y20070122 wrote:
兩邊都要更新,一邊...(恕刪)
我剛剛去看了一下KRACK的網站,其中的FAQ有以下表示:
What if there are no security updates for my router?
Our main attack is against the 4-way handshake, and does not exploit access points, but instead targets clients. So it might be that your router does not require security updates. We strongly advise you to contact your vendor for more details. In general though, you can try to mitigate attacks against routers and access points by disabling client functionality (which is for example used in repeater modes) and disabling 802.11r (fast roaming). For ordinary home users, your priority should be updating clients such as laptops and smartphones.
也就是說KRACK並不會利用基地台(路由器)而是針對4次握手的機制問題直接攻擊Client端,比較需要注意的是Client端(如:NB/手機/PAD)的更新。
網通設備會被影響的部分大概就是中繼器、橋接器、無線IoT設備、無線IPCAM等Client端設備。
所以說先去更新你的Client端設備比較重要。