KRACK Attack: What you need to know

KRACK Attack: What you need to know

The recently-disclosed Key Reinstallation Attacks (KRACK) are a series of serious weaknesses in the WPA2 protocol that is used to secure the vast majority of modern Wi-Fi networks.

The vulnerabilities are within the Wi-Fi standard itself, and not individual products or implementations. As such, all Wi-Fi enabled devices should be considered affected, and vulnerable, until a patch is made available by their respective vendors.

An attacker within range of a Wi-Fi client can trick that client into using a cryptographic key that the attacker is able to calculate, thus allowing the attacker to decrypt and eavesdrop on all of the network traffic between the Wi-Fi client and the Access Point. This could allow the attacker to steal usernames and passwords, as well as personal or financial information.

How worried should I be?

Although this is a significant attack against the WPA2 protocol, and the details of these vulnerabilities have been disclosed, no tooling has been made available thus far, although it is not inconceivable that attackers could create their own tools to perform such an attack.

Furthermore, an attacker wishing to target you would need to be within Wi-Fi range of your devices, making this very much a local attack.

How do I protect myself?

As previously mentioned, any Wi-Fi enabled device (computer, phone, tablet, e-reader, watch, etc) is likely to be affected. The only way to fully mitigate these vulnerabilities is to wait for device manufacturers to release software patches and then install those as soon as possible.

In the interim, the only way to mitigate an attack using KRACK is to avoid using Wi-Fi (in favour of Ethernet or 4G). Users for whom this is not an option, additional effort and awareness should be put into ensuring connections are made using encryption. Two ways to do this are to use a Virtual Private Network (VPN), either one provided by your company for corporate use, or a reputable VPN service for private use. Alternatively, ensuring all websites are visited using SSL/TLS (i.e. URLs start with https://), and being vigilant for ‘insecure website’ browser warning, which could indicate the connection is being tampered with.

Two tools that can help in this regard are HTTPS Everywhere from the Electronic Frontier Foundation (https://www.eff.org/https-everywhere), or the Brave browser for iOS devices (https://brave.com/).

This guidance/information is correct at the time of writing (2pm, 16 October 2017).

If you are unsure what immediate actions you need to take to ensure your organisation is protected, please get in touch and we can provide advice.

As always, if you suspect a breach has happened, contact our incident response team as soon as possible. 

Subscribe for more Research like this

Please type your first name
Please type your last name
Please enter a valid email address

About Sebastien Jeanquier

Principal Consultant, Assurance

CREST
CREST STAR
CHECK IT Health Check Service
CTAS - CESG Tailored Assurance Service
CBEST
PCI - Approved Scanning Vendor
Cyber Essentials
CESG Certified Product
CESG Certified Service
First - Improving Security Together
BSI ISO 9001 FS 581360
BSI ISO 27001 IS 553326