Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
ozymandOS
Jun 9, 2004

github just kicked my yubikey 4's off my account due to this vuln

yubikey 4 cannot receive firmware updates

welp

Adbot
ADBOT LOVES YOU

scottch
Oct 18, 2003
"It appears my wee-wee's been stricken with rigor mortis."

ate all the Oreos posted:

how about that "iOS and Windows are still vulnerable to the group key handshake" bit

from the paper: "Finally, when the group key handshake is attacked, an adversary can replay group-addressed frames, i.e., broadcast and multicast frames."

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



eversion posted:

github just kicked my yubikey 4's off my account due to this vuln

yubikey 4 cannot receive firmware updates

welp

good news tho

https://www.yubico.com/keycheck/verify_otp

apseudonym
Feb 25, 2011

Honestly if in 2017 you rely on wifi encryption alone you're doing it really wrong.

If you're worried about your devices getting into hostile networks I sure hope you've never paired to any open networks since thats the way we've setup mitms forever.

Cybernetic Vermin
Apr 18, 2005

there have been quite a few of those posts already though, and i keep wondering whether they should be read "99.99% of users are loving idiots and should get off the internet", and whether you actually have been advicing your friends and family to not use wifi

Thanks Ants
May 21, 2004

#essereFerrari


lomarf, ubiquiti have a firmware out for their poo poo already, aerohive havent even acknowledged it as an issue that needs addressing

:rip:

McGlockenshire
Dec 16, 2005

GOLLOCKS!
so just to make sure I understand, this is the apocalypse for every wpa_supplicant client that has ever existed and there is no patch at the AP that will mitigate it?

post hole digger
Mar 21, 2011

Thanks Ants posted:

lomarf, ubiquiti have a firmware out for their poo poo already, aerohive havent even acknowledged it as an issue that needs addressing

:rip:

ruckus either lol

Thanks Ants
May 21, 2004

#essereFerrari


buy bin wifi, replace it every two years

M_Gargantua
Oct 16, 2006

STOMP'N ON INTO THE POWERLINES

Exciting Lemon

apseudonym posted:

Honestly if in 2017 you rely on wifi encryption alone you're doing it really wrong.

If you're worried about your devices getting into hostile networks I sure hope you've never paired to any open networks since thats the way we've setup mitms forever.

so should I be finding a way to wipe all prior key exhange material from all my devices or should they have been doing that well enough through routine garbage collection?

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.

this is what i'm waiting on c'mon aerohive get it together

apseudonym
Feb 25, 2011

M_Gargantua posted:

so should I be finding a way to wipe all prior key exhange material from all my devices or should they have been doing that well enough through routine garbage collection?

Keys wouldn't really be stored afaik

Cybernetic Vermin posted:

there have been quite a few of those posts already though, and i keep wondering whether they should be read "99.99% of users are loving idiots and should get off the internet", and whether you actually have been advicing your friends and family to not use wifi

The exact opposite? If you're using tls and friends the network doesn't matter (and the network is always hostile). This doesn't noticably change the security posture for any device that has an open network in it's pairing list (e.g. Starbucks) aka just about all of them.

Normal people shouldn't get off the Internet, though sometimes I wish parts of the security community would.

Bulgogi Hoagie
Jun 1, 2012

We
hey i wonder if airport extremes will get an update

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE

lol I got mine for free from EFF last summer and it's affected.

gonna give mine to my Dad to use as a FIDO token for GMail since he doesn't even know what github is but he likes having a feeling of doing something cool and secure so that The Saudis can't spy on him (the same way I got him to switch to using FaceTime Audio whenever possible)

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

apseudonym posted:

Normal people shouldn't get off the Internet, though sometimes I wish parts of the security community would.

post hole digger
Mar 21, 2011

folks, folks... everyone should get off the internet, forever.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Btw, supposedly it's only the open gpg keygen functionality that's affected. U2f and otp modes are fine. But go ahead and get your free yubikey everyone, cause why not?

seriously the per unit cost for these is probably like $2 and I hope they're just charging this all back to infineon.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mrmcd posted:

Btw, supposedly it's only the open gpg keygen functionality that's affected. U2f and otp modes are fine. But go ahead and get your free yubikey everyone, cause why not?

seriously the per unit cost for these is probably like $2 and I hope they're just charging this all back to infineon.

i have used the rsa key generator on my yubikey for ssh, but got lucky?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
oh plus yubico could almost certainly buy insurance against this kind of event if they didn't want to hold the risk themselves

Acer Pilot
Feb 17, 2007
put the 'the' in therapist

:dukedog:

The replacement shipping option is kind of confusing. They have like 3 different free shipping options.

spankmeister
Jun 15, 2008






Oh cool I just ordered a free replacement of a yubikey I got for free at blackhat

Phone
Jul 30, 2005

親子丼をほしい。
this belongs here.

Daman
Oct 28, 2011
https://twitter.com/esetglobal/status/919974497926766593

https://www.blog.google/products/chrome/cleaner-safer-web-chrome-cleanup/

uhhh? tavis?

duTrieux.
Oct 9, 2003

Phone posted:

this belongs here.



it's me, the 13-year old who just learned layer filters

Thanks Ants
May 21, 2004

#essereFerrari


aerohive have spoken at last

https://www3.aerohive.com/support/security-bulletins/Product-Security-Announcement-Aerohives-Response-to-KRACK-10162017.html

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
lmao

post hole digger
Mar 21, 2011

lol ruckus's response is some top tier poo poo

quote:

What is the issue?
A research paper was published which claimed to have discovered [lol] a serious vulnerability/weakness in
WPA2 standard more specifically during the WPA2 handshake. An attacker within range of a victim can
exploit these weaknesses via overriding the keys and potentially extract/recreate encrypted information
that the device and AP is wirelessly transmitting with each other.

quote:

Is this issue severe?
On the Wi-Fi infrastructure, while duplicating the attack is hard and it happens mostly when BSS fast
transition (or 802.11r) is enabled on the Wi-Fi infrastructure the issue when possibility exists is severe.
Also, it is important to note that 11r is mostly disabled by default in most Wi-Fi gear. For the client side,
firmware must be upgraded to mitigate when available.

Still no patch or statement from their hardware division

https://forums.ruckuswireless.com/ruckuswireless/topics/severe-flaw-in-wpa2-cracked

AggressivelyStupid
Jan 9, 2012

speaking of Tavis,

https://twitter.com/taviso/status/920052238554251264

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:thurman:

maskenfreiheit
Dec 30, 2004

cinci zoo sniper posted:

mainly b/c they are not shy to pay senior 50k (before any deductions), where the locals will try to ratfuck you in the poverty faster than american healthcare

50k is like, good, in latvia? Like what is your rent like?

Notorious b.s.d.
Jan 25, 2003

by Reene

maskenfreiheit posted:

50k is like, good, in latvia? Like what is your rent like?

median income in latvia is like $400 a month dude

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Notorious b.s.d. posted:

median income in latvia is like $400 a month dude

latvian dollars or, like, real dollars

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

infernal machines posted:

latvian dollars or, like, real dollars

latvia dollars is euros

Luigi Thirty
Apr 30, 2006

Emergency confection port.

fishmech posted:

latvia dollars is euros

infernal machines posted:

latvian dollars or, like, real dollars

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shaggar posted:

excuse me but you are attacking the democrat brand which means you are a republican so i don't have to listen to you.

No I am a Russian bot

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


eset has a really good network to monitoring and auto-blocking connections to known malicious hosts I bet that's what they're bundling with chrome which is Good

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

https://twitter.com/tqbf/status/920009085608714240

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

BangersInMyKnickers posted:

eset has a really good network to monitoring and auto-blocking connections to known malicious hosts I bet that's what they're bundling with chrome which is Good
can't say i'm thrilled at the idea of the world's largest advertising company periodically scanning my computer, even if they have good intentions

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

dehumanize yourself and face to sandboxing

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




maskenfreiheit posted:

50k is like, good, in latvia? Like what is your rent like?

50k is beyond fantastic, basically the limit for non-managers. my rent right now is 250/mo for a 2br in decent area

  • Locked thread