If you don't lock your door at night, is that a vulnerability?
When I was growing up, our front door and back door were never locked. Was that a vulnerability? Did it create an attack vector? Were we at risk?
If your first reaction to the above questions is “hellyes!”, would you change your mind if you knew we lived on a dead end street in a small, secluded neighborhood, about 2 miles out, in dense woods, from the center of a very small town? That the last known neighborhood crime was when a group of unidentified kids (ahem) broke some windows in a house that was under construction? That we had dogs…fairly large and fairly loud dogs? My father kept a .45 automatic handy and knew how to use it? (He didn’t, but you get my drift here.)
Not being a security professional, my general impression is that, as with so many network/information security issues, the real answer is, “it depends.” And so it is with AirTight’s revelation this week of what it calls a “vulnerability” in the WPA2, the Wi-Fi Alliance industry security specification based on the IEEE 802.11i standard.
A lot of folks, including some of us at “Network World,” are arguing over AirTight’s WPA2 exploit and its implications for Wi-Fi security. My own view is that AirTight did little, leading up to yesterday’s demonstration, to provide any kind of context for their claim. “WPA2 is vulnerable” or “broken” or “iffy” or “questionable” is a lot different from “Under certain circumstances, a known characteristic of WPA2 sometimes can be used to spoof the Address Resolution Protocol and perhaps cause a few wireless clients to redirect their traffic to an internal attacker masquerading as default router.”
In my opinion, AirTight didn’t handle that well. But they weren’t alone. Even granting that AirTight didn’t release details to the Wi-Fi Alliance or to wireless LAN vendors, the WFA did little during the week except finally issue a pro forma statement, and refer inquiries to Aerohive’s Matthew Gast (who, to be fair, is the chair of the WFA’s Security Technical Task Group). Essentially it said “we take these kinds of things seriously; it’s based on well-known ARP spoofing; we’re awaiting details.” All of which is true, but one might have expected (at least I did) a bit more from the group that actually created the specification being challenged.
Finally, there was Cisco, or more accurately there was NOT Cisco. Cisco completely dominates both the enterprise and consumer Wi-Fi markets. The Big Dog. Big Stakes. Big Silence. I emailed Cisco for a comment, an assessment, a reaction, anything. Cisco PR referred me to the Wi-Fi Alliance statement.
UPDATE: At about 3:25 pm ET today, I received the following Cisco statement: “Cisco did not receive any information from the presenter ahead of time, but did have Information Security representatives in the audience during the official presentation. Cisco has assessed the latest information and determined that it does not represent a significant threat to our customers or warrant a Security Advisory at this time. We are not seeing significant interest from our customers but will consider an official response if this changes. At this time we are making information available internally to Cisco Account Managers to answer any customer questions. The key points focus on the need for a trusted, authenticated user to launch the attack and the number of readily available workarounds. These include blocking client-to-client communication (an existing feature of both Autonomous and Lightweight Cisco Access Points) and using IDS to detect ARP spoofing.”
If you’re inclined, you can follow the development of the story on our site with these links:
Our first report, by our Wireless Alert Newsletter Editor, Joanie Wexler.
Our FAQ on what was known prior to the Thursday demo and details from AirTight.
Our post-demo coverage, “AirTight defends Wi-Fi WPA2 ‘vulnerability’ claim” and Joanie’s “Upshot of the WPA2 brouhaha”
AirTight plans a Webinar on what it calls “Hole 196” on August 4. You can register online here.
AirTight found a way to use a group encryption key to set up a man in the middle attack — basically causing one authenticated wireless client to send its traffic to an attacking wireless client (also an authenticated user) masquerading as the first client’s default router or gateway. The set up makes use of the group encryption key (Group Temporal Key or GTK) shared by all the clients associated to a given access point.
So everyone seems to agree, “Yup, you can do that. Unless, you can’t.” For example, enabling “client isolation” on the access point means the clients attached to one access point can’t communicate with each other through the access point. So, while the attacker could cause the victim to switch to a new default router (ie, the attacker), the access point wouldn’t let the communication actually take place.
Part of AirTight’s point is that this is an insider threat. Which means that ONLY an insider can carry it out. That’s one of those good news/bad news things. Insiders clearly represent a potential threat. When I was a teenager, I thought my family represented a pretty significant threat: to my peace of mind, my general laziness, freedom of movement, etc.
But given AirTight’s revelations, I don’t see major changes pending in how enterprises currently deal with their wireless users. Do you?




