Register Guidelines E-Books Search Today's Posts Mark Forums Read

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle

Notices

Reply
 
Thread Tools Search this Thread
Old 10-19-2017, 04:59 PM   #16
HarryT
eBook Enthusiast
HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.HarryT ought to be getting tired of karma fortunes by now.
 
HarryT's Avatar
 
Posts: 85,544
Karma: 93383043
Join Date: Nov 2006
Location: UK
Device: Kindle Oasis 2, iPad Pro 10.5", iPhone 6
Quote:
Originally Posted by haertig View Post
If that's the case, why is there any worry about this WPA2 vulnerability?
It's primarily of concern to businesses, who could be vulnerable to interception of information flowing between systems on their network. The risk to individuals is probably very low: virtually all online communication involving sensitive data is encrypted these days.
HarryT is offline   Reply With Quote
Old 10-19-2017, 06:00 PM   #17
NullNix
Guru
NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.NullNix ought to be getting tired of karma fortunes by now.
 
Posts: 916
Karma: 13928438
Join Date: Jan 2013
Location: Ely, Cambridgeshire, UK
Device: Kindle Oasis 3, Kindle Oasis 1
Quote:
Originally Posted by haertig View Post
If that's the case, why is there any worry about this WPA2 vulnerability? Or is this encryption only used during login, and not routine transmission (downloading books)? But the DRM on eBooks would serve as effective encryption.

Or is this WPA2 vulnerability more than just the simple eavesdropping case that I'm assuming?
It allows a physically nearby attacker to perform a full man-in-the-middle attack on the connection, so in effect it can remove the encryption entirely, and block or inject arbitrary packets -- but only the encryption at the wifi level. If the layer beneath is communicating using another shared secret (as the Kindle does), the only thing the attacker can do is DoS the connection by just refusing to pass some or all packets on (or changing them in transit, which would cause them to be dropped by the recipient, with the same effect). Eavesdropping is impossible, and though the attacker can fake out DNS, since the attacker cannot mimic Amazon's HTTPS traffic (due to lack of their private keys), again all this can be used for is denial of service.
NullNix is offline   Reply With Quote
Reply

Tags
wi-fi vulnerabilities

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free (Kindle/Kobo/DRM-free) Vulnerable by Amy Lane [LGBT Urban Fantasy w/Romance] ATDrake Deals and Resources (No Self-Promotion or Affiliate Links) 0 06-09-2017 07:04 AM
Kindle 3 doesn't support WPA2? WilliamG Amazon Kindle 47 12-17-2011 11:29 PM
Free (Kindle) WHEN THE EAGLE SCREAMS - America's Vulnerability to Terrorism arcadata Deals and Resources (No Self-Promotion or Affiliate Links) 0 09-01-2011 11:23 PM


All times are GMT -4. The time now is 12:24 PM.


MobileRead.com is a privately owned, operated and funded community.