Houston, we’ve had a problem : WPA2 WiFi encryption is cracked, your computers and phones are at risk to be hacked.

@topffer (42156)
France
October 18, 2017 1:00pm CST
Until this week, the WPA2 protocol was supposed to be secure as it could only be attacked by breaking the password with a dictionary or by brute force, and fixes had been made to block a repeated attack at router level. It is no more true since 2 searchers of the University of Leuven in Belgium, Mathy Vanhoef and Frank Piessens, have discovered a major vulnerability permitting to crack WPA2 without needing to crack the password, so it is a matter of seconds. Once cracked all the WiFi data are visible for the attacker, including sensible data like logins and passwords. I give a link to a website that they have created to know the details if you are interested. To be simple, are at risk to be cracked until a fix is released : all Apple computers, tablets and phones, all Linux computers using wpa_supplicant 2.4+, all Android phones and tablets equipped with Android 6.0 and up. Have been patched and are safe provided that you installed the security updates : OpenBSD 6 and 6.1 since August 30th ; Windows 7, 8.1 and 10 since October 10th. A patch has been seeded in iOS 11.1 beta 3, watchOS 4.1 beta 3, tvOS 11.1 beta 3, and macOS High Sierra 10.13.1 beta 2, which are developer versions, on October 16th, but Apple has not stated when they will release these updates. Until a patch is released for your platform, I would recommend to avoid to use WiFi connections for anything needing security. To surf the web or watch a Youtube video, WiFi is alright. My phone, using an old Android version seems safe, while my Linux laptop is at risk. And you ?
This website presents the Key Reinstallation Attack (KRACK). It breaks the WPA2 protocol by forcing nonce reuse in encryption algorithms used by Wi-Fi.
14 people like this
13 responses
@kobesbuddy (74483)
• East Tawas, Michigan
18 Oct 17
I don't understand this, nither do I have an android cell phone. I don't use WiFi so, I'm not at risk for any of this.
5 people like this
@topffer (42156)
• France
18 Oct 17
If you do not use WiFi to connect your computer to internet you do not risk anything.
5 people like this
@kobesbuddy (74483)
• East Tawas, Michigan
18 Oct 17
@topffer We do have WiFi but, I never use it.
3 people like this
@pgntwo (22408)
• Derry, Northern Ireland
18 Oct 17
There was not a simple layman's terms version of this to be found earlier this week... Good share,
4 people like this
@topffer (42156)
• France
20 Oct 17
I shared it as soon as I discovered it. I thought that I was not the only one concerned.
1 person likes this
@pgntwo (22408)
• Derry, Northern Ireland
20 Oct 17
@topffer I can appreciate the seriousness of the exploit, even if reading most sensible accounts of it is exceedingly hard work.
1 person likes this
@pgntwo (22408)
• Derry, Northern Ireland
20 Oct 17
@topffer That tends to happen, I have found.
1 person likes this
@celticeagle (158876)
• Boise, Idaho
18 Oct 17
No Wifi for me then.
4 people like this
@celticeagle (158876)
• Boise, Idaho
18 Oct 17
@topffer .....I have a laptop and have had no problem.
4 people like this
@topffer (42156)
• France
18 Oct 17
@celticeagle Mine runs Linux. I hope that a fix will be released soon.
4 people like this
@topffer (42156)
• France
18 Oct 17
For a phone it is not a big problem, for a laptop it is more embarrassing, I have reconnected mine with a cable.
5 people like this
@louievill (28851)
• Philippines
18 Oct 17
My phone is at risk since it's a marshmallow and I use wi-fi
3 people like this
@topffer (42156)
• France
18 Oct 17
Android has switched to wpa_supplicant with Marshmallow, I hope that they will find a way to fix it, as quite all Linux flavors are also vulnerable actually, the only thing I cannot tell, is if it will be possible to do it with a simple update, or if it will need an upgrade. In the last case, each brand would have to release an upgrade for any different phone, and it will be probably not available for all phones.
3 people like this
@louievill (28851)
• Philippines
18 Oct 17
@topffer I'd just not think about it, it gives me a headache, better buy a hardware wallet for my cryptos lol
3 people like this
@topffer (42156)
• France
18 Oct 17
@louievill Lol, I hope that your cryptos will not also give you a headache.
2 people like this
@LadyDuck (457918)
• Switzerland
19 Oct 17
So my husband was right, the first thing he does when we change the router is to turn the Wi-Fi off, we only use a LAN cable. Thank you for the link.
3 people like this
@topffer (42156)
• France
19 Oct 17
@LadyDuck I am a bit paranoid, and I surf with Tor when I connect to a public WiFi with my phone,using Orbot which is a good app to connect to the Tor network on an Android device.
3 people like this
@topffer (42156)
• France
19 Oct 17
WiFi cannot be 100% secure, but I do not imagine that somebody could spend years to decrypt a recorded WiFi signal, except a state secret service. WPA2, once patched, is still reasonably secure.
3 people like this
@LadyDuck (457918)
• Switzerland
19 Oct 17
@topffer I use my laptop when I wait for him at the hospital. He has a weekly treatment and I have to wait for a little more than one hour. I have no personal data at all stored on that laptop, they can get nothing interesting.
3 people like this
@DaddyEvil (137145)
• United States
19 Oct 17
My phone is running version 5.1 so should be safe. Also my tablets. The only at-risk machine I have is my old pc that I have running Linux right now. Thank you for the information, Top! I will let people know at work today.
3 people like this
@topffer (42156)
• France
19 Oct 17
I discovered that yesterday, and thought that it was important to share it on myLot. Android 6 and above are at risk because they use wpa supplicant like quite all Linux flavors. I hope that we will have a patch released quickly.
3 people like this
@DaddyEvil (137145)
• United States
19 Oct 17
@topffer You and me both, Top! I really do appreciate you telling us! I hadn't encountered this information yet.
3 people like this
@KrauseHome (36448)
• United States
21 Oct 17
I have seen a lot of updates coming thru in the last couple of days, so I am sure most are aware. One of the largest recent issues was accessing Facebook from a phone, etc.
1 person likes this
@topffer (42156)
• France
21 Oct 17
Microsoft deserves congratulations in this case, they have reacted at light speed to release a security update for all supported Windows versions
@1hopefulman (45123)
• Canada
20 Oct 17
That sounds terrible!
1 person likes this
@1hopefulman (45123)
• Canada
20 Oct 17
@topffer Is it the public WiFi that is having the problem or also the one we have at home?
1 person likes this
@topffer (42156)
• France
20 Oct 17
@1hopefulman The public WiFi is usually not encrypted, it is the WiFi in your home, like in any business, that are at risk here.
1 person likes this
@topffer (42156)
• France
20 Oct 17
That's terrible, but it will be probably fix for all OS in a few weeks.
1 person likes this
• Pamplona, Spain
20 Oct 17
I don´t use wifi at all. Its good to warn all others though thank you as they are not aware of what might go on. My mobile is not a smart phone either although sometimes I wish that it was.
1 person likes this
• Pamplona, Spain
20 Oct 17
@topffer I feel a bit sheepish as most everyone has a smart phone and I have this ordinary one but it is new. Its what I can afford and I needed to have one living here so I could only buy that. I know they are safer yes and more manageable and you don´t have to keep charging them up so often either.
1 person likes this
@topffer (42156)
• France
20 Oct 17
Phones who are not smart are the most secure, they stay free of virus and malware.
1 person likes this
@topffer (42156)
• France
20 Oct 17
@lovinangelsinstead21 As long as it does the job for you, it is alright. My smartphone was not very expensive for a 4G smartphone, I bought it new 130 Euros, and you can find small second hand smartphones for 40 Euros. I have to charge mine every evening, and I do not use it a lot.
1 person likes this
@much2say (53959)
• Los Angeles, California
20 Oct 17
Oh great. Well looks like I need to study this . . . I think I have the newer Android but I don't really do anything that needs security. I was going to say we have no laptop but Hubby does bring home the laptop from work . . . I better see if he knows about this !
1 person likes this
@much2say (53959)
• Los Angeles, California
20 Oct 17
@topffer Ok, will have to discuss this with Hubby. He is way more savvy about this stuff and would understand all the lingo . . . but I do understand "problem" and "hacked" !
1 person likes this
@jstory07 (134393)
• Roseburg, Oregon
18 Oct 17
I have an android cell phone so I hope it is safe. After all it is suppose to be a cell phone.
3 people like this
@topffer (42156)
• France
18 Oct 17
All phones are safe if you do not use a WiFi connection. The versions of Android before 6.0 Marshmallow (released in November 2015) are safe. 6 and up are using wpa_supplicant and are at major risk to have their wifi hacked.
3 people like this
@jstory07 (134393)
• Roseburg, Oregon
19 Oct 17
@topffer It is a smart phone with a wifi connection. We run the security program every day.
2 people like this
@JESSY3236 (18911)
• United States
20 Oct 17
My fiance has an apple computer. I'll let him know.
1 person likes this
@topffer (42156)
• France
20 Oct 17
If it is not already fixed, it will probably be soon fixed for Apple. I will have to wait more, as Linux developers are not paid.
@YrNemo (20261)
18 Oct 17
I will have to go do more research about this. Your discussion worried me. I use a laptop, wifi but my laptop is not having anything to do with Apple or Linus, should I still worry?
3 people like this
@topffer (42156)
• France
18 Oct 17
If it is a Windows laptop, and the updates are done automatically, then it is safe. Microsoft fixed the vulnerability in a security update released on October 10th for all the supported versions of Windows.
3 people like this
@YrNemo (20261)
19 Oct 17
@topffer I am tempted to do a happy dance after reading your reply, but I am too sleepy, I will do that happy dance later when I have more time . Thanks .
3 people like this