Security · 1h ago
KRACK Attack Broke WPA2 by Reusing Encryption Keys
In 2017, researcher Mathy Vanhoef revealed KRACK, an attack that exploited a flaw in the WPA2 four-way handshake to force key reinstallation and nonce reuse. This allowed attackers within Wi-Fi range to decrypt traffic, with Linux and Android 6.0+ devices particularly vulnerable due to an all-zero key installation. The attack did not crack passwords but targeted the protocol itself, affecting virtually all WPA2 networks.
Meridian48 take
KRACK remains a textbook case of how a subtle protocol flaw can undermine years of assumed security, though widespread patching has mitigated its impact.
Read the full reporting
KRACK: How WPA2 Wi-Fi Encryption Was Broken by Reusing a Key →
DEV Community
krack-attackwpa2-vulnerability