Google Patches KRACK WiFi Flaw in Android November Security Update

'Some vendors take longer than others to update for critical vulnerabilities - case in point is Google's Android mobile operating system. On Nov. 6, Google released an Android update patching a vulnerability that IT vendors have known about for months. On Oct. 16, security researcher Mathy Vanhoef working at Belgian University KU Leuven publicly disclosed the KRACK WiFi vulnerability that impacted all WiFi devices that use WPA2 encryption, including every Android device ever built.' -- source: https://www.esecurityplanet.com/mobile-security/google-patches-krack-wifi-fl... Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 http://www.cms.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/

On Wed, 8 Nov 2017 14:46:32 +1300, Peter Reutemann wrote:
'On Nov. 6, Google released an Android update patching a vulnerability that IT vendors have known about for months.'
-- source: https://www.esecurityplanet.com/mobile-security/google-patches-krack-wifi-fl...
From <https://arstechnica.com/gadgets/2017/11/pixel-wont-get-krack-fix-until-december-but-is-that-really-a-big-deal/>: “...the KRACK vulnerability won't be patched on Google-branded devices until December. That's right, Pixel and Nexus owners will have to survive a whole extra month being vulnerable to KRACK. But this isn't as huge of a problem as you might imagine.” “KRACK is a big deal for some devices, but it's mainly those that use WPA2 as their primary form of security. A lot of times this is IoT stuff like video cameras or "dumber" devices like a printer. On Android, killing WPA2 security is no different from logging in to an open coffee shop Wi-Fi with 25 other random people. Android is used to this, and the OS and apps generally take the right precautions.” As has been said before, end-to-end security is the vital thing. If “insecure” wi-fi is a problem for your application, then you’re doing it wrong.
participants (2)
-
Lawrence D'Oliveiro
-
Peter Reutemann