Its been about a week since the KRACK thing broke, and I finally sat down Sunday night with a beer and a legal pad and went device by device through my apartment. If you havent done this yet, dont feel bad, I hadnt either until three days ago. Everyone wrote the "WPA2 is broken, panic now" post already so Im not going to redo that. What Im going to do is walk through what actually patching your stuff looks like, because its messier than the headlines made it sound.
Quick reminder of what were even dealing with: Mathy Vanhoef found a flaw in how the WPA2 handshake works, basically letting an attacker on your local network trick a device into reinstalling an already-used encryption key. It doesnt mean your neighbor can just waltz onto your wifi from the street. It means a device on your network could get its traffic decrypted or, on some Android and Linux setups, worse. Fine. Now the boring part.
Your router first. This is the one people skip because its annoying. I run a TP-Link Archer C7 I bought for like 90 bucks a couple years back, and TP-Link had a firmware beta up within a few days that patches the client-side reinstallation issue. Logging into the admin panel at 192.168.0.1 to check for a firmware update is not most peoples idea of a Sunday, I get it, but it takes maybe ten minutes including the reboot. If your router is from an ISP and you never touch it, call them. Comcast and the like have been pushing updates on their leased gateways without you doing anything, which for once is actually the correct amount of hand-holding.
Phones next. My Pixel 2 already had this covered out of the box since it shipped with the October security patch baked in, so that ones a non-issue for me, lucky timing. My wife's phone is a different story. Its an old Nexus 5 shes refused to replace because "it still works fine," and its stuck two Android versions behind with zero chance of ever seeing this patch. That phone is basically permanently vulnerable now unless she upgrades, and no amount of me nagging her about it has worked in eighteen months so I doubt tonight's the night either. This is the actual ugly part of the Android patching story that doesnt get said enough: a huge chunk of phones out there are just never getting fixed, full stop, and its not really the owners fault.
Laptops. Windows machines were mostly already covered because Microsoft quietly shipped the fix back in the October 10th Patch Tuesday, before the public disclosure even happened, which in hindsight was a pretty smart bit of coordination. Macs needed the latest update Apple pushed out. If youre on a random Linux distro, check whether your wpa_supplicant package has been updated, its usually a one-line apt command.
Now the stuff nobody talks about. I've got two Wemo smart plugs and a set of cheap smart bulbs I bought off some no-name brand on a whim last Christmas, and I genuinely have no idea if any of that will ever see a firmware fix. I checked the Wemo app, no update listed. The bulbs dont even have a changelog anywhere I can find. This is the part that actually bugs me more than the router stuff, because at least a router is a device I understand and can reflash myself. A lightbulb with wifi in it that nobody is going to patch in six months, let alone two years from now, is a genuinely dumb thing to have plugged into my network, and I bought it anyway because it was on sale. Thats on me I guess.
If youre doing this same walkthrough tonight, dont expect it to be a clean pass. Youll get through the router and your main phone feeling pretty good about yourself, and then youll hit some ancient tablet in a drawer or a smart plug from a company that may not even exist anymore, and youll just have to shrug and either unplug it or accept the risk. I unplugged the bulbs. The plugs I'm leaving on for now because turning my desk lamp on from my phone is apparently a hill Im willing to die on.