11 ms·
As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor
by sequence7 9y ago
As an Android user is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor.
This really does highlight the absolute disaster zone that the Android handset market has become as far as updates are concerned. I'm sure the Pixels will get a fix relatively quickly but almost every other Android user is going to be left in security limbo.
- janvdberg 9y agoUse an always-on VPN?
- Ambroos 9y agoThis is one of those things that should be better with modern handsets and the security patch level for Android. Hopefully a fix for this is included in the November set. In general most bigger manufacturers have been somewhat decent in updating their flagship devices. With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates. Samsung is similar if I remember correctly. Hopefully a big exploit like this will be enough of a kick in the butt to get manufacturers releasing security updates faster.
- sequence7 9y agoI have a HTC 10, a flagship device that's barely a year old the fact that I now have to wait a couple a months for a patch to what is clearly a critical vulnerability is just ridiculous. The fact that anyone without a flagship device should now throw that phone away because it will probably never be patched is despicable. I totally agree with your hope that this will kick both the manufacturers and Google in the butt enough to get something done about this. I don't like our chances though!
- Perseids 9y agoTo underline your point, even my Nexus 5 (_from Google_), which is a little less than 3 years old, will never receive security updates. And one of the main reasons I chose the Nexus was to be sure to get updates on time. Except for the security vulnerabilities, everything of the device is totally fine. It's such a waste of resources… (In this case I at least have an alternative in the form of Lineage OS, which will only cost me time and nerves for the migration.)
- Fnoord 9y agoYou'd expect better from the horse's mouth, but most other companies are worse. I got a Fairphone 2 and my partner a Wileyfox Swift 2X. Both have very good software support thus far. Near monthly updates. Wileyfox phone is a bit new, but they got a good track record. Nokia (HMD) also seems to be back, this time with good software support (thus far). Compare that to Motorola. Hopefully Android Orea 8 with Project Treble will stop this ridiculous trend for the rest of us. Together with the smartphone market being saturated (budget phones of 200 EUR are very decent these days), we may end up with long term support on older yet still decent devices.
- endorphone 9y agoThe Nexus 5 was released 4 years ago. At the same time the iPhone 5C was released. The 5C also won't receive a patch for this. There is a problem with handset abandonment, but this is true across all vendors, and it does not underline sequence7's claim that this is solely an Android problem.
- macawfish 9y agoA lot of phone companies are locking their devices from receiving new kernels. Its dumb and I hate it.
- pfg 9y agoTo be fair, these two examples are both on the extreme end: The Nexus 5 being one of the longest supported Android phones on the market, and the 5C having a rather short support period, compared to other iPhones like the 5S, which was released along with the 5C and got iOS 11. Security updates for the Nexus 5 also stopped shipping about a year earlier. There's still room for improvement for Apple (5 years of security updates seems reasonable), but there's still a large gap.
- DougWebb 9y agoThe problem is that these aren't phones anymore; they're small computers. They should have support lifetimes that are comparable to desktop computers.
- kevin_thibedeau 9y agoLineageOS has got your back: https://download.lineageos.org/pme https://download.lineageos.org/pme
- ajr0 9y agothis is why I am rooting for initiatives like PostmarketOS [0] and similar initiatives in the hopes ot break this mentality that every year we need to buy new hardware in order to stay secure. [0] https://www.postmarketos.org/ https://www.postmarketos.org/
- deleted 9y ago[deleted]
- tripzilch 9y agoFortunately the term "flagship" doesn't promise anything about support, patches or security. It's just a word that means you paid more for having all the bells and whistles that the OEM could offer at the time, instead of going for the next-best model or such. Fortunately, whether you can afford the best of the best with all the optional extras or a cheaper second-tier model doesn't affect the security of the device. And it shouldn't, because if you can't afford a "flagship" device, doesn't mean you can afford to get hacked either. Unfortunately, while the security-update frequency ought to be comparable, it turns out that it's mainly comparably bad :-/
- pnutjam 9y agoAny https traffic is going to be safe from this attack, a VPN would also protect you.
- mceachen 9y agoFrom TFA: Although websites or apps may use HTTPS as an additional layer of protection, we warn that this extra protection can (still) be bypassed in a worrying number of situations. For example, HTTPS was previously bypassed in non-browser software, in Apple's iOS and OS X, in Android apps, in Android apps again, in banking apps, and even in VPN apps.
- willstrafach 9y agoThis only applies to apps which screw up validation of TLS certificates. There is an unfortunate amount of them, but certainly does not apply to all apps (and not an issue for websites). Either way, this disclosed vulnerability only involves link layer man-in-the-middle in order to collect traffic. Active manipulation of traffic (Required for TLS intercept) is more complicated.
- sp332 9y agoAccording to https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it https://char.gd/blog/2017/wifi-has-been-broken-heres-the-com... it will be in the November 6 Android patch level.
- giobox 9y ago"With a Sony flagship from the last 18 months for example, you usually won't run more than two months behind on security updates." That's still truly terrible compared to Apple's legacy device support. iOS 11 and future patches still support even the iPhone 5s, a phone from 2013.
- alex_duf 9y agoI know it's not ideal nor user friendly, but you can get a device that is supported by lineage os. You get updates every week.
- krrrh 9y agoSince this is fixed by a patch to wpa_supplicant LineageOS does fix it, but it is pointed out elsewhere in this thread that Lineage is still vulnerable to older hacks like broadpwn on many devices since they have a hard time patching kernel-level vulnerabilities without vendor participation. Your advice is valid, but it’s important to not have a false sense of security.
- alex_duf 9y agoI wasn't aware of that, thanks
- Tepix 9y agoPray for a vendor patch. The fix landed today in the hostap repository: https://w1.fi/cgit/hostap/commit/?id=a00e946c1c9a1f9cc65c72900d2a444ceb1f872e https://w1.fi/cgit/hostap/commit/?id=a00e946c1c9a1f9cc65c729...
- rightos 9y agoDoes this resolve the issue on the AP side of things? Could I theoretically have an AP update that would resolve this with no need to update clients?
- tesseract 9y agoUnfortunately no, from what I understand this is primarily an attack against clients.
- rightos 9y agoAh yes, I see now that the patch is actually to wpa_supplicant. Well, hopefully this means no kernel patch will be needed.
- pritambaral 9y agoBoth APs and clients need to be patched[0]. Mitigations are possible on AP side if no updates are available[1]. [0]: "Finally, although an unpatched client can still connect to a patched AP, and vice versa, both the client and AP must be patched to defend against all attacks!" [1]: "you can try to mitigate attacks against routers and access points by disabling client functionality (which is for example used in repeater modes) and disabling 802.11r (fast roaming)."
- 1ba9115454 9y agoCurrently the only mitigation is to constrain your browsing to properly configured https (SSL) web sites.
- w458cmau 9y agoOr using a VPN.
- hunter2_ 9y agoIt was quite nice to let a wifi router be the VPN client to offload it from all your laptops/phones/etc. and better guarantee "VPN always on".. so much for that.
- deleted 9y ago[deleted]
- filomeno 9y agoYou can (try) to restrict your browsing to HTTPS sites only. But it's very difficult to ensure that all the communications your device is making (background services, vendor apps...) go through that channel.
- haggy 9y agoThis issue is two-fold right. You can install plugins that force SSL client side (on the main site and any AJAX calls thereafter) but like you said you have no idea what calls that site is making server side. They could be sending everything you send them over plaintext after the initial TLS secured request. Rough times.
- Gaelan 9y agoLuckily, the servers past the initial SSL link won’t be using wifi, so at least you won’t be any worse off than before.
- 9y ago
- bjpbakker 9y agoAs others suggested ensure that all communication uses TLS (be it https et al or tunnel traffic through a VPN). Also you could install a better version of Android on your phone rather than an outdated vendor version. That will probably fix more security related issues than just this one :)
- jannes 9y agoHow would you make sure that apps use TLS for comunication? In the browser it's easy to see, but in apps those details are hidden away from the user.
- utilisateur 9y agoVendor version contains blobs (binary objects) for drivers which are most often than not a problem to deal with for OSS and cause various bugs. It's usually workable depending on vendor and hardware but not exactly a perfect solution either.
- endorphone 9y agoor waiting (hopelessly) for a patch from my vendor If this is an actual in the wild exploitable issue, there will be patches very quickly for handsets in the support period, as quickly as there is for iOS. This has been the case repeatedly before as well. What a weird post in general. Maybe wait to complain about this a month down the line or so? Instead it's just effectively noisy rhetoric.
- sequence7 9y agoThe support period for an iPhone is at least 3 years of regular patches and feature updates. Most Android phones on the market will have a 'support period' of 12 months if you're lucky. My point is that the roll-out of updates to Android is unacceptably poor and inconsistent and relies on optimism on the part of the user. The use of the word hopelessly was probably unnecessarily dramatic I agree but I'll leave it there so your comment makes sense.
- Piskvorrr 9y agoThere's a patch for iOS? Wonderful! Oh wait, there isn't.
- endorphone 9y agoDid you intend to post that reply to me? Because of course there isn't a patch for iOS yet, and when there is it will leave out hundreds of millions of devices that no longer receive patches. My point was that if one wants to stomp their feet and do the easy "Damn Android" complaint, at least wait until the basis is sound.
- Piskvorrr 9y agoAh, you're right, sorry: that was intended one reply up, where the poster seems to claim that iOS is already patched.
- hollander 9y agoDitch wifi, go 4G only!
- whyever 9y agoI'm not convinced 4G is more secure.
- Piskvorrr 9y agoIt does have higher barriers to entry, and penalties for broadcasting unlicensed. Granted, that's both more of an obfuscation than anything else.
- nradov 9y agoThere are many places indoors where I can get a WiFi signal but no cellular service.
- pritambaral 9y agoRegarding mobile data in the US: https://news.ycombinator.com/item?id=15477286 https://news.ycombinator.com/item?id=15477286
- SmellyGeekBoy 9y agoI appreciate this is coming from a UK perspective and that not everyone is this lucky, but I don't remember the last time I used public WiFi on my phone thanks to a general mistrust of it and the fact that 4G (or at least HSPA+) has very good coverage here.
- GunlogAlm 9y agoSame here (Devon, UK) — although I do use the WiFi we have on buses here, and occasionally when in cafés.
- jrg 9y agoThis is about WiFi "protected" with WPA2: basically treat it as suspiciously as you would any public WiFi. If you choose not to use public WiFi because you can't "trust" it, then you now need to stop using your private WiFi too (until your systems get appropriate patches).
- beingmyself2 9y agoDon't forget the fact that carriers are now snooping your 4G data and selling it to advertisers. It has been a bad week for privacy.
- drzaiusapelord 9y agoUbiquity just released a patch for KRACK and soon others will I imagine. From a client perspective, same as always, wait for a patch from your OS vendor. edit: it seems this patch only handles modes where the AP is a client like a bridge or site-to-site. Its still a client-side fix and patching AP's used traditionally won't fix this. In practice, everything of value should be going over TLS. If you're worried you should be using a VPN on untrusted networks. This attack, if I'm reading it right, doesn't do anything someone on your wlan or lan can't do right now via ARP poisoning and other attacks. So being on that work connection or restaurant wifi is almost the same risk level of this attack.
- hunter2_ 9y agoThe thing is, not every protocol offers TLS. Take SMB (network shares) for example... encryption is only offered as of v3 and if a company/university wants to allow Windows 7 clients, they're capped to SMB v2.1.
- drzaiusapelord 9y agoThat's a good example. I guess there's other mitigation at work here. In my case if I'm in a public wifi area and connecting to my work PC then I'm using VPN to access smb. Smb just isn't open to the wifi attacker. In a case that it is, its curious how you would inject data into a smb stream and not fail checksums from client-side chechking. Maybe its trivial to deal with this, not sure. If the WPA2 protected wifi network is using AES, which is the most common in my experience, then they won't be able to inject any data. From the Krack website: If the victim uses either the WPA-TKIP or GCMP encryption protocol, instead of AES-CCMP, the impact is especially catastrophic. Against these encryption protocols, nonce reuse enables an adversary to not only decrypt, but also to forge and inject packets.
- hunter2_ 9y agoTrue, but what I'm getting at is watching (not injecting/modifying) the username and password fly across the campus airwaves.
- millettjon 9y agoI orded a librem5 for this among other reasons. https://puri.sm/shop/librem-5/ https://puri.sm/shop/librem-5/
- spsful 9y agoYou should be good if you’re up to date as of November 6th (I think, it may be November 8th) Swiftonsecurity tweeted this out, it’s a description of KRACK and various devices affected by it. Apparently google already fixed it on android? Also it says that iOS is rumored to be protected against this since iOS 11 but it’s not confirmed. Nobody has put out an official statement yet. What’s weird is that commercial vendors like Ubiquiti UniFi (I use them myself) have already released fixes for their APs but the paper says that clients should be the priority and get fixed from KRACK ASAP. And it’s weird because I don’t know of any client-side fix released in the wake of KRACK being public. https://char.gd/blog/2017/wifi-has-been-broken-heres-the-companies-that-have-already-fixed-it https://char.gd/blog/2017/wifi-has-been-broken-heres-the-com...
- rconti 9y agoOctober 6th/8th, you mean? I found it interesting that, in his article, he said: "With our novel attack technique, it is now trivial to exploit implementations that only accept encrypted retransmissions of message 3 of the 4-way handshake. In particular this means that attacking macOS and OpenBSD is significantly easier than discussed in the paper" but elsewhere it said recent versions of OS X and iOS are not impacted. I wonder if the "safe" OSes are only vulnerable to the blocking/replay but not the decryption of data? My UniFi AP-PROs show up today so I'll make sure to update them first thing. Also, I'm having a bit of a hard time understanding the attack. It sounds like he forces them to connect to his AP, performs the attack, then allows them to connect to the intended network with the zeroed key, THEN is able to sniff that client's traffic because he knows their key? If I understand correctly, this means he cannot sniff the whole network's traffic, only the traffic between the attacked client and the AP? This makes me wonder about the meaning of a pre-shared key, but I'm guessing the PSK is only used to setup the relationship between client and AP, and then after the initial connection/pairing the pre-shared key is no longer used...
- deanishe 9y agoThis blog post explains it a bit: https://blog.cryptographyengineering.com/2017/10/16/falling-through-the-kracks/ https://blog.cryptographyengineering.com/2017/10/16/falling-...
- Veratyr 9y agoInstall one of the major ROMs like AOSP or LineageOS. Relying on your vendor for software or purchasing a device that forces you to isn't the best idea these days.
- scott_karana 9y ago> Relying on your vendor for software or purchasing a device that forces you to isn't the best idea these days. Relying on the efforts of unpaid volunteers doing their best to hack together binary blobs is also not the best idea... Not all devices are supported by major ROM distributors, nor is the support guaranteed to be endless or current... (even some devices as major as the Galaxy S6 for example)
- Veratyr 9y agoOnly so much depends on those binary blobs though and changes to, for example, wpa_supplicant, happen at a much higher level.
- scott_karana 9y agoAgreed, but unfortunately if the difficulty of maintaining/backporting/forward-porting binary blobs means that nobody will release ROMs for your device (anymore), your point is pretty much irrelevant. ;-)
- efreak 9y agoThis is true, however it doesn't make the point irrelevant. 1. Beyond difficulty of porting blobs, you might well also simply get your updates from a custom ROM faster than you'll get them from the manufacturer, even if it's still supported. That in itself is an advantage. 2. Backporting updates to third party components can be simple (assuming a stable ABI/API); the easiest case is probably that of just dropping binaries from a similar phone that did get updated into a zip file and then flashing it. Look at busybox installers, for example; all you need is a version compiled for your hardware. Java components can sometimes be changed as well (see xposed). This works on desktop systems as well, sometimes: I've been able to 'fix' older games into working just by dropping a newer version of a dll into the game directory (directx, openal, etc)) 3. Maybe the company is just stupid. Motorola (or is it Verizon?) has tried Marshmallow for the Moto E2 in Europe, but not in the US. I'd expand on this but I'm on mobile and I'm lazy.
- pkulak 9y agoAlways using a VPN should be a mitigation until a patch is released. Should only be a couple weeks out for Pixel devices.
- firewall-bad 9y ago"is there any mitigation for this other than ditching my handset and switching to an iPhone or waiting (hopelessly) for a patch from my vendor." Using a VPN is the best way to mitigate this until your device is patched, assuming you trust your VPN provider or run your own VPN. Edit: Actually, even if you don't trust your VPN provider, you'll be protected against this attack (KRACK), given their client is implemented properly.
- krrrh 9y ago> given their client is implemented properly. Unfortunately this is a big part of trusting your VPN provider. It’s shocking how bad the situation is, especially it seems on those marketed via Android apps. [1] [1] https://arstechnica.com/information-technology/2017/01/majority-of-android-vpns-cant-be-trusted-to-make-users-more-secure/ https://arstechnica.com/information-technology/2017/01/major...
- firewall-bad 9y agoWell the VPN ecosystem has an enormous long tail - the paper you cite tested 283 (!) apps. It's unfortunate but somewhat expected that a significant number, especially the ones that haven't been around for long, would have issues. I'm sure, given the size of that list, that they tested some of the biggest players on the VPN space. I think it'd be good to know which apps were tested and didn't show any issues, especially in light of Krack and the Android bug on wpa_supplicant.
- foobaw 9y agoDisclaimer: Used to work for an OEM With critical bugs like these, it's certain Google will require recent devices that have enough affected users to be updated ASAP. Expect an update within in a few weeks.
- rphlx 9y agoThe problem is that "recent" seems to mean <3 years old, and often, <2 years old. But there are still millions of active Galaxy S3s, S4s, S5s, etc.