<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KRACK - Apple security notices need more detail in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/KRACK-Apple-security-notices-need-more-detail/m-p/3422#M350</link>
    <description>&lt;P&gt;Yes, this is confusing. I am now seeing information for IPhone 8, IPhone 8 plus, and IPhone X at this link (in addition to the original IPhone 7 information). It looks like there are multiple CVE numbers for KRACK (Apple is showing CVE-2017-13080 for the 7 and&amp;nbsp;&lt;SPAN&gt;CVE-2017-13078 and&amp;nbsp;CVE-2017-13079 for the 8 and X) and they are providing information separately.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2017 14:58:20 GMT</pubDate>
    <dc:creator>kpinkham</dc:creator>
    <dc:date>2017-11-07T14:58:20Z</dc:date>
    <item>
      <title>KRACK - Apple security notices need more detail</title>
      <link>https://community.isc2.org/t5/Industry-News/KRACK-Apple-security-notices-need-more-detail/m-p/3239#M332</link>
      <description>&lt;P&gt;Apple announced new security updates November 1st 2017. This time they explicitly list KRACK fix but only for iPhone 7 and iPad Pro 9.7 inch. Does that mean everything else was already patched or that everything else is vulnerable? Apple need&amp;nbsp;to be specific and clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Official apple announcement:&amp;nbsp;&lt;A href="https://support.apple.com/en-us/HT208222" target="_blank"&gt;https://support.apple.com/en-us/HT208222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the bottom of that page:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Wi-Fi&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Available for: iPhone 7 and later, and iPad Pro 9.7-inch (early 2016) and later&lt;/P&gt;&lt;P&gt;Impact: An attacker in Wi-Fi range may force nonce reuse in WPA clients (Key Reinstallation Attacks - KRACK)&lt;/P&gt;&lt;P&gt;Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.&lt;/P&gt;&lt;P&gt;CVE-2017-13080: Mathy Vanhoef of the imec-DistriNet group at KU Leuven&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 18:46:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/KRACK-Apple-security-notices-need-more-detail/m-p/3239#M332</guid>
      <dc:creator>AJ2</dc:creator>
      <dc:date>2017-11-02T18:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: KRACK - Apple security notices need more detail</title>
      <link>https://community.isc2.org/t5/Industry-News/KRACK-Apple-security-notices-need-more-detail/m-p/3422#M350</link>
      <description>&lt;P&gt;Yes, this is confusing. I am now seeing information for IPhone 8, IPhone 8 plus, and IPhone X at this link (in addition to the original IPhone 7 information). It looks like there are multiple CVE numbers for KRACK (Apple is showing CVE-2017-13080 for the 7 and&amp;nbsp;&lt;SPAN&gt;CVE-2017-13078 and&amp;nbsp;CVE-2017-13079 for the 8 and X) and they are providing information separately.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 14:58:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/KRACK-Apple-security-notices-need-more-detail/m-p/3422#M350</guid>
      <dc:creator>kpinkham</dc:creator>
      <dc:date>2017-11-07T14:58:20Z</dc:date>
    </item>
  </channel>
</rss>

