. 24/7 Space News .
INTERNET SPACE
Security flaw prompts fears on Wi-Fi connections
By Rob Lever
Washington (AFP) Oct 16, 2017


A newly discovered flaw in the widely used Wi-Fi encryption protocol could leave millions of users vulnerable to attacks, prompting warnings Monday from the US government and security researchers worldwide.

The US government's Computer Emergency Response Team (CERT) issued a security bulletin saying the flaw can open the door to hackers seeking to eavesdrop on or hijack devices using wireless networks.

"Exploitation of these vulnerabilities could allow an attacker to take control of an affected system," said CERT, which is part of the US Department of Homeland Security.

The agency's warning came on the heels of research by computer scientists at the Belgian university KU Leuven, who dubbed the flaw KRACK, for Key Reinstallation Attack.

According to the news site Ars Technica, the discovery was a closely guarded secret for weeks to allow Wi-Fi systems to develop security patches.

Attackers can exploit the flaw in WPA2 -- the name for the encryption protocol -- "to read information that was previously assumed to be safely encrypted," said a blog post by KU Leuven researcher Mathy Vanhoef.

"This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. The attack works against all modern protected Wi-Fi networks."

The researcher said the flaw may also allow an attacker "to inject ransomware or other malware into websites."

The KRACK vulnerability allows attackers to circumvent the "key" on a Wi-Fi connection that keeps data private.

The Belgian researchers said in a paper that devices on all operating systems may be vulnerable to KRACK, including 41 percent of Android devices.

- 'Be afraid' -

The newly discovered flaw was serious because of the ubiquity of Wi-Fi and the difficulty in patching millions of wireless systems, according to researchers.

"Wow. Everyone needs to be afraid," said Rob Graham of Errata Security in a blog post.

"It means in practice, attackers can decrypt a lot of Wi-Fi traffic, with varying levels of difficulty depending on your precise network setup."

Alex Hudson, of the British-based digital service firm Iron Group, said the discovery means that "security built into Wi-Fi is likely ineffective, and we should not assume it provides any security."

Hudson said Wi-Fi users who browse the internet should still be safe due to encryption on most websites but that the flaw could affect a number of internet-connected devices.

"Almost certainly there are other problems that will come up, especially privacy issues with cheaper Internet-enabled devices that have poor security," Hudson said in a blog post.

Researchers at Finland-based security firm F-Secure said in a statement the discovery highlights longstanding concerns about Wi-Fi systems' vulnerability.

"The worst part of it is that it's an issue with Wi-Fi protocols, which means it affects practically every single person in the world that uses Wi-Fi networks," F-Secure said in a statement.

The F-Secure researchers said wireless network users can minimize the risks by using virtual private networks, and by updating devices including routers.

The Wi-Fi Alliance, an industry group which sets standards for wireless connections, said computer users should not panic.

"There is no evidence that the vulnerability has been exploited maliciously, and Wi-Fi Alliance has taken immediate steps to ensure users can continue to count on Wi-Fi to deliver strong security protections," the group said in a statement.

"Wi-Fi Alliance now requires testing for this vulnerability within our global certification lab network and has provided a vulnerability detection tool for use by any Wi-Fi Alliance member."

Microsoft said it released a patch on October 10 to protect users of Windows devices.

"Customers who have Windows Update enabled and applied the security updates, are protected automatically," Microsoft said.

A Google spokesman said, "We're aware of the issue, and we will be patching any affected devices in the coming weeks."

INTERNET SPACE
Facebook beefs up food delivery options from its app
Washington (AFP) Oct 13, 2017
Facebook on Friday announced a new feature to make it easier for users to order meals from nearby restaurants and service providers without leaving the social network. A new "order food" feature rolled out for US users lets Facebook users order delivery or takeout from restaurant chains such as Papa John's and Panera, and on-demand services including Delivery.com and DoorDash. "People al ... read more

Related Links
Satellite-based Internet technologies


Thanks for being there;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Monthly Supporter
$5+ Billed Monthly


paypal only
SpaceDaily Contributor
$5 Billed Once


credit card or paypal


Comment using your Disqus, Facebook, Google or Twitter login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

INTERNET SPACE
Roscosmos: International Space Exploration to Continue Despite Geopolitical Situation

US spacewalkers install 'new eyes' at space station

NASA May Extend BEAM's Time on the International Space Station

USNO Astronomers Measure New Distances To Nearby Stars

INTERNET SPACE
Russia May Adjust Space Program to Construct Super-Heavy Carrier Rocket

DARPA Awards Aerojet Rocketdyne Contract to Develop Hypersonic Advanced Full Range Engine

SpaceX launches, lands recycled rocket

Angola's First Satellite to Be Launched From Baikonur Spaceport Dec. 7

INTERNET SPACE
Russian Space Research Institute Announces July 2020 Date for Mission to Mars

ASU examines Mars' moon Phobos in a different light

Mars Study Yields Clues to Possible Cradle of Life

Another Chance to Put Your Name on Mars

INTERNET SPACE
China launches three satellites

Mars probe to carry 13 types of payload on 2020 mission

UN official commends China's role in space cooperation

China's cargo spacecraft separates from Tiangong-2 space lab

INTERNET SPACE
Turkey, Russia to Enhance Cooperation in the Field of Space Technologies

SpaceX launches 10 satellites for Iridium mobile network

Lockheed Martin Completes First Flexible Solar Array for LM 2100 Satellite

GomSpace and Luxembourg to develop space activities in the Grand Duchy

INTERNET SPACE
Understanding rare earth emulsions

Missing link between new topological phases of matter discovered

Space radiation won't stop NASA's human exploration

Saab upgrading Norwegian radars under NATO contract

INTERNET SPACE
Are Self-Replicating Starships Practical

New telescope attachment allows ground-based observations of new worlds

Biomarker Found In Space Complicates Search For Life On Exoplanets

The Super-Earth that Came Home for Dinner

INTERNET SPACE
Ring around a dwarf planet detected

Helicopter test for Jupiter icy moons radar

Solving the Mystery of Pluto's Giant Blades of Ice

Global Aerospace Corporation to present Pluto lander concept to NASA









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.