![]() |
#1 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 57
Karma: 4066
Join Date: Jan 2013
Device: N/A
|
![]()
Very quiet indeed.
|
![]() |
![]() |
![]() |
#2 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
Given that both Amazon's and Kobo's eInk reader run Linux and there are patches already available for Linux, I would not be surprised to see new firmware to fix the vulnerability fairly soon.
Given the nature of the Krack vulnerability, I'd worry more about your wireless router than your Kobo device. |
![]() |
![]() |
![]() |
#3 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,847
Karma: 3212428
Join Date: Jun 2011
Device: iphone stanza, kobo touch,ASUS TF300,KOBO GLO, Kobo Aura HD, Kobo Mini
|
Quote:
|
|
![]() |
![]() |
![]() |
#4 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
I hate to be the voice of gloom and doom, but KRACK is already an issue for me. Network administration/security in an education environment is kinda fun—invite the hackers in and give them user names and passwords to give them a jumpstart. In our wireless environment, disabling fast BSS transitions mitigates the issue but real fixes are not here yet.
As the old saw goes, Ask not whether you're paranoid, ask whether you're paranoid enough! |
![]() |
![]() |
![]() |
#5 | |
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 154
Karma: 32060
Join Date: Aug 2017
Device: Kobo Aura H2O, Kobo Aura One, Pocketbook Inkpad 3 Pro
|
Quote:
|
|
![]() |
![]() |
![]() |
#6 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
I'm using DDWRT on my wireless router at home and would recommend it for most people who have some technical skills.
|
![]() |
![]() |
![]() |
#7 |
Still reading
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 13,892
Karma: 103895653
Join Date: Jun 2017
Location: Ireland
Device: All 4 Kinds: epub eink, Kindle, android eink, NxtPaper
|
It's an unpatched client approved to use your WiFi that creates the vulnerability.
|
![]() |
![]() |
![]() |
#8 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 58
Karma: 4158
Join Date: Nov 2012
Device: Kobo Glo, Kobo Aura H2O, Kobo Aura One
|
|
![]() |
![]() |
![]() |
#9 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
|
![]() |
![]() |
![]() |
#10 |
*carrier lost*
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 62
Karma: 14000
Join Date: Aug 2015
Location: 2001:db8:e:b00c::f00d
Device: Kobo Forma, H2O v1, Aura HD
|
The bug affects wpa_supplicant and hostap. The latter most probably isn't used on the Kobo eink readers, but the former is for connecting to wireless LANs. However, the attack mentioned does not in a compromise of the WPA2 passphrase, but instead a single session can be read. For a ebook reader I would guess that its WLAN is off most of the time, and only sporadically switched on for syncing. At least as a temporary user measure this shouldn't be a burden on users. And even if a session gets compromised at the data link level, I fail to see what damage could be done? A firmware download is rare, and then the attacker doesn't get any valuable information I would think. Sending a hacked firmware inband doesn't seem to be really possible, but I might be wrong here. Seeing reading statistics also doesn't strike me as too dangerous unless in those cases where someone doesn't want even Kobo to see them. So the danger of Krack on ebook readers doesn't strike me as even low.
|
![]() |
![]() |
![]() |
#11 |
*carrier lost*
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 62
Karma: 14000
Join Date: Aug 2015
Location: 2001:db8:e:b00c::f00d
Device: Kobo Forma, H2O v1, Aura HD
|
|
![]() |
![]() |
![]() |
#12 | |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
Quote:
If it wasn't for my love for the usage graphs, I might not have bothered to install DD-WRT on the 7000P. I have enough fun with wireless at work these days to keep me satisfied. |
|
![]() |
![]() |
![]() |
#13 |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
From what I've read, the nonce reuse vulnerability needs to be on both ends of the connection to allow the man in the middle attack to work. It would appear that Apple and Microsoft—for supported products—are releasing/have released patches while some Linux distributions have patches available. Pretty much leaving Android devices as the potential victims.
Last edited by DNSB; 10-28-2017 at 02:40 AM. |
![]() |
![]() |
![]() |
#14 |
Connoisseur
![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 67
Karma: 770
Join Date: Jun 2010
Location: Pennsylvania, USA
Device: Kindle 4 Basic, Kobo Aura
|
Client patching is the more important of the two -- router is only important if it's being in a client mode. And as mentioned Linux-based devices may be more vulnerable to the four-way handshake vulnerability.
Assuming that our Kobo's are affected I'm hoping the company will chime in on that and if/when updated firmware is being tested / released. Or if this last firmware update had already patched for it. In my case the biggest concern I have right now is the user logon aspects of my device over Wifi and especially purchasing anything via the device. A low risk of course given that an attacker would need to be in close proximity of the Wifi signal, but still a concern. Last edited by roebeet; 10-28-2017 at 09:41 PM. Reason: syntax |
![]() |
![]() |
![]() |
#15 | |
Bibliophagist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,795
Karma: 168959602
Join Date: Jul 2010
Location: Vancouver
Device: Kobo Sage, Libra Colour, Lenovo M8 FHD, Paperwhite 4, Tolino epos
|
Quote:
To quote from the krackattacks.com website: Currently, all vulnerable devices should be patched. In other words, patching the AP will not prevent attacks against vulnerable clients. Similarly, patching all clients will not prevent attacks against vulnerable access points. Note that only access points that support the Fast BSS Transition handshake (802.11r) can be vulnerable. That said, it is possible to modify the access point such that vulnerable clients (when connected to this AP) cannot be attacked. However, these modifications are different from the normal security patches that are being released for vulnerable access points! So unless your access point vendor explicitly mentions that their patches prevent attacks against clients, you must also patch clients. The first paragraph is why we have disabled Fast BSS Transitions on our corporate network. |
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Troubleshooting Kindle PW vulnerable to wpa2 krack vulnerability? | Eagle Reader | Amazon Kindle | 16 | 10-19-2017 06:00 PM |
Glo Fast draining battery issue & Kobo's response | itsmir | Kobo Reader | 14 | 01-06-2015 02:04 PM |
My kobo doesn't work and I can't get a response from the technical team! | jb1 | Kobo Reader | 19 | 12-28-2011 01:30 PM |
Official Response from Craig to my inquiry about the LCD Defective Panel & OS 2.2 | tipstir | Android Devices | 3 | 04-01-2011 03:42 AM |
Kobo books needs to improve customer service response | robko | Kobo Reader | 4 | 11-18-2010 01:47 PM |