I’m in the U.K. at the moment on holidays, but some things need to be announced on our DDLS blog. For those who may have missed it, there is a bug in Wi-Fi which has been given the name Key Reinstallation Attacks (aka. KRACK), which makes it possible to inject and manipulate data as well as eavesdrop on communications over the air. The only main limitation is that an attacker needs to be within range of a victim to exploit these weaknesses.

It affects WPA2 Personal and Enterprise, regardless of the encryption ciphers used by a network. It mostly affects Linux and Android 6.0 and above, as well as macOS and OpenBSD. Windows and iOS are more or less unaffected due to the way they implement WPA2.

Patches will need to be applied to your particular O/S when available.

More information can be obtained from the websites below:

https://www.krackattacks.com/

https://www.theregister.co.uk/2017/10/16/wpa2_krack_attack_security_wifi_wireless/

Stay safe, Terry Griffin

Principal Technologist: Security



Feature Articles


Blog
Understanding PRINCE2 Version 6 vs 7: Themes, risks & issue management
By Fred Carenese | 21 May 2024
Blog
The Growing Importance of Management Skills and the AMA CPM Certification in 2024
By Gary Duffield | 29 July 2024
Blog
Transforming Your Business and Workforce with Microsoft AI Training
By Leif Pedersen | 30 July 2024
Blog
CGEIT Training & Certification: Aligning IT with Business Objectives
By Jeremy Daly | 22 May 2024
Blog
CDPSE Certification: Bridging the Gap Between Privacy and Technology
By Jeremy Daly | 24 May 2024