How the KRACK attack destroys nearly all Wi-Fi security

Found on Ars Technica on Monday, 16 October 2017
Browse Software

The research is built upon previous explorations of weaknesses in WPA2's component protocols, and some of the attacks mentioned in the paper were previously acknowledged to be theoretically possible. However, the authors have turned these vulnerabilities into proof-of-concept code, "and found that every Wi-Fi device is vulnerable to some variant of our attacks. Notably, our attack is exceptionally devastating against Android 6.0: it forces the client into using a predictable all-zero encryption key."

Sometimes it's just surprising how suddenly giant bugs are found in wide-spread protocols that have been in use for years. It's almost like nobody bothered to look at the details before.