Hey, What should we do to mitigate against the krack vulnerability in our mikrotik gear? I checked the changelogs at https://mikrotik.com/download/changelogs/, but there's no mention of krack (assumedly because the last updates are from before krack was announced). I assume people are working on a firmware update? - Ben -- -- echo [q]sa[ln0=aln256%Pln256/snlbx]sb241167078674140849351213545168413280214786211741720960170477998338109578719788558437971008954751099682787776927198532026019640182283695835073769037269976965492880188752740629807625756643115316959456234027360849928332596130768194snlbxq|dc
Hi Ben, If you're on the most recent versions of RouterOS, then you should be fine. Mikrotik released a statement on Monday, available at https://forum.mikrotik.com/viewtopic.php?t=126695. Regards, Ben Farmer -----Original Message----- From: Public [mailto:public-bounces@talk.mikrotik.com.au] On Behalf Of Ben Williams Sent: Wednesday, 18 October 2017 16:15 To: MikroTik Australia Public List <public@talk.mikrotik.com.au> Subject: [MT-AU Public] krack Hey, What should we do to mitigate against the krack vulnerability in our mikrotik gear? I checked the changelogs at https://mikrotik.com/download/changelogs/, but there's no mention of krack (assumedly because the last updates are from before krack was announced). I assume people are working on a firmware update? - Ben -- -- echo [q]sa[ln0=aln256%Pln256/snlbx]sb241167078674140849351213545168413280214786211741720960170477998338109578719788558437971008954751099682787776927198532026019640182283695835073769037269976965492880188752740629807625756643115316959456234027360849928332596130768194snlbxq|dc _______________________________________________ Public mailing list Public@talk.mikrotik.com.au http://talk.mikrotik.com.au/mailman/listinfo/public_talk.mikrotik.com.au
*) wireless - improved WPA2 key exchange reliability; That’s it right there :) Their forum thread about it suggests only a small amount of chipsets have the issue though so you may not need to do anything.. On Wed, 18 Oct 2017 at 5:16 pm, Ben Williams <benw01@gmail.com> wrote:
Hey,
What should we do to mitigate against the krack vulnerability in our mikrotik gear?
I checked the changelogs at https://mikrotik.com/download/changelogs/, but there's no mention of krack (assumedly because the last updates are from before krack was announced).
I assume people are working on a firmware update?
- Ben
--
-- echo [q]sa[ln0=aln256%Pln256/snlbx]sb241167078674140849351213545168413280214786211741720960170477998338109578719788558437971008954751099682787776927198532026019640182283695835073769037269976965492880188752740629807625756643115316959456234027360849928332596130768194snlbxq|dc _______________________________________________ Public mailing list Public@talk.mikrotik.com.au http://talk.mikrotik.com.au/mailman/listinfo/public_talk.mikrotik.com.au
-- Damien Gardner Jnr VK2TDG. Dip EE. GradIEAust rendrag@rendrag.net - http://www.rendrag.net/ -- We rode on the winds of the rising storm, We ran to the sounds of thunder. We danced among the lightning bolts, and tore the world asunder
Mikrotik have advised that it doesn't affect RouterOS devices as they don't implement the "nonce" WPA components, here is some information which might help. https://forum.mikrotik.com/viewtopic.php?f=21&t=126695 Regards Paul -----Original Message----- From: Public [mailto:public-bounces@talk.mikrotik.com.au] On Behalf Of Ben Williams Sent: Wednesday, 18 October 2017 5:15 PM To: MikroTik Australia Public List Subject: [MT-AU Public] krack Hey, What should we do to mitigate against the krack vulnerability in our mikrotik gear? I checked the changelogs at https://mikrotik.com/download/changelogs/, but there's no mention of krack (assumedly because the last updates are from before krack was announced). I assume people are working on a firmware update? - Ben -- -- echo [q]sa[ln0=aln256%Pln256/snlbx]sb241167078674140849351213545168413280214786211741720960170477998338109578719788558437971008954751099682787776927198532026019640182283695835073769037269976965492880188752740629807625756643115316959456234027360849928332596130768194snlbxq|dc _______________________________________________ Public mailing list Public@talk.mikrotik.com.au http://talk.mikrotik.com.au/mailman/listinfo/public_talk.mikrotik.com.au
participants (4)
-
Ben Farmer
-
Ben Williams
-
Damien Gardner Jnr
-
Paul Julian