PSA: Update your Wi-Fi Routers & Client OS

Discussion in 'Fred's House of Pancakes' started by Prodigyplace, Oct 16, 2017.

  1. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,797
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    Not yet. But stay tuned, the list is getting updated as they hear.

    Posted via the PriusChat mobile app.
     
    Mendel Leisk likes this.
  2. mmmodem

    mmmodem Senior Taste Tester

    Joined:
    Nov 17, 2011
    2,732
    1,703
    0
    Location:
    Bay Area, CA
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    Yawn. Much ado about nothing. Nearly everything private that comes out of my house goes out https. Besides, there's still a few WEP networks (older Comcast and AT&T equipment I suspect given the SSID) in my neighborhood, one is even open. What people need to know is there is no such thing as absolute security. WPA2 can be better hacked in a few hours.

    It's simpler to live your life and accept that WPA2 is the best consumer wireless security we have available similar to credit cards with a chip are the best. They are not full proof. There's no such thing. Even Bitcoins can be hacked and they are encryption!

    The chances of you being hacked are slim to none. Don't do obvious things like running Windows XP or do online banking at public wifi. Encrypt your home router with WPA2 and lock your Prius. Worrying about KRACK is like buying wheel locks for your stock Prius rims. No one wants them. They want the corporate business accounts with much more money on the line.
     
  3. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    All Wi-Fi routers and clients are affected. Some vendors releasted patches last qweek.
    I suspect iOS 11.0.3 fixed some devices. The update has a security component but Apple has not yet disclosed what was fixed.
    macOS High Sierra 10.13 Supplemental Update appear to be the patch for macOS.
     
    RCO and pilotgrrl like this.
  4. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    WPA-PSK & WPA2-TKIP-PSK are broken worse than WPA2-AES-PSK. I need to ask whether both TKIP & AES are fixed, or just AES.

    WPA2-TKIP was just meant to permit migration to the more secure WPA2-AES anyway.
     
  5. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    This vulnerability affects the WPA-Enterprise & WPA2-Enterprise too.
    WEP was the original, very broken attempt at wireless security. Any device running WEP should be able to run at least WPA ot WPA2-TKIP.

    WPA2-AES requires hardware encryption.
     
    mmmodem likes this.
  6. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    58,759
    40,461
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    You guys do realize that @bisco and me are just dumbstruck and poleaxed, by this acronym onslaught, lol.
     
  7. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    According to my wireless vendor, they fixed the key handshake both TKIP & AES.

    TKIP has other security weaknesses, though.
     
    RCO and pilotgrrl like this.
  8. ETC(SS)

    ETC(SS) The OTHER One Percenter.....

    Joined:
    Oct 28, 2010
    8,102
    6,908
    0
    Location:
    Redneck Riviera (Gulf South)
    Vehicle:
    Other Non-Hybrid
    Model:
    N/A
    Meh.....

    I used to be protected when I lived in the county because you had to park close enough to my house for me to see you in order for you to be close enough to listen in......inviting investigation.

    I live in a neighborhood now and don't even bother to mask my SSID because I have the best alarm systems known to mankind........elderly retired neighbors with ankle biters that will both quickly and aggressively investigate abnormal things.
    In counter-terrorism, they call this WIN-WIN.....or "what is normal.......what is not" and I never EVER presume that any activity conducted on the internet is private.
     
    RCO and mmmodem like this.
  9. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    Just update your router and all your wireless devices and you should be OK. Some manufacturers released updates last week without disclosing that they fixed this vulnerability.

    Some people like the tech pr0n here. My workday today has been consumed by this issue. @pilotgrrl is lucky she is not working today, IMHO.
     
    RCO and pilotgrrl like this.
  10. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    58,759
    40,461
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    Do you mean update the firmware? Last firmware release for mine was released May 01, 2013. I think I'll just put on my inverted-collander helmet and try to look fierce.

    Seriously, I guess it's wait-and-see for a few days, see if the manufacturers, or Microsoft, Apple, Google and whomever, come through with something.
     
    RCO, bisco and Prodigyplace like this.
  11. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    Yes, I mean your router firmware.
    It is a much larger issue for me with over 20,000 user devices depending on my network. Our client support team is working on a strategy to update the client devices too.
     
    pilotgrrl and Mendel Leisk like this.
  12. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    58,759
    40,461
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    Ah, erm, 20,000 eh. :oops::oops::oops::oops::oops:
     
  13. VFerdman

    VFerdman Senior Member

    Joined:
    Jul 5, 2017
    1,185
    1,212
    3
    Location:
    Western Massachusetts
    Vehicle:
    2007 Prius
    Model:
    Three
    Are there patches already? I thought it just got announced yesterday. There are many different clients and many different routers out there. How can I find the patches for my various clients and my router?
     
  14. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    on 3300 APs.
    Fortunately we will update them centrally, not individually.
     
    pilotgrrl likes this.
  15. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    Some wireless manufacturers have been working on this for the past 2 months.
    Our vendor released their patches last week.
    It appears that Microsoft & possibly Apple released theirs last week too.
     
  16. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,797
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    Microsoft has patches for all supported versions of Windows, according to the Verge.

    Posted via the PriusChat mobile app.
     
  17. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    I prefer hearing direct from the vendor. I have not seen any statement from Microsoft.
     
    RCO likes this.
  18. VFerdman

    VFerdman Senior Member

    Joined:
    Jul 5, 2017
    1,185
    1,212
    3
    Location:
    Western Massachusetts
    Vehicle:
    2007 Prius
    Model:
    Three
    So, my clients are Windows (7 and 10), Linux (Raspberry Pi running Raspbian) and Android (5 and 6). My router is an older Netgear WNDR4300v2. That's pretty diverse. I need patches from Microsoft, Google and Netgear (for an older piece of hardware). Let's see how this plays out.
     
    RCO likes this.
  19. Mark57

    Mark57 2021 Tesla Model 3 LR AWD

    Joined:
    Aug 14, 2009
    2,945
    2,738
    0
    Location:
    OK
    Vehicle:
    Other Electric Vehicle
    Model:
    N/A
    SSID masking only keeps the honest people out as anyone that's touched Linux knows. Those of us that were/are WarDrivers (I was once #5 World Wide for network discoveries) can tell you SSID masking is worthless. It "might" keep your neighbors off your network, but that's about it. Anyone can boot up a distro of Knoppix with built in tools (or Kali, or Blackbox) and go to town on any signal they can see. I've never done it outside our own network for PEN testing, but it's not hard.

    Based on what we've discovered and mapped since 2005 about 60% worldwide use WPA2 and a few more % use the older WPA and WEP.

    All, if a patch is available from your manufacturer, patch your equipment. Don't be "that guy."
     
    pilotgrrl likes this.
  20. Prodigyplace

    Prodigyplace 2025 Camry XLE FWD

    Joined:
    Nov 1, 2016
    12,394
    11,676
    0
    Location:
    Central Virginia
    Vehicle:
    Other Hybrid
    Model:
    XLE
    If you are using WPA2 with AES (not TKIP) you are pretty well protected generally. Some enterprises using 802.11r to improve roaming may have more issues.
     
    RCO likes this.