Security Alert! 你的Wi-Fi会受到KRACK的影响!

Mauro Rizzi
October 18, 2017

Serious security weakness discovered in WPA2 in the last day or two presents a serious security issue for Wi-Fi networks and the devices that use them.

WPA2, 这就是所有现代Wi-Fi网络的安全方式吗, has weaknesses that can be exploited by an attacker within range of a victim using key reinstallation attacks (KRACKs). 研究人员发现 Mathy Vanhoef, KRACK exploits limitations in implementations of the handshake processing in the 802.11 protocol.

克拉克安全变更

它如何破解你的Wi-Fi?

There is a process by which every device is authenticated before it is allowed access to a Wi-Fi network. This process is invisible to the end-user so there would be no obvious way for you to know that a security break has occurred.

When your device uses a four-way authentication "handshake", it is the third step that is targeted. This is the step where a Wi-Fi client attempts to connect to a protected Wi-Fi network. The encryption key may be resent multiple times during this step, which if collected by the attackers and replayed in specific ways, 802.11 .安全加密可以被破解. For a more technically detailed explanation, check out Mathy Vanhoef’s 黑客攻击网站.

当Wi-Fi安全被KRACK破坏时会发生什么?

Many people blindly assume that whatever Wi-Fi network they are using, their personal and business data is protected from prying eyes. However, by exploiting the weaknesses as KRACK does, the attacker can eavesdrop on all 没有交通 你通过网络发送. That data might include sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on.

然而,也不全是坏消息

There are no automated tools that allow someone to deliver this attack in a simple way today. 事实上,铁集团的首席技术官 Alex Hudson says an attacker needs to be on the same Wi-Fi network as you in order to carry out any nefarious plans with KRACK. "You’re not suddenly vulnerable to everyone on the internet," he says.

In the meantime …

Stick to websites that use HTTPS encryption as data encrypted with a higher-level protocol like HTTPS and or TLS, is safe. Check for the green lock in the address bar that ensures your web browser shows it is safe to browse with HTTPs. Secure websites are still secure even with Wi-Fi security broken. 加密网站的url将以“HTTPS”开头,,而不安全的网站则以“HTTP”开头.“电子前沿基金会非常棒 HTTPS Everywhere浏览器插件 can force all sites that offer HTTPS encryption to use that protection.

If you’re using an encrypted virtual private network (VPN) then your traffic is secured even in case of a successful KRACK attack.

还有我的wifi密码?

This vulnerability does not expose nor reveal your Wi-Fi credentials in use on the network to an attacker. So, there’s no need to change the password as part of a mitigation. The exploit targets information that should have been encrypted by the WLAN infrastructure, so the attacker doesn’t need to crack your password to implement it.

Should I contact my network vendor regarding their products?

Your network vendor should be aware of KRACK and providing either patches or workarounds for their products.

如果您是ALE的客户或合作伙伴, update your OmniAccess and OmniAccess Stellar WLAN products to the latest available software releases which include patches for the flaw.

We are investigating the potential impact on all of our products and will publish updates as soon as possible on our ALE public website for security advisories. Check our 安全建议页面  定期获取最新资讯.

Mauro Rizzi

Mauro Rizzi

Network Business Development Director, Alcatel-Lucent Enterprise

Mauro joined ALE in 2009 to support the Central Mediterranean Countries with his presales skills and abilities. He then took the challenge to move to the position of business developer for the SEMEA region and visited quite a lot of customers around the globe and especially in Africa. Mauro is currently in charge of the development of the ALE networking business through the assistance and support in the roadmap definition and evolution. He supports the development of the marketing assets for inbound and outbound campaigns and special, dedicated programs meant to enable partners to be able to sell more and get more out of the solution proposed by Alcatel-Lucent Enterprise.

Mauro graduated as an Electronic Engineer from the University of Brescia and then achieved an MBA from University of Padua. 38岁的Mauro Rizzi是一名健身和科技爱好者

About the author

Latest Blogs

AI在网络安全博客图片
数字时代网络

人工智能对抗网络威胁的好处和风险

而人工智能可以减少工作量, provide new types of protection and increase adaptablity, 这也带来了新的风险.

演讲中的女性
数字时代通信

降噪对ASR的惊人影响

An ALE study reveals that noise reduction techniques can negatively impact transcription accuracy in Artificial Speech Recognition (ASR) applications.

一个人在看笔记本电脑
业务连续性

供应链弹性和业务适应性

Strategic supply chain resilience and business adaptability to thrive in the face of adversity

网- mod -振兴- edu -博客- 402 x226形象.jpeg
Education

以现代化校园网络振兴教育

A modern, campus-wide network upgrade aligns capabilities with academic, 今天和明天的研究和业务重点. 

Tags - Security, Security

Chat
}