Technoglitch
Core Member
Called KRACK, the attack does not actually recover the victim's Wi-Fi password. It works by reinstalling the encryption key that's already in use which, due to a flaw in WPA2, can be used to remotely decrypt traffic.
Since this is a hole in the WPA2 protocol itself, all devices are affected in some way, no matter the software you're running. Wi-Fi routers, Android phones, iOS devices, Apple computers, Windows computers, Linux computers — all of them.
The vulnerability is extremely dangerous. An attacker could use it to decrypt some or all traffic from a network, including your passwords, credit card numbers, metadata such as cookies etc. In some cases, an attacker could be able to inject malicious data directly into the traffic, like adding malware to a (normally safe) website you're visiting.
Depending on the encryption protocols one uses, the attack can range from bad to worse; in some cases, an attacker will only be able to decrypt your traffic. In others, they'll be able to essentially take over your connection, forging and injecting packets as they please.
For example, 41% of Android devices and currently in use and numerous Linux variants are vulnerable to a particularly nasty variant of the attack, which according to Vanhoef, "makes ittrivial to intercept and manipulate traffic sent by these Linux and Android devices."
Huge security flaw leaves Wi-Fi devices wide open to hackers
Since this is a hole in the WPA2 protocol itself, all devices are affected in some way, no matter the software you're running. Wi-Fi routers, Android phones, iOS devices, Apple computers, Windows computers, Linux computers — all of them.
The vulnerability is extremely dangerous. An attacker could use it to decrypt some or all traffic from a network, including your passwords, credit card numbers, metadata such as cookies etc. In some cases, an attacker could be able to inject malicious data directly into the traffic, like adding malware to a (normally safe) website you're visiting.
Depending on the encryption protocols one uses, the attack can range from bad to worse; in some cases, an attacker will only be able to decrypt your traffic. In others, they'll be able to essentially take over your connection, forging and injecting packets as they please.
For example, 41% of Android devices and currently in use and numerous Linux variants are vulnerable to a particularly nasty variant of the attack, which according to Vanhoef, "makes ittrivial to intercept and manipulate traffic sent by these Linux and Android devices."
Huge security flaw leaves Wi-Fi devices wide open to hackers