Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping
arstechnica.com
arstechnica.com
From the earlier thread [1] I gleamed that maybe a MAC filter could help, but it sounds like that's not going to help much because MAC addresses can be easily spoofed.
The article here recommends sticking to sites with HTTPS, which isn't really something we always have control over, and isn't something we can realistically expect our non-technical WiFi users to be able to strictly adhere to.
VPNs were also suggested, but again, mandating that everybody on our WiFi must connect through a VPN is rather impractical, and I'm personally not sure which VPN providers are supposed to be trustworthy to begin with.
If people here have other suggestions, I'd love to hear them.
I imagine everyone else feels the same way: mostly limited by the upstream. If I had 100 Mbps Internet, there'd be no difference, for instance.
Well you don't need a Playstation to begin with, but millions of users find it a useful feature.
> For any competitive game, Wi-Fi is a no-go to begin with.
Sure, but it's also used for streaming, as well as downloading/patching games, including single-player titles.
Your suggestion would have meant that I couldn't connect my Playstation to the Internet, which is a little bit silly, especially given that my scenario is not an uncommon one.
We have to do this because I live in crowded London and WiFi barely works when you have 40 other networks next to you.
That's heinously ugly though.
Hollow baseboards.
Well that was hug's point - yes, you can buy your way out of the problem, but if you have integrated Wi-Fi, you don't need to.
(I know, I know, we here still use traditional computers but we are probably a minority …)
https://lifehacker.com/hack-together-a-way-to-connect-an-ipa...
Plug the USB-to-Ethernet adapter into the camera adapter
Plug an Ethernet cable into the USB-to-Ethernet adapter Plug the Ethernet cable into your router
Plug the lightning cable into the camera adapter
Plug the lightning cable into the power adapter (or powered USB hub)
Plug the power adapter (or powered USB hub) into the wall
Connect the camera adapter (or the powered usb hub) to your iOS device
The attack works against both WPA1 and WPA2, against personal and enterprise networks, and against any cipher suite being used (WPA-TKIP, AES-CCMP, and GCMP).
You can host your own internal VPN, it's just to ensure the traffic over wifi is secure. If you are a corporation you probably have a VPN already, for people outside the office to access the internal network. Then just setup rules so wifi clients can only access the VPN server (however yes, it is easier said that done for most home users).
Luckily most major websites/applications you'll use will have HTTPS and HSTS enabled.
I can recommend Mullvad[1] which takes none of your information for registration, and which ticks all the right boxes on That One Privacy Site's VPN comparison chart[2].
Only use secure transports over wireless connections. Which many including myself have been recommending for years anyway.
Properly configured HTTPS (i.e. servers with good protocol/cypher/key options preferably with HSTS too) should be sufficient so as a user you can make sure you limit what you access over wireless. Luckily HTTPS is becoming very common both for actual web-sites/-applications and other services that use it as a transport (TFS for instance). As a service admin, protect your users by mandating HTTPS.
Similarly, SSH and protocols wrapped in it are safe. RDP should be good too if correctly configured.
If you are using "plain" or broken protocols over wireless (for example, file access via SMB/samba): stop unless the content being accessed is public anyway. This may affect many in office environments. If you are responsible for running a network make sure no traffic via unprotected protocols goes over network legs with wireless access points.
DNS is generally not secure which could a concern for this if spoofing attacks are successful (so far only inspection/eavesdropping attacks have been proven?) as that would allow DNS poisoning. HTTPS and friends still protect your content here if your users use them properly (i.e. they never ignore certificate warnings), though if you are paranoid about privacy (which some people need to be) an outsider knowing what DNS lookups you make could be enough of a concern.
Source: https://www.krackattacks.com/
I wonder if this is also going to require client side patching from the OS vendors.
https://community.ubnt.com/t5/UniFi-Beta-Blog/FIRMWARE-3-9-3...
But I get an 'Access Denied' error when visiting it (I am logged in).
https://www.theregister.co.uk/2017/10/16/wpa2_inscure_kracka...
It is basic knowledge, that in a radio based system, like Wifi, Bluetooth, ZigBee, … you need to be near the source. That is called physics.
With some techniques you may passively can monitor radio waves, but for active attacks you will always need to be close by. That is called physics in general and specifically electromagnetic waves.
Or is this a way to break the Wi-Fi password and connect without it?
> attackers will be able to eavesdrop on nearby Wi-Fi traffic as it passes between computers and access points. It might also mean it's possible to forge Dynamic Host Configuration Protocol settings, opening the door to hacks involving users' domain name service.
Basically they can see all your traffic and modify it. Your LAN becomes the Internet over an open AP and you don't know which servers you're connecting to.
macOS and iOS computers have been issued patches to mitigate the issue on vulnerable networks.
Source: https://m.imore.com/krack-wpa2-wi-fi-exploit-already-fixed-i...
memo to self: Assume that nothing is really secure, so behave.
This was rather obvious from WEP, no?