episode.ascii — live render
● episode

News Update – kr00k WIFI Vulnerability

TL;DRThe Kr00k vulnerability (CVE-2019-15126) affects Broadcom and Cypress WiFi chips in billions of devices, causing data packets to transmit unencrypted when a device disassociates from a router. Security researchers discovered it while…

Jordan + Scott discuss the kr00k vulnerability in this trial episode of a Hacked News Update

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Whatever you're listening to this on right now, it's almost certainly got a WiFi chip in it. It's almost certainly using something called WPA2, a security method that provides data protection and network control. Essentially, when you use WiFi, you are sending information flying through the air between your device and your router. And WPA2 is the encryption that makes sure all that data flying through the air is secure from anyone trying to watch. Secure enough for consumers sending credit card numbers. Secure enough for governments. Secure. And now that we've established just how secure that system is, it's October 2016 and a video pops up on YouTube. The video is four minutes long, narrated by a Belgian guy named Matty Van Hoof. In the video, Matty connects to Wi Fi on an Android device and he goes to match.com. He then opens up the command line on a computer and starts to force the random number used in the Wi Fi encryption to reset over and over again until he's able to parse out. I'm not gonna pretend to understand what he's doing, but I understand what he achieves. At the end of the video, Matti goes to log in to match.com on his Android device, He types in his username, types in his password, and he clicks login. And we watch. As the username and password he typed in on the phone appears on the screen of the laptop. We watch as he plucks that encrypted information out of the air and displays it in plain text right on his screen. We watch as he cuts through encryption seemingly secure enough for personal data and financial information and government documents in four minutes flat. The discovery was named key reinstallation attack or crack. There was a bunch of press coverage of cracked with a k. People got scared. Cracked with a k was patched. All was well. Until just this week, when another video went up, introducing us to something called Crook. You might notice this episode is coming out much sooner than our normal schedule. We're trying something new here. Today, we're gonna have a quick conversation about Crook, how it works, what it means, and where it's going here on let's call it a hacked news update.

Speaker 2: Jordan has just, propped a mic stand against another mic stand because one is, he broke one probably in a drunken fury.

Speaker 1: I'm a professional, and I will not dignify these spurious accusations. Alright. So I sit down on my laptop. I connect to Wi Fi. I go to wikipedia.com or whatever. What's happening in the air between the router and my laptop?

Speaker 2: Sure. So let's just not talk about, HTTPS encryption. Let's just pretend that the entire Internet doesn't have any kind of encryption on it. Just use that as a starting block. That's an easy way to start. Between your computer and the Wi Fi router, what's happened is you've logged in to the Wi Fi. You know, we've all had to do that process. Essentially, the Wi Fi router in your your computer kinda go through this handshake process where they pass keys back and forth that allow them to encrypt data to send back and forth between each other so that nobody else can kinda see what's going on.

Speaker 1: Right. So I log into the Wi Fi in my apartment. I can see 10 other Wi Fi networks, but I obviously can't log in to them because they don't have the password. But I also can't just sort of grab that data that's flying through the air out of the air because it's encrypted during this handshake process?

Speaker 2: Yeah. Yeah. So so, like, going back to our, like, Wi Fi episode and our kind of original season, the data traffic is typically encrypted. So WPA two, personal and enterprise are the most common kind of, Wi Fi encryption algorithms. And what they do is they create an encryption key set between your device and the Wi Fi router so that nobody else can really see that data. Why is this called Crook? The reason it's called Crook, k r zero zero k, is, similar to crack. What's happening is is when my laptop, say, and the Wi Fi router, you know, create a set of keys, they're these unique kind of, like, long string, encryption keys. But what happens is is that if my laptop ever disassociates from the Wi Fi router, the default protocol is that the keys get replaced with just zeros, hence the k r zero zero k, which isn't that big a deal. It's kind of a good thing that it does that, except for that all of the remaining packets in the transmission queue send out with this kind of new key set. So they send out over this essentially unencrypted channel.

Speaker 1: So you're trying to keep the the network in this disassociated state. So the packets that are in the queue, they're kinda flying through the air are, you know, they're they're decryptable, basically.

Speaker 2: You could kind of extend it to that because what you can do is you can actually force the disassociations. So my laptop will constantly be trying to reassociate with the Wi Fi router, and then you just keep forcing the disassociation. So you can actually send a deauthentication packet. There's a whole suite of, tools that let you kind of manipulate Wi Fi traffic and listen to Wi Fi traffic. Aircrack is the, like, suite of tools. And that doesn't let you stretch the window out, but can let you just kind of keep disassociating a device, resetting the key set, allowing you to read most of the packets. Is that difficult? I could probably do it in, like, thirty minutes. Really? Yeah. It's not too crazy.

Speaker 1: Oh, interesting. Is this the thing that the average person would need to worry about, or is this are there easier ways to get the traffic that's going from a person

Speaker 2: to No. It's there's probably not an easier way. It's not super complicated, but, you'd have to really be a target. Somebody would really wanna see your data. It's not like it's you roll into a Starbucks and you pull out your phone and connect to the router and, you know, somebody's looking at everyone's traffic. They have to identify you, figure out what the address of your phone is, you know, force the disassociation, read the packets in. Like, it's it's not something that you can do in mass scale. This is much more of a targeted attack. Mhmm.

Speaker 1: This is a vulnerability in the Wi Fi chips specifically, like the Broadcom and the Cypress chips. Is this the kind of thing where they just they release an update and this problem vanishes?

Speaker 2: Yeah. Theoretically, they should be able to, but the problem is that it's not the chipmaker that probably has to release the update. It then has to trickle through every, you know, hardware provider. So everything you have that has one of these chips in it is probably gonna need a firmware update. So, you know, it's not just, you know, Cypress. It's the 30,000 companies that make something with a Cypress chip in it.

Speaker 1: Right. Amazon hasn't updated their echo yet to have a firmware update that addresses Crook. Therefore, it's still vulnerable to it. Yeah. Interesting. So this is the kind of thing where it's like the person you wanna be looking the person you're kind of holding responsible is the technology manufacturer who either has or hasn't released a firmware update that addresses this.

Speaker 2: Yeah. Likely. I I'm sure they will be, and especially the major ones like Amazon. I can I can foresee them coming out with solutions to this, especially seeing as, you know, over their bandwidth channels, they have things running, like, you know, what people are asking Alexa and, you know, other personal recordings of what we're saying in our homes? But, yeah, it's I'm sure there is probably you know, come to think of it again, there probably is a way to do it in a mass scale, and that would be very complicated. Like, when I said it was very targeted, I'm sure you could write something that kinda monitors all of the air traffic around you and then sends d auth and dissociation attacks at everybody and then kind of bulk wholesale reads in all of that data. That would be much more complicated, but you probably could do that on second thought.

Speaker 1: Right. That state, that zero state, the crook with the two o's, you could just create that state on, say, a a network that's being used by tons and tons of people, and you'd be able to

Speaker 2: see all that traffic. Yeah. You'd be a nightmare for the Wi Fi router because you'd just constantly be bouncing people off of it. But and then reconnecting and just kind of constantly dumping transmission, buffers or queues of of packet data in an unencrypted or essentially unencrypted state. So, yeah, you could probably probably write a very complicated script and have a very complicated, you know, kind of device and sit and scrub a whole Wi Fi network if you really wanted to.

Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: Where is Daredevil? A miner. Don't miss the return of Marvel Television's Daredevil Born Again.

Speaker 2: So what's next?

Speaker 1: I feel liberated. We're gonna take this city back.

Speaker 4: Over Medicaid.

Speaker 3: In an all new season now streaming only on Disney plus.

Speaker 4: They're hunting us. It's time we started hunting them.

Speaker 1: I can work with that.

Speaker 4: This should be tons of fun.

Speaker 3: Marvel Television's Daredevil, born again, now streaming only on Disney plus.

Speaker 1: Why are people researching for these? Like, I understand a hacker going looking for one of these vulnerabilities because then essentially you could do something with it. You could deploy a hack with it. Why are people going and digging for these kind of mistakes, I guess, for these vulnerabilities, and then publishing them in YouTube videos and white paper reports for all the world to see? Yeah.

Speaker 2: Because it's a job now. Like, security research bug bounty, all that whole kind of suite of, security testing at the development level is like a you know, that's a profession. And, you know, we talked about this, I think, in the last episode where, you know, people don't intentionally create insecurity. They're intentionally trying to create a product or service. And by focusing solely on the output goal, they ignore some things that create insecurity. So there's an entire industry forming kind of in its wake coming afterwards, looking to clean up and patch those insecurities. I think that's how this bug was determined is literally one of these groups. I believe, was looking at an Amazon Echo, and they happened to reproduce a similar state to the the crack problem in that Wi Fi chip, and they were like, holy. It still exists.

Speaker 1: You talk about, like, move fast and break things and kinda makes sense there'd be a whole cottage industry that would come along and be like, we're gonna trail behind you and fix things.

Speaker 2: Yeah. And if you're really good at it, like, if you have that skill set and, you know, to logically rip down where the vulnerabilities could be and test for them and isolate them, you can make a pretty significant amount of money.

Speaker 1: This is an interesting hack and a vulnerability that affects billions and billions of devices. But generally speaking, do people need to worry about something like this, or is it more interesting as in, like, an intellectual academic sense?

Speaker 2: This isn't something that's gonna stop me from using Wi Fi. You know? I don't think there's most of the services that we use and that I depend on have a secondary layer of encryption. So even if they are sniffing my raw packets, those packets are encrypted anyway. So then we get into the requirement to do man in the middle attacks and bypass security checks for man in the middle attacks and all the rest of that jazz. So it's not something that I'm particularly worried about. Right. So

Speaker 1: It brings us back to the thing that we weren't bringing up in this, which is HTTPS, which is that even if

Speaker 2: Yeah.

Speaker 1: That packet is unencrypted, your traffic itself in the packet is encrypted?

Speaker 2: Yeah. So, like, HTTPS is a web protocol that encrypts your back and forth traffic between a web server and your web browser. So most of what I do on the Internet is web associated. So it's all through that kind of HTTPS tunnel. So it's encrypted. Like, HTTPS is now the standard rather than the alternative. So most significant web traffic, anything important on the Internet is gonna be HTTPS.

Speaker 1: So why is this important? Why is it getting so much coverage?

Speaker 2: Because it's, like, universal on a chip. It's a hardware problem. This isn't, like, a small line of code that needs to be changed. This is, you know, a security issue that comes about in a chip that's so widely used.

Speaker 1: A chip that's probably on the device that people are listening to this on.

Speaker 2: Yeah. It's literally my phone.

Speaker 1: Everybody. Thanks for listening to this little experiment. If you like getting this kind of a news update in between episodes, so this worked for you or if you've got any feedback at all, you can find us on Twitter at hacked podcast or reach us via email at get@hackedpodcast.com. We genuinely want all the feedback we can possibly be getting to make this show as good as it can be. As always, like and subscribe. And if you do like the show, check us out @patreon.comslashhackedpodcast. Thanks for listening.

Speaker 5: If you've got an insurance question, you could talk to the butcher at your local grocery store. He'd probably talk about trimming the fat, but it'd be about your brisket, not your insurance policies. Or you could talk to your local GEICO agent. They offer personalized assistance in finding the choicest cuts of coverage for all your insurance needs, which means more money for filet mignon. Or if you're a vegetarian, tofu lei mignon. To find a GEICO agent near you, visit geico.com/local.

Speaker 4: This episode is brought to you by Nespresso. Life moves quickly, and taking care of yourself shouldn't feel like another chore. With the new Nespresso Vertuo Up machine, morning routines become rituals. Whether organizing, getting the household moving, or preparing for the day, your coffee shouldn't ask for more. With Vertuo Up, just press brew and your morning begins. Rich aroma, bold flavor, zero effort. Press to explore. Every coffee, a new world. New Vertuo Up. Shop now at nespresso.com.

Speaker 6: Hey there. It's Way Fair here, where delivery and setup are as easy as a few taps on your phone. You're relaxing in an old hammock, scrolling Way Fair's app, when you spot it, a brand new patio set. Next thing you know, Way Fair delivers it right to your patio and sets it up. Oh, you need a new grill too? Alright. Wayfair's got you covered. With Wayfair's room of choice delivery and fast expert set up on qualifying orders, life gets a little easier. Visit wayfair.com or the Wayfair app.

Speaker 4: Wayfair. Every style. Every home.