• [^] # Re: commentaire link

    Posté par . En réponse au journal WPA2 est bronsonisé. Évalué à 7.

    Les deux utilisent wpa_supplicant qui est en effet le pire sur le sujet mais bon si on lit en details:

    In particular this means that attacking macOS and OpenBSD is significantly easier than discussed in the paper.

    Et encore:

    we discovered ourselves that Android, Linux, Apple, Windows, OpenBSD, MediaTek, Linksys, and others, are all affected by some variant of the attacks.

    Donc en gros tout le monde est tombe dans le piege, certains plus que d'autres (wpa_supplicant etant au top de la hierarchie).

    Ce que je mentionnais de OpenBSD c'est:

    OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure deadline: "In the open source world, if a person writes a diff and has to sit on it for a month, that is very discouraging". Note that I wrote and included a suggested diff for OpenBSD already, and that at the time the tentative disclosure deadline was around the end of August. As a compromise, I allowed them to silently patch the vulnerability. In hindsight this was a bad decision, since others might rediscover the vulnerability by inspecting their silent patch. To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo.

    Apres si tu trouves ca cool de mettre TOUS les autres systemes en danger c'est sympa, un petit peu egoiste tout de meme non? Quoiqu'il en soit, OpenBSD sera maintenant averti en ... dernier.