Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 16 Oct 2017 21:24:39 -0500
From:      Karl Denninger <karl@denninger.net>
To:        freebsd-security@freebsd.org
Subject:   Re: WPA2 bugz - One Man's Quick & Dirty Response
Message-ID:  <fb8d2dcb-2748-18fa-a25d-d52f4ea4c378@denninger.net>
In-Reply-To: <27180.1508206466@segfault.tristatelogic.com>
References:  <27180.1508206466@segfault.tristatelogic.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
On 10/16/2017 21:14, Ronald F. Guilmette wrote:
> In message <20171016230525.GA94181@funkthat.com>, 
> John-Mark Gurney <jmg@funkthat.com> wrote:
>
>>> In light of the recent WPA2 disclosures, it has occured to me that
>>> as of today it may be a Bad Idea for me to be exporting all of this
>>> stuff, read/write, to all of 192.168.1.0/24.
>> Doesn't matter, if your network is compromized, only strong encryption
>> and authentication will save you..
> Hummm... I *think* that maybe I'm starting to understand now.  But maybe
> not.  I'm at a bit of a disadvantage, because like 99.999% of the
> population I'm still not entirely 100% clear on what can and can't
> be done with these new WPA2 exploits.
Please understand that if you can get an AP to hand you a zero'd key
(with an intentionally "weak" client) THEN THAT PERSON JUST BECAME ABLE
TO ATTACH TO YOUR NETWORK AS AN AUTHORIZED USER.

Your network is thus exactly as "secure" as one that has an open RJ45
jack sitting at the end of your driveway and connected to your switch. 
If someone who plugged into that could screw you blind well, that's
exactly the situation you're now in.

Incidentally, has anyone yet figured out if this vector works on a
network configured for machine certificates instead of a PSK?  I'm not
certain from what I've looked at yet, and that is bothering me a LOT for
what should be obvious reasons.

-- 
Karl Denninger
karl@denninger.net <mailto:karl@denninger.net>
/The Market Ticker/
/[S/MIME encrypted email preferred]/

[-- Attachment #2 --]
0	*H
010
	`He0	*H

00H^Ōc!5
H0
	*H
010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA0
170817164217Z
270815164217Z0{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0"0
	*H
0
h-5B>[;olӴ0~͎O9}9Ye*$g!ukvʶLzN`jL>MD'7U45CB+kY`bd~b*c3Ny-78ju]9HeuέsӬDؽmgwER?&UURj'}9nWD i`XcbGz\gG=u%\Oi13ߝ4
K44pYQr]Ie/r0+eEޝݖ0C15Mݚ@JSZ(zȏNTa(25DD5.l<g[[ZarQQ%Buȴ~~`IohRbʳڟu2MS8EdFUClCMaѳ!}ș+2k/bųE,n当ꖛ\(8WV8	d]b	yXw	܊:I39
00U]^§Q\ӎ0U#0T039N0b010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA	@Ui0U00U0
	*H
:P U!>vJnio-#ן]WyujǑR̀Q
nƇ!GѦFg\yLxgw=OPycehf[}ܷ['4ڝ\[p6\o.B&JF"ZC{;*o*mcCcLY߾`
t*S!񫶭(`]DHP5A~/NPp6=mhk밣'doA$86hm5ӚS@jެEgl
)0JG`%k35PaC?σ
׳HEt}!P㏏%*BxbQwaKG$6h¦Mve;[o-Iی&
I,Tcߎ#t wPA@l0P+KXBպT	zGv;NcI3&JĬUPNa?/%W6G۟N000k#Xd\=0
	*H
0{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0
170817212120Z
220816212120Z0W10	UUS10UFlorida10U
Cuda Systems LLC10Ukarl@denninger.net0"0
	*H
0
T[I-ΆϏdn;Å@שy.us~_ZG%<MYd\gvfnsa1'6Egyjs"C [{~_KPn+<*pv#Q+H/7[-vqDV^U>f%GX)H.|l`M(Cr>е͇6#odc"YljҦln8@5SA0&ۖ"OGj?UDWZ5	dDB7k-)9Izs-JAv
J6L$Ն1SmY.Lqw*SH;EF'DĦH]MOgQQ|Mٙג2Z9y@y]}6ٽeY9Y2xˆ$T=eCǺǵbn֛{j|@LLt1[Dk5:$=	`	M00<+00.0,+0 http://ocsp.cudasystems.net:88880	U00	`HB0U0U%0++03	`HB
&$OpenSSL Generated Client Certificate0U%՞V=؁;bzQ0U#0]^§Q\ӎϡ010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CAH^Ōc!5
H0U0karl@denninger.net0
	*H
۠A0-j%--$%g2#ޡ1^>{K+uGEv1ş7Af&b&O;.;A5*U)ND2bF|\=]<sˋL!wrw٧>YMÄ3\mWR hSv!_zvl? 3_ xU%\^#O*Gk̍YI_&Fꊛ@&1n”} ͬ:{hTP3B.;bU8:Z=^Gw8!k-@xE@i,+'Iᐚ:fhztX7/(hY` O.1}a`%RW^akǂpCAufgDixUTЩ/7}%=jnVZvcF<M=
2^GKH5魉
_O4ެByʈySkw=5@h.0z>
W1000{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0
	`HeE0	*H
	1	*H
0	*H
	1
171017022439Z0O	*H
	1B@<I.oY;wLZ[4h̫j{le&ỳ΄v3~*--ogrԲ0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+7100{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0*H
	10{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0
	*H
.xtR6kn/Y1!%O-%A<304Պ.8WG_Vl~=#7ĈB)S[+9w<F[(:Lӡ).WI+c.Ă$U̿1ɢ2D1ea	!Yik|
h.gLhiS@U|p1g6m᱀`tRT#@9Jj'DAAGJ{,feR5^0UC޾*TP4_:fK3nWK`yLmjn؁~Lf!j~[)?]s3Pm/`+vwK~کGv=:vo{Wh
R2”?Ls$H?Kn@~k]`8ͽ#Qct ELL~đ^0d:W}5L2OުG:W|:'KJet0

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?fb8d2dcb-2748-18fa-a25d-d52f4ea4c378>