[Cryptography] [FORGED] Re: Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping

Peter Gutmann pgut001 at cs.auckland.ac.nz
Mon Oct 16 21:04:20 EDT 2017


Erwan Ounn <erwan.ounn.84 at gmail.com> writes:

>It’s indeed a critical vulnerability.

Is it?  While it's a cool attack, and yet another reason why RC4-equivalent
ciphers like GCM should be banned (we finally got rid of RC4, and now we're
busy reintroducing it under another name), it's actually kinda hard to
identify what real impact this will have on most users.  The publication of
equivalent vulns in WPS hasn't led to an orgy of compromises, for the typical
user it's just business^H^H^Hviruses as usual.

Not to mention that fact that it's a forever-day on most devices...

Peter.


More information about the cryptography mailing list