Google Banning User Privacy-Defying

ByNovak Bozovic-August 3, 2019.594 The Wi-Fi Alliance told vendors that the vulnerabilities of Dragonblood are secured, but the new finding concerns the safety of Wpa3. The vulnerabilities recently discovered by Dragonblood allow malicious actors to steal Wi-Fi password and access restricted networks. Security research warns against the closed security standards of Wi-Fi Alliance which prevent the community from acting more quickly. The two researchers on cyber-security who noticed the initial flaws have now discovered that two additional curves of BugsBrainpool were secure to use again. The approach included a quadratic residue test of Dragonfly without any side-channel leaks. The researchers (Mathy Vanhoef and Eyal Ronen) now claim that using Brainpool curves, Wpa3’s Dragonfly handshake introduces a second class of side-channel leakages. Ultimately this means that this weakness is still out there despite the advice given by the Wi-Fi Alliance that could lead to someone stealing Wi-Fi passwords and endangering your privacy. The two vulnerabilities reported recently are called Cve-2019-13377 and Cve-2019-13456. More specifically, when using Brainpool curves, the instability of Cve-2019-13377 is correlated with Wpa3’s Dragonfly handshake. In simple terms, this is a way of authenticating users or access points on Wpa3 routers. Although the Wi-Fi Alliance now recommends vendors to use P-521 curve attackers could use the newly found vulnerability to downgrade to the weaker P-256 vulnerability. The second weakness in Dragonblood relates to the implementation of Eap-pwd which is an authentication mechanism that Wpa and Wpa2 use. Eap-pwd however can still be used in Wpa3 routers as it is introduced to serve legacy purposes. Once again the researchers have warned against the activities of Wi-Fi Alliance introducing security updates. The Wi-Fi Alliance also relies on closed standards in terms of its development process rather than using open standards and allowing security experts to easily contribute. When a bug is found, it goes through a lengthy deployment phase that gives malicious actors plenty of time to plan their attacks. The Wi-Fi Alliance is now upgrading the Wi-Fi standard with adequate protections as a result of the aforementioned Dragonblood vulnerabilities. More information can be found in an updated version of the 2019 Dragonblood White Paperbest Safe Routers.