create account

Detection of a Serious Security Vulnerability by ghasemkiani

View this thread on: hive.blogpeakd.comecency.com
· @ghasemkiani ·
$4.98
Detection of a Serious Security Vulnerability
<center>
![Wireless networks](http://www.aljazeera.net/File/GetImageCustom/afddd988-ef76-4c8a-b08e-673a3931a961/747/441)
_The vulnerability is in the WPA2 protocol used to protect home and institutional wireless networks._
</center>

------------------


Researchers have discovered a serious loophole in the wpa2 protocol, a common security protocol used to protect home and enterprise wireless networks, allowing hackers to intercept traffic between computers and wireless network points.

The researchers called the gap "KRACK," an acronym for "Key Reinstallation Attack," and more details of the breach are expected to be released today at the krackattacks.com website before it will be officially released on November 1, in a security conference in Dallas.

Because of the gravity of the breach, it has become secret and fraught with security weeks ago for fear that the details leaked to cyber criminals and hackers before finding a suitable solution to security vulnerabilities.

According to a researcher who has been briefed on the vulnerability, it is working by exploiting the so-called four-way handshake system used to create keys to encrypt traffic. In one step the key can be sent several times, and when sent in certain ways, encryption can be used in a way that completely undermines it.

The United States Computer Emergency Readiness Team issued a warning saying that the impact of exploiting these vulnerabilities includes decoding, hijacking TCP connections, injecting content in HTTP, and repeated data transfer attacks or delayed for malicious purposes, and all applications of this protocol will be affected by the vulnerability.

Ars Technica, one of the researchers, said Aruba and Ubiquitoy, which sell wireless access points to large companies and government organizations, already have updates available to patch or reduce the vulnerability.

According to the site, it is unlikely to correct the vast majority of access points quickly, and perhaps some may not be corrected at all.

[Source](http://www.aljazeera.net/news/scienceandtechnology/2017/10/16/%D8%A7%D9%83%D8%AA%D8%B4%D8%A7%D9%81-%D8%AB%D8%BA%D8%B1%D8%A9-%D8%AE%D8%B7%D9%8A%D8%B1%D8%A9-%D8%A8%D8%A3%D9%85%D9%86-%D8%A7%D9%84%D8%B4%D8%A8%D9%83%D8%A7%D8%AA-%D8%A7%D9%84%D9%84%D8%A7%D8%B3%D9%84%D9%83%D9%8A%D8%A9)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorghasemkiani
permlinkdetection-of-a-serious-security-vulnerability
categorysecurity
json_metadata{"tags":["security","software","network","protocol"],"app":"juya/app","format":"markdown","percent_steem_dollars":10000}
created2017-10-17 12:35:09
last_update2017-10-17 12:35:09
depth0
children4
last_payout2017-10-24 12:35:09
cashout_time1969-12-31 23:59:59
total_payout_value4.845 HBD
curator_payout_value0.137 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,299
author_reputation90,438,911,242,538
root_title"Detection of a Serious Security Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id17,899,791
net_rshares2,206,821,742,364
author_curate_reward""
vote details (36)
@bellyrub ·
<p>This wonderful post has received a bellyrub 8.59 % upvote from @bellyrub thanks to this cool cat: @ghasemkiani.
My pops @zeartul is one of your top steemit witness, if you like my bellyrubs please go vote for him, if you love what he is doing vote for this comment as well.</p>
properties (22)
authorbellyrub
permlinkre-ghasemkiani-detection-of-a-serious-security-vulnerability-20171017t124421647z
categorysecurity
json_metadata{"tags":["security"],"app":"drotto/0.0.2"}
created2017-10-17 12:44:36
last_update2017-10-17 12:44:36
depth1
children0
last_payout2017-10-24 12:44:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length281
author_reputation7,904,765,975,109
root_title"Detection of a Serious Security Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id17,900,306
net_rshares0
@chan16735 ·
nice bro
properties (22)
authorchan16735
permlinkre-ghasemkiani-detection-of-a-serious-security-vulnerability-20171017t125805708z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-10-17 12:58:18
last_update2017-10-17 12:58:18
depth1
children0
last_payout2017-10-24 12:58:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length8
author_reputation306,179,440,245
root_title"Detection of a Serious Security Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id17,901,063
net_rshares0
@completelyanon ·
$0.37
Such a great post, thank you for sharing with us.
👍  
properties (23)
authorcompletelyanon
permlinkcompletelyanon-re-ghasemkianidetection-of-a-serious-security-vulnerability
categorysecurity
json_metadata""
created2017-10-17 13:05:18
last_update2017-10-17 13:05:18
depth1
children0
last_payout2017-10-24 13:05:18
cashout_time1969-12-31 23:59:59
total_payout_value0.371 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length49
author_reputation3,200,893,877,084
root_title"Detection of a Serious Security Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id17,901,410
net_rshares165,572,785,741
author_curate_reward""
vote details (1)
@the-tech-guy ·
$0.05
This might be the biggest issue since Heartbleed! If you guys are interested check out the [article by arstechnica.com](https://arstechnica.com/information-technology/2017/10/severe-flaw-in-wpa2-protocol-leaves-wi-fi-traffic-open-to-eavesdropping/), there's a lot more detail, AND it's in English.
👍  
properties (23)
authorthe-tech-guy
permlinkre-ghasemkiani-detection-of-a-serious-security-vulnerability-20171017t181342902z
categorysecurity
json_metadata{"tags":["security"],"links":["https://arstechnica.com/information-technology/2017/10/severe-flaw-in-wpa2-protocol-leaves-wi-fi-traffic-open-to-eavesdropping/"],"app":"steemit/0.1"}
created2017-10-17 18:13:45
last_update2017-10-17 18:13:45
depth1
children0
last_payout2017-10-24 18:13:45
cashout_time1969-12-31 23:59:59
total_payout_value0.051 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length297
author_reputation591,393,926,026
root_title"Detection of a Serious Security Vulnerability"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id17,912,116
net_rshares22,730,662,999
author_curate_reward""
vote details (1)