PC Tech for Hire
  • Home
  • Services
    • ProActive Care >
      • Antivirus
      • Backup
    • Web Hosting >
      • Showcase
    • Virus/Spyware Removal
    • PC Refresh
    • PC Reimage
    • Data Recovery
    • Recycling
    • Training
  • Blog
  • Recommendations
  • Remote Support

New WiFi Issue Could Affect Millions Of Users And Devices

10/17/2017

0 Comments

 
Picture
Security researchers have found a new critical security flaw dubbed "Krack" (Key Reinstallation Attacks) that affects literally every WiFi router and smart phone in use today. The reason? The security flaw resides in the WiFi standard itself, rather than in a third-party product.

In addition to being vast in scope and scale, Krack is a particularly nasty, versatile flaw, allowing hackers to intercept credit card numbers, passwords, photos and a whole host of sensitive personal information.

It works like this: A hacker finds a vulnerable WPA2 network, and then makes an exact copy of it, including impersonating the MAC address. This clone then serves as a "man in the middle" allowing the hacker who controls it to intercept everything passing through it.
WPA2 encryption requires a unique key to encrypt each block of plain text, but because Krack attacks make a copy that's indistinguishable from the original, they're able to use the same encryption key.

As bad as that is, it gets worse for Android and Linux users. Thanks to a bug in the WPA2 standard, these devices don't force the client to demand a unique encryption key with each use. Instead, they allow the key to be "zeroed out," literally creating an encryption key containing all zeroes, which interferes with a key part of the handshake process.

In addition to that, hackers can deploy specialized scripts that can cause the connection to bypass HTTPS, which leaves passwords and other normally protected data exposed.
​
If there's a silver lining, it is that the attack can't be used to target routers directly, but honestly, that's not much of a silver lining, because the potential damage this new vector could cause is virtually without limit.

Unfortunately, until a patch is released, there's not much you can do, short of turning off WiFi altogether. This may work for smartphone users, but it is simply impractical for routers.

There's some good news, though. The fix should be relatively easy to implement, although no ETA has been given at this point.

0 Comments

Your comment will be posted after it is approved.


Leave a Reply.

    Ronnie Morgan

    Hi!  I'm Ronnie, your PC Tech for Hire for the Montgomery, AL area!  Let me know if you need my 25+ years of experience to help you with your computer needs.

    Archives

    January 2018
    November 2017
    October 2017
    September 2017
    May 2016
    April 2016
    February 2016
    January 2016
    November 2015
    September 2015
    August 2015
    April 2015
    March 2015
    February 2015
    January 2015
    December 2014
    November 2014
    October 2014

    Categories

    All
    Antivirus
    Backup
    Computer Repair
    Computer Services
    Hacking
    Malware
    Montgomery
    Network
    Phishing
    ProActive Care
    Ransomware

    RSS Feed

Terms and Conditions                                                                                                                       Site Map                                                                                                       ©2016 PC Tech for Hire, LLC
  • Home
  • Services
    • ProActive Care >
      • Antivirus
      • Backup
    • Web Hosting >
      • Showcase
    • Virus/Spyware Removal
    • PC Refresh
    • PC Reimage
    • Data Recovery
    • Recycling
    • Training
  • Blog
  • Recommendations
  • Remote Support