So today's the day everyone with a wifi router is supposed to be mildly panicking, and I have to say, mission accomplished. The KRACK vulnerability dropped this morning (Key Reinstallation Attack, cooked up by a researcher named Mathy Vanhoef out of a Belgian university) and it basically means WPA2, the encryption every one of us has been trusting since roughly forever, has a hole in it. Not a "someone left a door unlocked" hole. More like the lock mechanism itself can be tricked into handing out a spare key if an attacker's close enough and patient enough.
I'm not going to walk you through the cryptographic handshake stuff, partly because there are already about four hundred posts doing that better than I could by lunchtime, and partly because what actually ate my evening wasn't the crypto. It was the depressing inventory of everything on my home network that I now have to go individually chase down and patch, one device at a time, like some kind of unpaid IT department for a household of one.
Here's what I've got connected right now, more or less: a laptop, a work laptop, two phones, a Chromecast, a printer that hasn't seen a firmware update since I bought it in 2014, a smart plug I bought on a whim for $19 that turns a lamp on and off, and the router itself, which is a TP-Link Archer thing I've had for about three years and never once logged into the admin panel of after initial setup. Guilty as charged.
The laptops were easy. Ubuntu had a patch basically same-day because Linux distros move fast on this stuff, and I imagine Windows and macOS won't be far behind (Microsoft apparently already pushed something out earlier this month before today's public disclosure, which is a neat trick: coordinated disclosure meant vendors got a heads up back in the summer). Android is the mess. My phone's on 7.1 and Google's patch is going out to Pixels and Nexus devices first, which means everyone on some Samsung or LG skin from two years ago is just going to sit there vulnerable for weeks or months, if they get it at all. That's not a KRACK problem specifically, that's just the whole Android update situation, which has been broken for years and nobody with the power to fix it seems to care enough.
The printer and the smart plug are the ones that actually got me annoyed. Neither is ever getting a security patch. Not this month, not ever. The printer's manufacturer stopped supporting that model's firmware a while back, and the smart plug is one of those white-label things from a company I couldn't even name off the top of my head: it showed up on Amazon, had a Chinese app with broken English in the settings menu, and I bought it because it was cheaper than the Wemo one. That's the real story under all of this, honestly. It's not really about whether Apple or Google patch fast (they mostly will). It's about the pile of cheap, forgettable IoT junk that quietly accumulates in a house over a few years, none of which anyone is thinking about updating, most of which nobody even remembers is still plugged in.
The actual practical risk for most people is lower than the headlines make it sound, for what it's worth. An attacker needs to be within physical wifi range, and a lot of the traffic that matters (banking sites, anything over HTTPS) has its own layer of encryption on top that KRACK doesn't touch. It's bad, it's a legitimate flaw in something huge numbers of devices rely on, but it's not "delete your wifi and move to the woods" bad. Use a VPN if you're on public wifi and paranoid, keep patching what you can, and maybe don't check your bank balance from the coffee shop tonight if you can help it.
I did finally log into that router admin panel, by the way. Changed the admin password from the default, which, in 2017, three years after setup, is a genuinely embarrassing thing to admit. No firmware update available for it yet. I'll check again this weekend. Or next weekend. We'll see how the week goes.