Key Reinstallation Attacks Breaking WPA2 by forcing nonce reuse Discovered by Mathy Vanhoef of imec-DistriNet, KU Leuven, 2017 Introduction We discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. An attacker within range of a victim can exploit these weaknesses using key reinstallation attacks (KRACKs). Concretely, attackers can use this novel attack
ããã > ã¬ã¸ã§ãã > ã¹ãã¼ããã©ã³æäºãã¿ã»çµ±è¨Â > ã»ãã¥ãªãã£Â > æ¤è¨¼çµæï¼é«æ¨æµ©å æ°ããç«è ¹ã®ãWiFiã·ã§ã¢ããæå·åãã¦ãã¯ãã®Wi-Fiãã¹ã¯ã¼ããå¹³æã§ä¿åãã¦ã æ¥æ¬ã®ã¯ã©ã¦ããã¡ã¦ã³ãã£ã³ã°ãµã¼ãã¹ãMakuakeãã§160ä¸åãã®è³éã調éããããWiFiã·ã§ã¢ãã9æ18æ¥ã«iOS/Androidã¢ããªããªãªã¼ã¹ãã¦ãµã¼ãã¹ãéå§ãã¾ããã ä½ããã¦ããéä¿¡åç·ï¼éä¿¡éï¼ãä»è ã«å£²ã£ããè²·ã£ãããããã¨ã§ãä½ã£ã¦ããã¨ãã¯ã·ã§ã¢ããããè¶³ããªãã¨ãã¯ã·ã§ã¢ãããã¨ããå½¢ã§éä¿¡ã®è²©å£²èªç±åãç®æãã¦ããããã§ãã å ·ä½çã«ã¯ã·ã§ã¢ãããå ´åã¯ãèªèº«ãã¢ã¯ã»ã¹ãããã¨ãã§ããï¼ãã¹ã¯ã¼ããç¥ã£ã¦ããï¼SSIDã¨ãã¹ã¯ã¼ãã¨ä½ç½®æ å ±ãç»é²ãã¾ããããã¨ãè¿ãã«ããã·ã§ã¢ãããã人ã¯ãã¹ã¯ã¼ããç¥ããã«ãã®ã¢ã¯ã»ã¹ãã¤ã³ããå©ç¨ãããã¨ãå¯è½ã«ãªãã¾ãããããéä¿¡ã¯
éµä¾¿å±ã§ã¯ãå¿«é©ã«ã¹ãã¼ããã©ã³ãªã©ã®éä¿¡æ©å¨ããå©ç¨ããã ããç°å¢ã¥ããã®ä¸ç°ã¨ãã¦ãã客ãã¾ããã¼ã§ã®ãNTTãã³ã¢ãauãã½ãããã³ã¯ã®Wi-Fiï¼å ¬è¡ç¡ç·LANï¼ãµã¼ãã¹ãå°å ¥ãã¦ããã¾ããï¼å¯¾è±¡å±ã«éãã¾ããï¼ æ±äº¬23åºå ã®éµä¾¿å±ãä¸å¿ã«è¨ç½®ãã¦ãã¾ããåéµä¾¿å±ã®ç«å°ç°å¢çã«ãããæºå¸¯é»è©±å社ã®ãµã¼ãã¹å°å ¥ç¶æ³ãç°ãªãã¾ãã®ã§ã詳ããã¯ã次ã®ãWi-Fiå°å ¥éµä¾¿å±ã®ä¸è¦§ãã§ã確èªãã ããã
æ¥æ¬éµä¾¿ã¯3æ24æ¥ãæ±äº¬23åºå ã«æå¨ããéµä¾¿å±ã«ããã¦ãNTTãã³ã¢ãKDDIãã½ãããã³ã¯ã¢ãã¤ã«ã®å ¬è¡ç¡ç·LANãµã¼ãã¹ãéå§ãããã¨ãçºè¡¨ããã å©ç¨å¯è½ã¨ãªãéµä¾¿å±ã¯ä¸é¨ãé¤ãæ±äº¬23åºå ã®ç´1000å±ãå ¬è¡ç¡ç·LANãµã¼ãã¹ã¯ãdocomo Wi-Fiãau Wi-Fi SPOTãã½ãããã³ã¯Wi-Fiã¹ãããã®3ã¤ããã ããau Wi-Fi SPOTã¯5æä»¥éã«é 次è¨ç½®ãé²ãã¦ããã ãªãå¼ççãåèçãç¥å¥å·çãªã©æ±äº¬23åºå¤ã®ä¸é¨éµä¾¿å±ã§ãå ¬è¡ç¡ç·LANãµã¼ãã¹ãå©ç¨å¯è½ãæ¥æ¬éµä¾¿ã®ãµã¤ãã§Wi-Fiå°å ¥éµä¾¿å±ã®ä¸è¦§ãå ¬éãã¦ããã
任天å ã¯2æ27æ¥ããã³ãã³ãã¼DSã¨Wiiåãã®ãããéä¿¡ãµã¼ãã¹ããã³ãã³ãã¼Wi-Fiã³ãã¯ã·ã§ã³ãã5æ20æ¥åå¾11æã§çµäºããã¨çºè¡¨ãããçµäºå¾ã¯ãããã§ã ã©ãã¶ã¤ã®æ£®ãï¼DSï¼ãªã©ã対å¿ã½ããã§ã®ãããéä¿¡ãµã¼ãã¹ãå©ç¨ã§ããªããªãã 任天å ã¯ããµã¼ãã¹ããå©ç¨ããã ãã¦ããçæ§ã«ã¯èª ã«ç³ã訳ãããã¾ããããä½åãçè§£ã®ã»ã©ããããããé¡ããããã¾ããé·ãã«ããããå©ç¨ããã ãããããã¨ããããã¾ãããã¨ãã¦ããã ãã³ãã³ãã¼DSã¨Wiiã®ç¡ç·LANæ©è½ã使ãããããçµç±ã§ã¦ã¼ã¶ã¼å士ã®å¯¾æ¦ã交æµãªã©ãã§ãããµã¼ãã¹ãDSã®ã大åå¥ï¼ãã³ããã©ã¶ã¼ãºDXãããã±ããã¢ã³ã¹ã¿ã¼ ã½ã¦ã«ã·ã«ãã¼ï¼ãã¼ãã´ã¼ã«ããããWiiã®ãããªãªã«ã¼ãWiiããè¡ã¸ãããã ã©ãã¶ã¤ã®æ£®ããªã©ã対å¿ã½ããã§ã¯éä¿¡ãã§ããªããªããé信以å¤ã®ã²ã¼ã ã¯å¾æ¥éãå©ç¨ã§ããã DSã®ããã³ãã³ãã¼D
é«éç¡ç·éä¿¡ã®ããã®ã¤ã³ãã©ãæ´ã£ã¦ããªãå°åã§ã¤ã³ã¿ã¼ããããæ®åãããã«ã¯ã©ãããã°ããã ãããï¼çãã¯ãã¡ãããé£è¡ãã¦ããç©ä½ããWi-Fi黿³¢ãç §å°ããã¨ãããã®ã«ãªãã Wiredã«ããã¨ãGoogleã¯ãµãã©ç æ¼ ä»¥åã®ã¢ããªã«ãæ±åã¢ã¸ã¢ã®å½ã ãªã©ã«åå¨ãã人éé¢ããå ´æã«ãæ°çãé£è¡è¹ãå©ç¨ããç¡ç·ãããã¯ã¼ã¯ãæ§ç¯ãã¹ãåãçµãã§ããã¨ããã åãµã¤ãã¯ãé«é«åº¦ãã©ãããã©ã¼ã ãã¨åä»ãããããããã£ãä»çµã¿ã«ãããä¸çä¸ã§ããã10åäººãæ°ãã«ã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§ããããã«ãªãã¨ä¼ãã¦ãããã¾ãé£è¡è¹ã®é»æ³¢ã¯ãæ°ç¾å¹³æ¹ãã¤ã«ï¼100å¹³æ¹ãã¤ã«ã¯ç´260å¹³æ¹kmï¼ã®å°åã«ãã人ã ã«å±ãã¨ããã The Wall Street Journalï¼WSJï¼ãå é±å ±ããã¨ããã«ããã¨ãGoogleã¯ã¢ããªã«ãã¢ã¸ã¢ã§æºå¸¯é»è©±éä¿¡äºæ¥ã«åå ¥ããããå¤ãã®äººãã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§
å¤åºå ã§ã¹ãã¼ããã©ã³ï¼ã¹ããï¼ãã¿ãã¬ããï¼å¤æ©è½æºå¸¯ç«¯æ«ï¼ããã½ã³ã³ãªã©ãã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§ããå ¬è¡ç¡ç·LANãµã¼ãã¹ã®å¢åå³ãå¤ããã¤ã¤ãããã¹ããã®ãããæ¥ç¶ç°å¢ã®æ´åãé²ããæºå¸¯é»è©±äºæ¥è 3社ãå ¬è¡ç¡ç·LANã®è¨ç½®å ´æï¼ã¢ã¯ã»ã¹ãã¤ã³ã=APï¼ãæ°åä¸å±è¦æ¨¡ã«å¢ãã䏿¹ãã¹ãããæ®åãã以åããå ¬è¡ç¡ç·LANãå±éãã¦ãã"èè"äºæ¥è ã®ä¸ã«ã¯æ¤éããã¨ãããåºå§ãã¦ãããã©ã¤ããã¢ããå±±æç·å ã«ãã¼ãçããã
æ¥æ¬éä¿¡ã¯6æ14æ¥ã4Gã¢ãã¤ã«ã«ã¼ã¿ãb-mobile4G WiFi2 100æ¥ããã±ã¼ã¸ãã6æ16æ¥ã«çºå£²ããã¨çºè¡¨ããã b-mobile4G WiFi2ã¯ã3Gåç·ã¨LTEã«å¯¾å¿ããã¢ãã¤ã«ã«ã¼ã¿ãä¾¡æ ¼ã¯3ä¸2800åã§ã100æ¥éã¾ãã¯10Gãã¤ãã«éããã¾ã§å©ç¨ã§ããã100æ¥çµéå¾ãSIMãè²·ãæ¿ãããã¨ã§ãb-mobile4G WiFi2ã®ç¶ç¶å©ç¨ãå¯è½ã ã ãµã¤ãºã¯é«ãç´99mmÃå¹ ç´55.3mmÃåãç´11.2mmã§ãééã¯ç´95gãã«ã©ã¼ã¯ãã¼ã¬ã³ãã£ã¼ã¬ãããã¢ã¤ãªãã·ã¥ã°ãªã¼ã³ããã¤ã¤ã«ãã«ã¼ããã¼ã«ãã¯ã¤ãã®4è²ãç¨æããã
NTTããã¼ããã³ããã©ãããã©ã¼ã ï¼NTTBPï¼ã¨NTTè¥¿æ¥æ¬ã¯2012å¹´4æ23æ¥ãç¦å²¡å¸ã2012å¹´4æ27æ¥ã«æä¾ãéå§ããå ¬è¡ç¡ç·LANãµã¼ãã¹ãFukuoka City Wi-Fiãã«ã¤ãã¦ãNTTBPãéå¶ãåè¨ããã¨çºè¡¨ãããNTTè¥¿æ¥æ¬ã®ãã¬ããå ãæ´»ç¨ããç¦å²¡å¸ã¨ã¨ãã«èªæ²»ä½ã«ãããå ¬è¡ç¡ç·LANãµã¼ãã¹ã®æ°ããªå©ç¨ã¢ãã«ãå±éããã åãµã¼ãã¹ã¯ç¦å²¡å¸ãé½å¸ã®é åããã³é½å¸éç«¶äºåã®åä¸ãç®æããï¼1ï¼æµ·å¤ããã®æ è¡å®¢ãªã©æ¥è¨ªè ã«å¯¾ããå©ä¾¿æ§ã®åä¸ãï¼2ï¼æ å ±çºä¿¡åã®å¼·åãï¼3ï¼ç½å®³æã®æ´»ç¨ââãç®çã¨ãã¦æ´åãããå°ä¸éå ¨é§ ãå¸å½¹ææ¬åºè1Fã»è¥¿å´ãµãããåºå ´ãªã©ã«ãç¡æã§ç¡ç·LANãå©ç¨ã§ããç°å¢ãç¦å²¡å¸ãæä¾ä¸»ä½ã¨ãªã£ã¦ç¨æããã å ·ä½çã«ã¯æ¥è¡è ã®å©ä¾¿æ§åä¸ãç®çã«ã1åããã15åéãæ¥ç¶åæ°ã¯ç¡å¶éã§ç¡æã¤ã³ã¿ã¼ãããæ¥ç¶ãæä¾ãããä»å¾ç¦å²¡å¸ã®æ å ±çºä¿¡å
宿°å ±åã§ã®è¨ªæ¥å¤å½äººåãã®ããªã¼Wi-Fiç°å¢æ´åæ¨é²ãç®çã¨ãã¦ãå¹³æ24年度ããæä¾ãã¦ããç¡æå ¬è¡ç¡ç·LANãµã¼ãã¹ãFukuoka City Wi-Fiãã«ã¤ãã¾ãã¦ã¯ãWi-Fiã®æ®åç¶æ³ãWi-Fiãµã¼ãã¹ã®å¤æ§åãéä¿¡ç°å¢ã®å¤åçãè¸ã¾ãã令åï¼å¹´ï¼æ31æ¥(æææ¥)ããã¡ã¾ãã¦ããµã¼ãã¹ãçµäºãããã¾ããã åæ½è¨ã«ãããä»å¾ã®Wi-Fiãµã¼ãã¹ã«ã¤ãã¾ãã¦ã¯ãããããã®æ½è¨ã¸ãååããã ããã
ã¦ã£ã«ã³ã ã¨ã¦ã£ã«ã³ã æ²ç¸ã¯4æ12æ¥ãã»ã¤ã³ã¼ã¤ã³ã¹ãã«è£½PHS端æ«ãPORTUSï¼WX02Sï¼ãã4æ26æ¥ã«çºå£²ããã¨çºè¡¨ããã3Gãã¼ã¿éä¿¡ãµã¼ãã¹ãULTRA SPEEDãã使ã£ãWi-Fiã«ã¼ã¿æ©è½ã®ã»ããPHSã«ããé話æ©è½ãå©ç¨ã§ããã 700mAhã®å¤§å®¹éããããªãæè¼ããWi-Fiã«ã¼ã¿ã¨ãã¦é£ç¶éä¿¡ç´4æéãPHSé»è©±æ©ã¨ãã¦é£ç¶é話ç´14æéãé£ç¶å¾ ã¡åãç´50æ¥ã«å¯¾å¿ãã¦ããããµã¤ãºã¯å¹ ç´124mmÃé«ãç´50mmÃåãç´15mmã§ãééã¯ç´120gãã«ã©ã¼ã¯ãã¯ã¤ãããã©ãã¯ããã«ã¼ã®3è²ã ä¾¡æ ¼ã¯ãW-VALUE SELECTãã§ä¸æ¬è³¼å ¥ããå ´åã3ä¸5520åãæ¯æã®å©ç¨æéããæå¤§24ã«æä¸å®éé¡ãå²ãå¼ããW-VALUEãå²å¼ãé©ç¨ããã¨è² æ é¡ã¯å®è³ª1ä¸2000åã¨ãªããæéã³ã¼ã¹ã¯ãã¦ã£ã«ã³ã ãã©ã³Wããé©ç¨ããã
ãã¤ã³ãã«ã¼ãä¸è¦§ ãã¤ã³ããããã ãè²·ä¸ããã¤ã³ã ãã¼ãã¹ãã¤ã³ã ãã¤ã³ããã¤ãã ã試ãå¼æå¸ ç¹å ¸ã³ã¼ã¹ ç°å¢ç¤¾ä¼è²¢ç®ã³ã¼ã¹ JALãã¤ã«ã¨äº¤æ Pontaã«ã¼ãã«ã¤ã㦠Pontaã«ã¼ãã¨ã¯ ãã¼ã½ã³Pontaã«ã¼ãå ¥ä¼ Pontaææºä¼æ¥ï¼Ponta.jpã¸ï¼ dãã¤ã³ãã«ã¼ãã«ã¤ã㦠dãã¤ã³ãã«ã¼ãã¨ã¯ï¼dpoint.docomo.ne.jpã¸ï¼ dãã¤ã³ãã«ã¼ãå ¥ä¼ ä¾¿å©ãªãµã¼ãã¹ ãã¤ã³ãç §ä¼ï¼ãã¼ã½ã³IDãã°ã¤ã³ï¼ ãã¼ã½ã³å ¬å¼ã¹ãã¼ããã©ã³ã¢ã㪠ããããµPonta ããããµPontaã«ã¤ã㦠ãµã¼ãã¹ä¸è¦§ éè¡ã»éèãµã¼ãã¹ ãã¼ã½ã³ATM ããããã«ã¼ã ATMã»ä¿éºã®æ å ±ã¯ãã¡ãï¼ å¤è²¨ä¸¡æ¿æ© æ¯æã å©ç¨ã§ãããæ¯ææ¹æ³ ã¬ã¸ãã£ã¼ã¸ åç´ä»£è¡ Ticket Restaurant®ï¼ãã±ããã¬ã¹ãã©ã³ï¼ Apple Pay éµä¾¿ã»å® é ããªããªã¼ãµã¼ãã¹
ç·åçã¯ï¼æ¥ãNTTããã¼ããã³ããã©ãããã©ã¼ã ï¼ï¼¢ï¼°ï¼ããå社ã®å ¬è¡ç¡ç·ï¼¬ï¼¡ï¼®ãµã¼ãã¹ã§ãå©ç¨è ã®åæãå¾ãªãã¾ã¾ãç¹å®ã®ä¼æ¥ã®ãã¼ã ãã¼ã¸ãè¦ãããªãããã«ããã¨ãã¦ãåçºé²æ¢ãæ±ããè¡æ¿æå°ãè¡ã£ãã åé¡ã¨ãªã£ãã®ã¯ãNTTBPããæ±äº¬ï¼ï¼åºå ã®ã»ãã³âã¤ã¬ãã³ãã¤ãã¼ã¨ã¼ã«ãã¼ãªã©ã®åºèã§æ¨å¹´ï¼ï¼æã«æä¾ãå§ããç¡ç·ï¼¬ï¼¡ï¼®ãµã¼ãã¹ã顧客伿¥ã¨ç«¶åé¢ä¿ã«ããã¤ã³ã¿ã¼ãããå°å£²ã大æã®ã¢ãã¾ã³ã¨æ¥½å¤©å¸å ´ã®ãã¼ã ãã¼ã¸ã«æ¥ç¶ã§ããªãè¨å®ã«ãã¦ããã ç·åçã¯ãå©ç¨è ã®åæãªãã«éä¿¡å ããã§ãã¯ãã¦ããç¹ãåé¡è¦ãã黿°éä¿¡äºæ¥æ³ãç¦ãããéä¿¡ã®ç§å¯ãã®ä¾µå®³ã«å½ããã¨å¤æãããNTTBPã¯ãã§ã«ã両社ã®ãã¼ã ãã¼ã¸ã«æ¥ç¶ã§ããªããã¨ã§å©ç¨è ããäºè§£ãå¾ãä»çµã¿ã«æ¹ããã
ç·åçã¯4æ4æ¥ãç¡ç·LANãµã¼ãã¹ãæä¾ããã³ãã¯ãããªã¼ã«å¯¾ãã黿°éä¿¡äºæ¥æ³ç¬¬4æ¡ã«è¦å®ãããéä¿¡ã®ç§å¯ãã侵害ããã¨ãã¦ãè¡æ¿æå°ãè¡ã£ãã ç·åçãã³ãã¯ãããªã¼ããåãã説æã«ããã¨ãå社ã¯ç¡ç·LANãµã¼ãã¹ã®æä¾ã«ä¼´ããå©ç¨è ã«ç¡æã§ç«¯æ«ã®MACã¢ãã¬ã¹ãç¹å®ã®SNSãµã¼ãã¹ã«æ¥ç¶ããéã®IDãªã©ãè¨é²ãä¿åãã¦ããã¨ãããç¯ç½ªãªã©ã«å©ç¨ãããå ´åã«å©ç¨è ãç¹å®ãããªã©ã®çç±ã説æãã¦ããã ç·åçã¯ãéä¿¡ãå©ç¨è ã«ç¡æã§è¨é²ãä¿åãããã¨ã¯éä¿¡ã®ç§å¯ã侵害ãããã®ã¨èªãããããããã³ãã¯ãããªã¼ã«å¯¾ããåçºé²æ¢çãæ©æ¥ã«åãã¾ã¨ãã宿½ç¶æ³ãå ±åããããæå°ãã¦ããã
NTTã°ã«ã¼ãã®ä¼ç¤¾ãæµé大æã¨ææºããé½å ã®ã¬ã¹ãã©ã³ãªã©ã§è¡ã£ã¦ããã¤ã³ã¿ã¼ãããæ¥ç¶ãµã¼ãã¹ã§ãå©ç¨è ã«ç¡æã§ç«¶åããã·ã§ããã³ã°ãµã¤ããªã©ãé²è¦§ã§ããªãããã«ãã¦ãããã¨ãåãããç·åçãåçºé²æ¢ãæ±ããè¡æ¿æå°ãè¡ãã¾ããã è¡æ¿æå°ãåããã®ã¯ãNTTã®é¢é£ä¼ç¤¾ã§ãæ±äº¬ã»ä¸å¤®åºã«æ¬ç¤¾ã®ãããNTTããã¼ããã³ããã©ãããã©ã¼ã ãã§ãã ç·åçãªã©ã«ããã¾ãã¨ããNTTããã¼ããã³ããã©ãããã©ã¼ã ãã¯ãå»å¹´ï¼ï¼æããæµé大æã®ã»ãã³ï¼ã¢ã¤ã»ãã¼ã«ãã£ã³ã°ã¹ã¨ææºããæ±äº¬ï¼ï¼åºã®ãã¡ããªã¼ã¬ã¹ãã©ã³ããã³ã³ããã¨ã³ã¹ã¹ãã¢åããã¦ï¼ï¼ï¼ï¼ãæä½ãã«ç¡ç·ã使ã£ãã¢ã¯ã»ã¹ãã¤ã³ããè¨ç½®ããç¡æã®ã¤ã³ã¿ã¼ãããæ¥ç¶ãµã¼ãã¹ãè¡ã£ã¦ãã¾ãã ãããããNTTããã¼ããã³ããã©ãããã©ã¼ã ãã¯ãææºå ã¨ãµã¼ãã¹ãç«¶åããå¥ã®ï¼ç¤¾ã®ã·ã§ããã³ã°ãµã¤ããªã©ã«ã¤ãã¦ãå©ç¨è ã«ç¡æã§é²è¦§ã§ããªãã
å¹³ç´ ããTSUTAYAããå©ç¨ããã ã ãããã¨ããããã¾ãã 2022å¹´10æ6æ¥ããã¡ã¾ã㦠ãã¡ãã®ãã¼ã¸ã®å ¬éãçµäºããã¦ããã ãã¾ããã å¼ãç¶ããTSUTAYAããã®ããããç¹éã¯ä»¥ä¸ãã¼ã¸ãããæ¥½ãã¿ããã ãã¾ãã ç¹éä¸è¦§ãã¼ã¸ã¸
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}