KRACK in Wi-Fi security: Everything you need to know – CNET

Now Playing: Watch this: Wi-Fi has a big security flaw – and you need to act now

James Martin/CNET

Wi-Fi is everywhere, and you’re on it all the time. Get your guard up.

A newly revealed Wi-Fi weak spot puts just about every device at risk, from your work computer to the phone in your hand and the laptop you tote to the coffee shop.

What’s especially frustrating is that a potential attack, called KRACK, would slip in through a vulnerability in a fundamental security protocol.

Here’s a rundown on all the key information.

What happened?

A researcher in Belgium named Mathy Vanhoef stumbled across a problem in the code behind WPA2, a protocol that makes wireless connections work in practically every device. The flaw means that all devices are vulnerable to hackers who want to pick up on all the internet traffic flowing in and out of laptops, phones, smart home devices and anything else with a Wi-Fi connection.

Why the name KRACK?

It’s short for “Key Reinstallation Attack.” It refers to the trick Vanhoef found could be used to open up your internet traffic to hackers, which forces a device to repeat sensitive information to establish an internet connection. 

Is it as bad as it sounds?

The good news is that a hacker has to be nearby to carry out an attack that takes advantage of this problem. The bad news is that a hacker could carry out the attack on virtually anything nearby with a Wi-Fi connection. Your devices are likely vulnerable.

What’s the best way to protect myself?

The most important thing you can do is update your devices as patches become available. Second, you’ll want to consider patching your router firmware if the manufacturer doesn’t update it for you automatically. Finally, you can change your passwords as an extra protective measure — this is the least important step, even though your instinct might be to change your passwords right away. But changing your password won’t block out hackers.

Can other people’s unpatched devices make me unsafe?

Even if you patch your Android phone and your home router, you could be vulnerable if you connect your phone to another unpatched router. On the plus side, Vanhoef found that routers are harder to attack than phones and other devices. For the time being, the safest thing to do is to avoid using Wi-Fi on your phone if at all possible.

Does turning off phone Wi-Fi protect you, or are the cellular networks vulnerable?

Cellular networks are not affected by KRACK. Still, if you want to really turn off Wi-Fi, have at it. On Android devices, that’s pretty straightforward. In an iPhone or iPad that runs iOS 11, you’ll have to go to Settings to do so. Turning off Wi-Fi from the control center (that little panel of buttons that appears when you swipe up from the bottom of your screen) doesn’t turn iti all the way off.

Is HTTPS at risk?

Many websites — the ones that start with HTTPS — put an extra layer of encryption on your internet traffic to keep it scrambled up as it travels to its destination. The KRACK attack doesn’t break this encryption, so it could help secure your data. However, Vanhoef said, HTTPS alone might not be enough to protect your data if a hacker uses KRACK to read your internet traffic, considering the number of times hackers have found ways to break the encryption.

When will companies starting patching?

Windows customers are already protected if they installed software updates released last Tuesday. Google has said it’s aware of the problem and will be releasing any patches necessary in the coming weeks. Amazon is also looking into what patches are needed. CNET has reached out to several other device manufacturers and will update this list as more information becomes available.

Do attackers need to have physical/local access to your network, or can they do so remotely?

Hackers must be near your device to use this attack. This significantly cuts back on the breadth of attack a single hacker can carry out at once. However, the weakness is currently so pervasive that Vanhoef said everyone should assume all their devices are affected and vulnerable.

Security:  Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

CNET Magazine: Check out a sample of the stories in CNET’s newsstand edition.

Leave a Reply

Your email address will not be published. Required fields are marked *