AGL 34.90 Decreased By ▼ -0.30 (-0.85%)
AIRLINK 127.50 Increased By ▲ 4.27 (3.47%)
BOP 5.16 Increased By ▲ 0.12 (2.38%)
CNERGY 3.89 Decreased By ▼ -0.02 (-0.51%)
DCL 8.05 Decreased By ▼ -0.10 (-1.23%)
DFML 43.20 Decreased By ▼ -1.02 (-2.31%)
DGKC 75.00 Increased By ▲ 0.65 (0.87%)
FCCL 24.75 Increased By ▲ 0.28 (1.14%)
FFBL 49.51 Increased By ▲ 1.31 (2.72%)
FFL 8.90 Increased By ▲ 0.12 (1.37%)
HUBC 142.95 Decreased By ▼ -2.90 (-1.99%)
HUMNL 10.45 Decreased By ▼ -0.40 (-3.69%)
KEL 3.96 Decreased By ▼ -0.04 (-1%)
KOSM 7.81 Decreased By ▼ -0.19 (-2.38%)
MLCF 33.11 Increased By ▲ 0.31 (0.95%)
NBP 57.39 Increased By ▲ 0.24 (0.42%)
OGDC 144.51 Decreased By ▼ -0.84 (-0.58%)
PAEL 25.40 Decreased By ▼ -0.35 (-1.36%)
PIBTL 5.77 Increased By ▲ 0.01 (0.17%)
PPL 115.80 Decreased By ▼ -1.00 (-0.86%)
PRL 24.06 Increased By ▲ 0.06 (0.25%)
PTC 11.05 No Change ▼ 0.00 (0%)
SEARL 58.83 Increased By ▲ 0.42 (0.72%)
TELE 7.49 No Change ▼ 0.00 (0%)
TOMCL 41.20 Increased By ▲ 0.10 (0.24%)
TPLP 8.27 Decreased By ▼ -0.04 (-0.48%)
TREET 15.07 Decreased By ▼ -0.13 (-0.86%)
TRG 54.25 Decreased By ▼ -0.95 (-1.72%)
UNITY 27.70 Decreased By ▼ -0.15 (-0.54%)
WTL 1.31 Decreased By ▼ -0.03 (-2.24%)
BR100 8,645 Increased By 73.1 (0.85%)
BR30 27,123 Decreased By -153.1 (-0.56%)
KSE100 82,165 Increased By 706 (0.87%)
KSE30 26,067 Increased By 267.5 (1.04%)

A newly discovered flaw in the widely used Wi-Fi encryption protocol could leave millions of users vulnerable to attacks, prompting warnings Monday from the US government and security researchers worldwide. The US government's Computer Emergency Response Team (CERT) issued a security bulletin saying the flaw can open the door to hackers seeking to eavesdrop on or hijack devices using wireless networks.
"Exploitation of these vulnerabilities could allow an attacker to take control of an affected system," said CERT, which is part of the US Department of Homeland Security. The agency's warning came on the heels of research by computer scientists at the Belgian university KU Leuven, who dubbed the flaw KRACK, for Key Reinstallation Attack.
According to the news site Ars Technica, the discovery was a closely guarded secret for weeks to allow Wi-Fi systems to develop security patches. Attackers can exploit the flaw in WPA2 - the name for the encryption protocol - "to read information that was previously assumed to be safely encrypted," said a blog post by KU Leuven researcher Mathy Vanhoef.
"This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. The attack works against all modern protected Wi-Fi networks." The researcher said the flaw may also allow an attacker "to inject ransomware or other malware into websites."
The KRACK vulnerability allows attackers to circumvent the "key" on a Wi-Fi connection that keeps data private. The Belgian researchers said in a paper that devices on all operating systems may be vulnerable to KRACK, including 41 percent of Android devices.
'BE AFRAID'
The newly discovered flaw was serious because of the ubiquity of Wi-Fi and the difficulty in patching millions of wireless systems, according to researchers. "Wow. Everyone needs to be afraid," said Rob Graham of Errata Security in a blog post. "It means in practice, attackers can decrypt a lot of Wi-Fi traffic, with varying levels of difficulty depending on your precise network setup."
Alex Hudson, of the British-based digital service firm Iron Group, said the discovery means that "security built into Wi-Fi is likely ineffective, and we should not assume it provides any security." Hudson said Wi-Fi users who browse the internet should still be safe due to encryption on most websites but that the flaw could affect a number of internet-connected devices. Researchers at Finland-based security firm F-Secure said in a statement the discovery highlights longstanding concerns about Wi-Fi systems' vulnerability.

Comments

Comments are closed.