<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WiFi is now cracked / hacked / broken - What can be done to protect ourselves? in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1344#M147</link>
    <description>&lt;P&gt;Unless we've all been hiding under a rock this morning, word has spread quite quickly that KRAck, a new vulnerability with WiFi WPA2, where the attack vector can zero out the encryption due to multiple request of the key exchange.&amp;nbsp; If your CEO or a friend on the street approaches you as a cyber security expert, what would you say?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;From POV - use a VPN when on WiFi to protect yourself to start.&amp;nbsp; Even with trusted WiFi connections, there is the opportunity for someone to exploit your WiFi on your system to see the traffic. Add another layer of encryption with a VPN - corporate or personal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those who have been under a rock and not learned about KRACK, here is some additional info: &lt;A href="https://arstechnica.com/information-technology/2017/10/how-the-krack-attack-destroys-nearly-all-wi-fi-security/" target="_blank"&gt;https://arstechnica.com/information-technology/2017/10/how-the-krack-attack-destroys-nearly-all-wi-fi-security/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 17:41:49 GMT</pubDate>
    <dc:creator>James</dc:creator>
    <dc:date>2017-10-16T17:41:49Z</dc:date>
    <item>
      <title>WiFi is now cracked / hacked / broken - What can be done to protect ourselves?</title>
      <link>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1344#M147</link>
      <description>&lt;P&gt;Unless we've all been hiding under a rock this morning, word has spread quite quickly that KRAck, a new vulnerability with WiFi WPA2, where the attack vector can zero out the encryption due to multiple request of the key exchange.&amp;nbsp; If your CEO or a friend on the street approaches you as a cyber security expert, what would you say?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;From POV - use a VPN when on WiFi to protect yourself to start.&amp;nbsp; Even with trusted WiFi connections, there is the opportunity for someone to exploit your WiFi on your system to see the traffic. Add another layer of encryption with a VPN - corporate or personal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those who have been under a rock and not learned about KRACK, here is some additional info: &lt;A href="https://arstechnica.com/information-technology/2017/10/how-the-krack-attack-destroys-nearly-all-wi-fi-security/" target="_blank"&gt;https://arstechnica.com/information-technology/2017/10/how-the-krack-attack-destroys-nearly-all-wi-fi-security/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 17:41:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1344#M147</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2017-10-16T17:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi is now cracked / hacked / broken - What can be done to protect ourselves?</title>
      <link>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1348#M149</link>
      <description>&lt;P&gt;What a crazy day it's been!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(ISC)²'s Director of Cybersecurity Advocacy, John McCumber, had a few thoughts on this subject - you can check them out&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://blog.isc2.org/isc2_blog/2017/10/krack-exploit-ruining-your-day.html" target="_self"&gt;on the blog today&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 20:13:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1348#M149</guid>
      <dc:creator>Kaity</dc:creator>
      <dc:date>2017-10-16T20:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi is now cracked / hacked / broken - What can be done to protect ourselves?</title>
      <link>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1353#M150</link>
      <description>&lt;P&gt;The researchers who discovered it have a very nice site at&amp;nbsp;&lt;A href="https://www.krackattacks.com/" target="_blank"&gt;https://www.krackattacks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, only Android and Linux are affected, as all the other OS builders don't conform to the standard.&amp;nbsp; Most enterprise-class Wifi manufacturers already have a fix out.&amp;nbsp; If they don't, maybe that's a pretty good indicator to shop for a new vendor.&amp;nbsp; Otherwise, end-to-end encryption is probably the safest bet for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly, I never trust WPA2 security, mostly because people never bother to set decent passwords, so I encrypt all my traffic with a VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 20:59:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1353#M150</guid>
      <dc:creator>John</dc:creator>
      <dc:date>2017-10-16T20:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi is now cracked / hacked / broken - What can be done to protect ourselves?</title>
      <link>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1357#M151</link>
      <description>&lt;P&gt;I don't think it's Android and Linux alone, Windows&amp;nbsp;received a fix as part of last weeks patch tuesday,&amp;nbsp;I was also reading today Apple devices not on the last beta are also affected as this has only been patched sometime between the vendor notice date (CERT/CC's broad note 28th Aug&amp;nbsp;2017).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I totally agree however on the need&amp;nbsp;to keep check on vendors timeliness on providing patches. Apples resolution for instance is only presently fixed in beta so unless they push out 11.1 or 11.0.4 you are likely vulnerable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This&amp;nbsp;also raises the question of "how far back will they fix this?". Both Android and iOS alike have the legacy support issue. then of course we have IoT devices....&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:09:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/WiFi-is-now-cracked-hacked-broken-What-can-be-done-to-protect/m-p/1357#M151</guid>
      <dc:creator>esl-gareth</dc:creator>
      <dc:date>2017-10-17T11:09:16Z</dc:date>
    </item>
  </channel>
</rss>

