Wi-Fi Encryption Vulnerability (KRACK): Some More Information. by nolnocluap

View this thread on steempeak.com
· @nolnocluap · (edited)
$21.83
Wi-Fi Encryption Vulnerability (KRACK): Some More Information.
<center>
![wifi.png](https://steemitimages.com/DQmZ5neRdLNgcD53u2j3Uhy6vgttMrPLcjmVE9s4JBibv2T/wifi.png)
</center>

There are a few posts about this already but for those who haven't heard yet, the last days have seen a serious vulnerability discovered in the (WPA2) protocol that is widely used to secure most Wi-Fi networks.    

[above image credit](https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it)

From [here](https://github.com/kristate/krackinfo) & [here](https://www.krackattacks.com/)...

<blockquote>
In a key reinstallation attack, the adversary tricks a victim into reinstalling an already-in-use key. This is achieved by manipulating and replaying cryptographic handshake messages. When the victim reinstalls the key, associated parameters such as the incremental transmit packet number (i.e. nonce) and receive packet number (i.e. replay counter) are reset to their initial value. Essentially, to guarantee security, a key should only be installed and used once. Unfortunately, we found this is not guaranteed by the WPA2 protocol. By manipulating cryptographic handshakes, we can abuse this weakness in practice.
</blockquote>

**Unless a known patch has been applied, assume that all WPA2 enabled Wi-fi devices are vulnerable.**

This vulnerability makes it possible for a hacker in proximity to a WPA2 protected Wi-Fi network (in your home, the airport, coffee shop, etc.)  to intercept your transmissions and obtain your sensitive exchanges including passwords, account numbers and other important information.
<center>
![logo-small.png](https://steemitimages.com/DQmRqmpMxB9zZEnhDgbtQb1YUmPDbaEzsxrmCbVAWhktPvX/logo-small.png)
[credit](https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it)
</center>
IT teams globally are in the process of patching corporate Wi-Fi service infrastructure and distributing patches for Microsoft endpoint devices (laptops) which provide protection from this vulnerability.  For non-managed user devices, including those running Android, Apple iOS, MacOS and Linux, the following precautions or actions are recommended:

* Review the additional information on the KRACK vulnerability and the vendors who have patches available or coming soon, at sites [like this](https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it).
* Update the firmware of your home Wi-Fi router, or call your service provider to get your router updated if they are the ones who support it.  Always keep these devices updated.
* Avoid if possible using unfamiliar Wi-Fi networks in the near term, where the status of this vulnerability is unknown. This would include most public (airports, cities, etc.) and private (hotels, service providers) Wi-Fi services.  Over time most Wi-Fi networks will be updated to remove this vulnerability, but it takes time.  
* Avoid logging into bank accounts, financial institutions, work accounts, etc. over Wi-Fi if you want to be certain that your information will not be intercepted. Access any accounts over a wired (ethernet) connection to protect yourself.
* If you must use Wi-Fi, ensure that you are connecting to an SSL/TLS secured website (i.e. sites using https: instead of just http:) which will provide adequate protection for your transactions. Browsers typically have an indicator such as a lock icon to identify an https (SSL/TLS secured) connection.
* Update your self-managed mobile, laptop, home PC and IoT devices:   
   * Apple will release a fix for iOS devices and MacOS devices shortly, so be sure to download and update these as soon as possible.
   * Microsoft released a fix for Windows devices on Oct. 10.
   * Android devices are particularly vulnerable. Google indicated that the fix for KRACK would arrive as part of next month's Android security updates, so be especially cautious until these security updates become available and have been downloaded. 
   * Linux devices may use a number of different distributions. Most have information or patches available.  Check the web regarding your particular distribution and when a fix will become available.  
    * IoT devices are also vulnerable if they use Wi-Fi to connect to the Internet. Check with your personal device’s manufacturer for any update instructions. 

The most important part to resolve the vulnerability is to patch the “client” ie laptop, phone etc end.  However, ideally, all Wifi routers should have their firmware updated as well to complete the patching, but isn’t as critical. Many home Wifi/ADSL router manufacturers have not released a patch yet and I suspect many older routers will never be patched. If it is managed by your ISP, you may wish to contact them for information. As long as your computer/mobile device is patched you should be safe though. 

 For those interested, the Windows patches required are below: -

    Windows 10 build 1511 = KB4041689
    Windows 10 build 1607 = KB4041691
    Windows 10 build 1703 = KB4041676
    Windows 7 = KB4041678 and KB4041681

You can find whether this patch has installed by going to control panel > programs and features > Installed Updates: if you see the required patch(s) above for your Operating system then you are patched.

![unnamed.jpg](https://steemitimages.com/DQmZRXMMJABoVUkBUxyVot9AYjbKZTYetW2gJwUCmTVVsbA/unnamed.jpg)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 10 others
properties (23)
post_id15,626,941
authornolnocluap
permlinkwi-fi-encryption-vulnerability-krack-some-more-information
categorytechnology
json_metadata"{"app": "steemit/0.1", "format": "markdown", "links": ["https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it", "https://github.com/kristate/krackinfo", "https://www.krackattacks.com/"], "image": ["https://steemitimages.com/DQmZ5neRdLNgcD53u2j3Uhy6vgttMrPLcjmVE9s4JBibv2T/wifi.png"], "tags": ["technology", "news", "wifi", "world", "life"]}"
created2017-10-19 09:38:57
last_update2017-10-19 09:40:18
depth0
children8
net_rshares9,503,315,994,569
last_payout2017-10-26 09:38:57
cashout_time1969-12-31 23:59:59
total_payout_value17.767 SBD
curator_payout_value4.061 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length5,374
author_reputation41,051,906,712,730
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (74)
@steemitrobot ·
http://i.imgur.com/0L71kDM.png
This post was resteemed by @steemitrobot!
Good Luck!

> **Resteem your post just send 0.100 SBD or Steem with your post url on memo. We have over 2000 followers. Take our service to reach more People.**

> **Pro Plan: just send 1 SBD or Steem with your post url on memo we will resteem your post and send 10 upvotes from our Associate Accounts.**

The @steemitrobot users are a small but growing community.
Check out the other resteemed posts in steemitrobot's feed.
Some of them are truly great. Please upvote this comment for helping me grow.
properties (22)
post_id15,626,974
authorsteemitrobot
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t094033405z
categorytechnology
json_metadata"{"app": "busy/1.0.0", "tags": ["technology"]}"
created2017-10-19 09:39:54
last_update2017-10-19 09:39:54
depth1
children0
net_rshares0
last_payout2017-10-26 09:39:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length575
author_reputation-780,229,240,448
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@lahcen80 · (edited)
A beautiful post with information that can be used and this is what I look for in our steemit community
properties (22)
post_id15,628,069
authorlahcen80
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t100440265z
categorytechnology
json_metadata"{"app": "steemit/0.1", "tags": ["technology"]}"
created2017-10-19 10:04:30
last_update2017-10-19 10:05:27
depth1
children0
net_rshares0
last_payout2017-10-26 10:04:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length103
author_reputation105,789,957,935
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@nirgf ·
Interesting article
	Thank you
Follow Me @NirGF
properties (22)
post_id15,628,501
authornirgf
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t101302861z
categorytechnology
json_metadata"{"app": "steemit/0.1", "users": ["nirgf"], "tags": ["technology"]}"
created2017-10-19 10:13:06
last_update2017-10-19 10:13:06
depth1
children0
net_rshares0
last_payout2017-10-26 10:13:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length47
author_reputation3,658,755,036,990
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@lpreap ·
Crazy that it was hacked, but useful information.
properties (22)
post_id15,628,521
authorlpreap
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t101334026z
categorytechnology
json_metadata"{"app": "steemit/0.1", "tags": ["technology"]}"
created2017-10-19 10:13:36
last_update2017-10-19 10:13:36
depth1
children0
net_rshares0
last_payout2017-10-26 10:13:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length49
author_reputation54,954,087,385,762
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@alidanish786 ·
yes I know black hat hackers always make a new way to hack wifi..and they also hack bank accounts and even the facebook or gmail account.But thank you to aware us with the tips how to prevent from being hack.nice post.
properties (22)
post_id15,628,913
authoralidanish786
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t102151336z
categorytechnology
json_metadata"{"app": "steemit/0.1", "tags": ["technology"]}"
created2017-10-19 10:21:54
last_update2017-10-19 10:21:54
depth1
children0
net_rshares0
last_payout2017-10-26 10:21:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length218
author_reputation967,287,455,495
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@minnowsupport ·
<p>Congratulations!  This post has been upvoted from the communal account, @minnowsupport, by nolnocluap from the Minnow Support Project.  It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, someguy123, neoxian, followbtcnews/crimsonclad, and netuoso.  The goal is to help Steemit grow by supporting Minnows and creating a social network.  Please find us in the <a href="https://discord.gg/HYj4yvw">Peace, Abundance, and Liberty Network (PALnet) Discord Channel</a>.  It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.</p>
properties (22)
post_id15,630,366
authorminnowsupport
permlinkre-nolnocluap-wi-fi-encryption-vulnerability-krack-some-more-information-20171019t104916896z
categorytechnology
json_metadata"{"app": "cosgrove/0.0.1", "tags": ["technology"]}"
created2017-10-19 10:49:15
last_update2017-10-19 10:49:15
depth1
children0
net_rshares0
last_payout2017-10-26 10:49:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length611
author_reputation104,981,098,086,561
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@cloudspyder ·
My advice use a strong password, in my experience a corporate wi-fi can take down at the average time of 30 minutes using bruteforce and
properties (22)
post_id15,632,306
authorcloudspyder
permlinkre-nolnocluap-20171019t19328698z
categorytechnology
json_metadata"{"app": "esteem/1.4.6", "format": "markdown+html", "community": "esteem", "tags": "technology"}"
created2017-10-19 11:27:24
last_update2017-10-19 11:27:24
depth1
children0
net_rshares0
last_payout2017-10-26 11:27:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length136
author_reputation7,356,422,544,596
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries
0.
accountesteemapp
weight500
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@mrsquiggle ·
This post received an upvote from MSP3k.com
This post received a 15% vote by @mrsquiggle courtesy of @choogirl from the Minnow Support Project ( @minnowsupport ). [Join us in Discord](https://discord.gg/tuJsjYk).

Upvoting this comment will help support @minnowsupport.
properties (22)
post_id15,633,684
authormrsquiggle
permlinkthis-post-received-an-upvote-from-msp3k-com-1508413696
categorytechnology
json_metadata"{"app": "msp3k/1.0", "format": "markdown+html", "community": "minnowsupport", "tags": ["minnowsupport", "msp3k", "minnowsupportproject", "steemit", "minnowsunite"]}"
created2017-10-19 11:48:18
last_update2017-10-19 11:48:18
depth1
children0
net_rshares0
last_payout2017-10-26 11:48:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length225
author_reputation2,996,861,459,862
root_title"Wi-Fi Encryption Vulnerability (KRACK): Some More Information."
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000