What to Know About the WIFI Vulnerability

What to Know About the WIFI Vulnerability

As many of you may have heard yesterday, the security protocol used to protect the vast majority of Wi-Fi connections has been partially compromised by Belgian researchers – potentially exposing encrypted wireless traffic to malicious eavesdroppers and attacks. Presidio engineering was notified of the impending release on this information on the evening of October 15, 2017 and has been working diligently to understand the impact to our customers ever since.

Several critical new security vulnerabilities (generally known as Key Reinstallation AttaACKs, or “KRACKs”) were publicly announced yesterday that affect wireless networks using either a pre-shared key (password) or 802.1x (PEAP, EAP-TLS) to authenticate users. Nine of these vulnerabilities require client operating system updates to patch user devices like laptops, mobile phones, tablets, etc. However, one vulnerability in particular affects most wireless vendors — including Cisco and Meraki — and targets Fast Secure Roaming (a.k.a Fast BSS Transition, or FT) capabilities inherent in the 802.11r protocol.

The good news is that there are no automated tools to take advantage of these new vulnerabilities, but that could change quickly – several weeks would be the best guess. It’s also worth noting that any traffic that’s encrypted at the application level isn’t at risk – it’s only wireless application traffic that’s clear-text (DNS, FTP, Telnet) that are subject to being decrypted as a result of this vulnerability.

Again, in order to be fully protected, patches and OS updates will be required on wireless clients and wireless infrastructure devices alike. Microsoft has publicly announced that client devices with automatic updates are protected, and Apple devices are rumored to be protected as well. Cisco WLCs will need to be upgraded to code that is expected to be available this Thursday or Friday.

For Presidio's Engineering Statement on the WPA2 Injection Attack, such as document details the expected impact, where to go for current information, and guidance on how to address the overall vulnerabilities, please contact Matt Rutter, at [email protected].

要查看或添加评论,请登录

Matt Rutter的更多文章

  • The Weekly Seller ?? Empathy (Part 1)

    The Weekly Seller ?? Empathy (Part 1)

    Didn't get The Weekly Seller Newsletter this Monday? Don't worry, here's what you missed. But remember, the only way to…

    1 条评论
  • The Weekly Seller ?? Curiosity (Part 3)

    The Weekly Seller ?? Curiosity (Part 3)

    Part 3 of the Curiosity series comes out tomorrow, March 18th at 9am ET. But, it will not be shared as a LinkedIn…

  • The Weekly Seller ?? Curiosity (Part 2)

    The Weekly Seller ?? Curiosity (Part 2)

    Didn't get The Weekly Seller Newsletter this morning? Don't worry, here's what you missed. But remember, the only way…

  • The Weekly Seller ?? February Recap: Resilience

    The Weekly Seller ?? February Recap: Resilience

    Sign up for the official (and FREE) newsletter distribution so you get each weekly's email every Monday. Unsubscribe at…

    1 条评论
  • The Weekly Seller ?? Resilience (Part 3)

    The Weekly Seller ?? Resilience (Part 3)

    Sales often involves facing rejection and setbacks. This month we've been exploring how 'Resilience' allows us to…

    5 条评论
  • Allow Me To Re-Introduce Myself

    Allow Me To Re-Introduce Myself

    I thought I'd take a moment for a candid reflection on who I am and why you should sign-up to receive my FREE…

    4 条评论
  • The Weekly Seller January Recap: Confidence

    The Weekly Seller January Recap: Confidence

    Last month, The Weekly Seller dove into the power of Confidence and its pivotal role in sales success. I shared…

  • 4-Ways to Provide Secure and Scalable Networks

    4-Ways to Provide Secure and Scalable Networks

    With IT manufacturers driving innovation, tracking new technologies and knowing which ones make sense for you company…

  • How To Make Global Procurement Less Painful

    How To Make Global Procurement Less Painful

    Before we begin, do me a favor, at the bottom in the "Comments" section write the country that has been the hardest…

    2 条评论
  • The Biggest Misconceptions About Managed Services

    The Biggest Misconceptions About Managed Services

    IT leaders are faced with a challenging balancing act: deploying new technologies for growth, profitability, and new…

社区洞察

其他会员也浏览了