Time for AirPort Extreme firmware update...

Question I have is will Apple since they have abandoned Airport development. If so how far down the model line will they patch. I have the last APE but also some last gen APX I use as satellites. So I'm hoping Apple patches for all models with WPA2 capability. This will be a test to see how much it really cares about user security with it's response time and comprehensiveness since the patch isn't that difficult from what I've read.
 
Comment

al256

macrumors 6502a
Jun 7, 2001
869
301
Apple needs to either drop their Airport and Time Capsule products or publicly affirm their commitment to bringing out new products which resolve this vulnerability. I'm not sure how long this will take to develop and release but don't leave us waiting a product which they have no intention of releasing.
 
Comment

benthewraith

macrumors 68040
May 27, 2006
3,130
137
Miami, FL
Apple needs to either drop their Airport and Time Capsule products or publicly affirm their commitment to bringing out new products which resolve this vulnerability. I'm not sure how long this will take to develop and release but don't leave us waiting a product which they have no intention of releasing.

It's something that can be patched with firmware, not hardware replacement.
 
Comment

StevieD100

macrumors 6502a
Jan 18, 2014
676
1,030
Living Dangerously in Retirement
This can't be overstated. How many hotels, Starbucks, etc. even know what "firmware" is or how to access their WiFi settings? And just think of all the cheap Chinese routers out there that will never see updates from the manufacturer.
That's why I always use a VPN from a device that I want to use in places like Starbucks. Also gets around stupid restrictions on what I can view in foreign parts.
 
Comment

Chupa Chupa

macrumors G5
Jul 16, 2002
14,834
7,394
Vanhoef said he began disclosing the vulnerabilities to vendors in July. US-CERT, short for the United States Computer Emergency Readiness Team, sent out a broad notification to vendors in late August. It is now up to device and router manufacturers to release any necessary security or firmware updates.

Why is the response from manufacturers so slow on something this important?
 
  • Like
Reactions: RuralJuror
Comment

Porco

macrumors 68040
Mar 28, 2005
3,165
6,155
Well this is bad. :eek:

I hope Apple (well, and ... everyone!) patches this on as many of its devices as possible, as soon as possible.
 
Comment
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.