Security Alert – KRACK Wi-Fi Vulnerability

November 15, 2017

by UNH Information Security Services

Affected Software and Version(s)

  • Windows Devices (Laptops, Desktops, Tablets)
  • Apple iOS Devices (iPhones, iPads, iPods)
  • Apple MacOS Devices (iMacs, MacBooks)
  • Phones, Tables and Chromebook’s running Android 6.0
  • Home and office Wi-Fi Routers
  • Smart-home Appliances and Devices (Google Home, Amazon Echo, Wireless Cameras, Smart TVs, IOT devices)

Vulnerability Summary

KRACK is an acronym that stands for a hacking technique called Key Reinstallation AttaCK, which can expose information shared on Wi-Fi networks. The vulnerability even affects networks that are secured with data encryption and passwords. Most Wi-Fi networks today use WPA 2 encryption, which is designed to keep all communications private so that if an attacker listens in, all they see is jumbled-up unintelligible information.

KRACK thwarts the protections provided in WPA 2 so that all information, including passwords, credit card numbers, and other PII is visible to attackers.

Recommended Remediation Steps

Please use the below information to download and install any applicable updates. Until you can install the updates, or until one becomes available, consider turning off Wi-Fi on all portable devices to minimize the risk of a security incident.

Fixed Software and Version(s)

  • Windows Devices (Laptops, Desktops, Tablets)

  • Apple iOS Devices (iPhones, iPads, iPods)
  • Apple MacOS Devices (iMacs, MacBooks)
  • Phones, Tables and Chromebook’s running Android 6.0
    • Google Android Security Bulletin released November 6, 2017 (Note: Depending on your Android device model and mobile carrier, the update may or may not be available. To check for the version and update your Android, follow the instructions here: https://support.google.com/pixelphone/answer/4457705)
  • Home and office Wi-Fi Routers
  • Smart-home Appliances and Devices (Google Home, Amazon Echo, Wireless Cameras, Smart TVs, IOT devices)
    • Google Home and Amazon Echo have both release updates that are installed automatically to your voice-controlled assistant. For other devices, such as Smart TVs and Wireless Cameras, consult the manufacturer’s websites for update information.

 

Bookmark and Share

Archive