Krack Attacks: A few days ago I reported via SecNews.gr about a flaw in the Wi-Fi standard that can be used by attackers to monitor wireless network traffic even if WPA2 protection is used.
Today we will see how much the bug can affect you, and who is most at risk.
The explanation of the attack
Key Reinstallation Attacks or Krack Attacks work on all Wi-Fi networks protected by the WPA2 protocol and in some cases can be used for injections that result in data manipulation. The attack works on WPA and WPA2 security standards against personal and corporate networks that have Wi-Fi connections.
The attack method works against the 4-way handshake of the WPA2 protocol. This handshake is performed when client devices, such as a smartphone or laptop, try to connect to the Wi-Fi network.
The handshake verifies credentials and negotiates an encryption key that is then used to protect traffic for as long as the connection remains active.
The main flaw discovered by the researchers affects the key and is achieved by “manipulating and replying cryptographic handshake messages”.
The researchers note that the data being transferred can (theoretically) be decrypted by the attacker.
Can the attack affect me?
Let's start with the good news. KRACK attacks are difficult for hackers to carry out for one simple reason: they have to be within range of a Wi-Fi network. Unlike some other global attacks like Heartbleed and Shellshock, the hacker cannot execute the KRACK attack remotely.
Second, a hacker can only attack one network at a time. Let's say the attacker is sitting in a public place, say a coffee shop in downtown Athens. It's very likely that he sees hundreds of networks within range, but there's no way he can attack all of them at once.
So if a hacker is thinking of launching a KRACK attack, the most likely targets could be large hotels, airports, train stations, or large public networks with thousands of people connecting every day.
Your home network is almost certainly safe.
The bad news? A KRACK attack has the potential to destroy you.
With a successful Krack attack, a hacker can easily obtain credit card numbers, passwords, your chats, emails, photos, and more. This can lead to financial losses and of course, identity theft. It should also be mentioned that with certain network configuration settings, attackers can inject malware, ransomware, and spyware into websites you visit and, by extension, into your computer.
Can KRACK be fixed?
Yes, hardware manufacturers and software developers can patch devices and software vulnerable to KRACK attacks. Microsoft and Apple were particularly quick, releasing beta patches the same day the flaw was publicly announced. Google has said it will release an updated version of Android in the coming weeks.
However, just because you use Wi-Fi connections on your mobile devices doesn't mean that the problem will be solved by just updating the software on those devices. The attack mainly targets routers but also IoT devices, so you should update your router or smart fridge immediately. This will probably take a long time, as many of the companies that make these devices are not as aware as Microsoft and Apple.
Your router is arguably the most critical device to update. If the model you are using has not updated its firmware, it would be a good idea to contact your internet provider and request an update as soon as possible.
What can I do until they decide to update the Firmware?
Use Ethernet: KRACK doesn’t affect the web in general, it just targets Wi-Fi connections. If you can connect to a network using an ethernet cable, your device will be safe.
Use cellular data on your phone: Similarly, when using mobile phones, just use your mobile internet connection rather than public Wi-Fi.
Tether connections from your phone: In public, it may be safer to use your phone’s tethering option rather than connecting directly to a Wi-Fi network.
Disable vulnerable Internet of Things (IoT) devices: You may not be worried about a hacker gaining access to your refrigerator’s data, but you should be concerned if they gain access to your network. Temporarily disable any highly sensitive IoT devices until a firmware update is available.
Use VPN: VPNs (virtual private networks) encrypt all of your network traffic, so even if a hacker manages to gain access with a KRACK attack, they won’t be able to decrypt it.
Are you worried about KRACK attacks?
The KRACK attacks are yet another reminder that we are not as invulnerable as we like to think.
We may use strong passwords, apps like KeePass, update software and firmwares, take a thousand security precautions, but ultimately we are at the mercy of the technology we use. As long as a technological flaw is discovered, it doesn't matter how consistent we are with security advice.
It should be mentioned that due to the nature of the attack and the degree of difficulty, you shouldn't worry too much, unless of course you are a very important person.
