NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
AngryDog
Oct 16, 2017Guide
KRACK Vulnerabilities
Does the latest firmware fix any of the below vulnerabilities? CVE-2017-13077, 13078, 13079, 13080, 13081, 13082, 13084, 13086, 13087, 13088 If not, when will firmware be released to fix thes...
- Oct 25, 2017
Let me share this forum link:
AngryDog
Oct 16, 2017Guide
Done! This is serious and needs addressing ASAP.
My only query is, is that does a patched AP with an unpatched device (like a mobile phone / laptop) mean that it is secure?
Auri
Oct 16, 2017Star
From what I understand, as long as ONE device is patched, you're OK. It appears that the hack works by forging a copy of the Wi-Fi network, then getting the device onto the forged network. If the device doesn't require a certificate re-send on the hop to the new network, then it's vulnerable. I tweeted a link:
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007_FAQ_Rev-1.pdf
Ideally, you want the client OS patched, and all routers as quickly as possible.
- AngryDogOct 16, 2017Guide
Reading more into this, and thanks to your link, traffic sent via HTTPS doesn't seem to be affected?
Also, would using a VPN negate this as well?
- AuriOct 16, 2017Star
It seems any tools for sniffing and decrypting network traffic would work once an attacker has you on "their" network. So, I'm thinking VPN and HTTPS should be pretty safe, since they're encrypted from the client to the destination. However, that doesn't preclude an attacker from recording the packets and eventually decrypting them. You're on "their" network, after all. At least, that's the way I see it.
- AngryDogOct 16, 2017Guide
Yes that would make sense. The idea is though to make sure you're not on "their" network, and the only way of doing that currently is to effectively get patched, once patches are available.
The issue is, when are those patches going to be available? It has become an arms race.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!