This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Any comments from Sophos regarding WPA2 may be cracked by KRACK (Key Reinstallation AttaCK)

firmware upgrades?



This thread was automatically locked due to age.
Parents Reply Children
  • Sophos just released this article;

    Sophos Wireless APs, XG-W, Cyberoam and SG-W appliances are affected. We will release patches as soon as they are made available to us.

    Apply patches as soon as they are available. Sophos will update this article whenever a patch is released to fix the vulnerability.

    Customers can reduce their exposure to the vulnerabilities by disabling the Fast Roaming options and disabling Mesh.

    My 2cents: Great so will just have to wait for a third party (f.e. Openwrt) to provide a patch, and then let sophos implement that patch in their updates. Two options, 1. this is gonna take some time, or 2. Sophos rushes out an update without proper testing and breaks stuff (aka the usual)

  • Ronald beat me to the punch.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Pretty sure there already patches out there on GitHub for wpa_supplicant -- which I think Sophos uses for at least some of their products.  Patch time may not be quite that long.. but of course there will be testing, etc. to be done.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Come on Sophos/Intel Mcafee , krackattacks.com is a criminal activity?