HomeSecurityKr00k: The bug that allows hackers to "break" Wi-Fi networks

Kr00k: The bug that allows hackers to “break” Wi-Fi networks

At the RSA 2020 security conference in San Francisco, security researchers from Slovakian company ESET will detail a new flaw that affects WiFi communications. A hacker can exploit this flaw, called Kr00k, with the goal of intercepting and decrypting WiFi network traffic. According to ESET, Kr00k affects all devices that use Broadcom and Cypress Wi-Fi chips. These are two of the most popular WiFi chipsets in the world and are included almost everywhere, from laptops to smartphones and from access points to smart speakers and other IoT devices. ESET researchers said they tested and confirmed that the Kr00k flaw affects devices from Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3) and Xiaomi (Redmi), as well as access points from Asus and Huawei.Kr00k: The bug that allows hackers to "break" Wi-Fi networks

In addition, ESET stated that more than a billion devices are vulnerable to the Kr00k bug, emphasizing that this is a "conservative estimate", as the number is estimated to be much higher in reality.ESET

But what is Krook? Kr00k is a bug like many other bugs that are discovered every day in the software that everyone uses. The difference is that Kr00k affects the encryption used to secure data packets sent over a WiFi connection.Krook wi-fi error

Typically, these packets are encrypted with a unique “key” that depends on the user’s WiFi password. However, ESET researchers say that for Broadcom and Cypress Wi-Fi chips, this “key” loses its value during a process called “disconnection.” “Disconnection” is something that naturally happens to a WiFi connection. It refers to a temporary disconnection that usually occurs due to a weak WiFi signal. WiFi devices enter a disconnected state many times during the course of a day, and when this happens, they automatically adjust to reconnect to the network they were previously using. ESET researchers say that hackers can put devices in a long disconnected state, receive WiFi packets intended for the attacked device, and then use the Kr00k flaw to decrypt the WiFi traffic. In this way, hackers can intercept and decrypt WiFi packets, which under normal circumstances are considered secure.

On the plus side, the Kr00k bug only affects WiFi connections that use WPA2-Personal or WPA2-Enterprise security protocols with AES-CCMP encryption. This means that if someone is using a device with a Broadcom or Cypress WiFi chipset, they can protect themselves from hacking attacks by using the newer WiFi authentication protocol, WPA3.

It is estimated that patches are already available for most devices. In addition, ESET has been working for months to responsibly disclose the Kr00k bug to Boadcom, Cypress and all other affected companies. According to ESET researchers, devices should already have received patches for the bug. Depending on the type of device, this may only mean installing the latest operating system or software updates ( Android , Apple and Windows devices, some IoT devices ), but a firmware update may be required.

Users can check if they received patches for the Kr00k bug by checking their device's OS/firmware changelog for fixes against CVE-2019-15126.crack

Finally, it is worth mentioning that users are easier to protect against the Kr00k bug than the KRACK, which was very critical and affected the WPA2 WiFi protocol, forcing most device vendors to use WPA3 by default. Later, a new KRACK attack, codenamed Dragonblood, was discovered, which even affected some newer WPA3 connections, but did not affect the entire WiFi ecosystem like the original KRACK attack did. Finally, ESET researchers said that they discovered Kr00k while observing the devastating effects of the KRACK attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS