Mathy Vanhoef le Eyal Ronen
A re hopoleng hore ka April bona bangoli ba
Leha ho le joalo, tlhahlobo e bonts'itse hore ts'ebeliso ea Brainpool e lebisa sehlopheng se secha sa ho lutla ha kanale ea lehlakore ho algorithm ea puisano e sebelisoang ho WPA3.
Ha o sebelisa Brainpool's elliptic curve, Dragonfly e kenya phasewete ka ho pheta-pheta mantsoe a 'maloa a password ho kopanya hash e khuts'oane pele e sebelisa elliptic curve. Ho fihlela hashe e khuts'oane e fumanoa, lits'ebetso tse entsoeng li ipapisitse le password ea moreki le aterese ea MAC. Nako ea ts'ebetso (e amanang le palo ea ho pheta-pheta) le tieho lipakeng tsa ts'ebetso nakong ea likhakanyo tsa pele li ka lekanyetsoa le ho sebelisoa ho fumana litšobotsi tsa password tse ka sebelisoang ntle le marang-rang ho ntlafatsa khetho ea likarolo tsa phasewete ts'ebetsong ea ho hakanya phasewete. Ho etsa tlhaselo, mosebelisi ea hokahanyang marang-rang a se nang mohala o tlameha ho fihlella sistimi.
Ho feta moo, bafuputsi ba fumane ts'oaetso ea bobeli (CVE-2019-13456) e amanang le ho lutla ha tlhahisoleseling ts'ebetsong ea protocol.
Ha e kopantsoe le mokhoa o ntlafalitsoeng oa ho sefa lerata ts'ebetsong ea tekanyo ea latency, litekanyo tse 75 ka aterese ea MAC li lekane ho fumana palo ea ho pheta-pheta. Ha u sebelisa GPU, litšenyehelo tsa lisebelisoa tsa ho hakanya phasewete e le 'ngoe ea bukana e hakanyetsoa ho $1. Mekhoa ea ho ntlafatsa ts'ireletso ea protocol ho thibela mathata a khethiloeng a se a kenyelelitsoe liphetolelong tsa litekanyetso tsa nakong e tlang tsa Wi-Fi (
Source: opennet.ru