From: Lonnie A. <li...@lo...> - 2017-10-16 17:30:34
|
AstLinux Users, For the sake of completeness, AstLinux standard builds do not contain WiFi client (wpa_supplicant) or server (hostapd) support, so the recent KRACK WPA2 security disclosures do not apply to AstLinux. Ref: Key Reinstallation Attacks Breaking WPA2 by forcing nonce reuse https://www.krackattacks.com Though, any attached WiFi WPA2 access points and corresponding clients may well be vulnerable, in particular any Linux clients using wpa_supplicant are particularly vulnerable. Note that this KRACK vulnerability affects WiFi non-encrypted traffic payloads such as HTTP, as if you tapped a cable, encrypted payloads such as HTTPS and OpenVPN remain secure. Lonnie |