Skip to Content
  • mail
  • blackboard
  • youtube
  • facebook
  • PowerCampus
Taint●Wisdom●Commitment
Normal Contrast
Font SizeDown Arrow
Medium

ENG
Down Arrow
IT security alert of Wi-Fi Protected Access II (WPA2) Multiple Vulnerabilities (KRACK) on 17 October 2017.
17/10/2017
Dear Staff and Students,

 

This is the IT security alert of Wi-Fi Protected Access II (WPA2) Multiple Vulnerabilities (KRACK) on 17 October 2017.

 

Multiple vulnerabilities were identified in Wi-Fi Protected Access II (WPA2) which could allow an attacker to conduct a key reinstallation attack (KRACK) on targeted devices that use WiFi. An attacker could decrypt the data or even conduct data tampering in the wireless connection.

 

To successfully conduct the attack, an attacker has to be within the wireless communication range of the Wi-Fi access point (AP) and the targeted device.

 

Impact
Information Disclosure
Data Manipulation

 

System / Technologies Affected
Wi-Fi enabled devices

 

Alert from Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT)
https://www.hkcert.org/my_url/en/alert/17101701

 

Actions taken by ITSO
1. Installed patches on college wireless computer.
2. Updated latest Firmware for all WiFi Access point in the College

 

Recommendations to Staff and Students
1. Install the latest patches on your wireless devices (e.g. smartphone, laptop, home wireless router). Vendors are rolling out patches and firmware updates. Please refer to the vendor’s information or the following vulnerability notice: https://www.kb.cert.org/vuls/id/228519 .
For Microsoft Windows device, please apply Microsoft October 2017 Security Updates through Windows update.
Microsoft October 2017 Security Updates addresses one of several vulnerabilities found in WPA2 via issuing a patch for CVE-2017-13080
https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/313ae481-3088-e711-80e2-000d3a32fc99

 

2. Use HTTPS to encrypt sensitive information.
Always check to make sure there’s a green lock icon in the address bar of your browser. That lock indicates that an HTTPS (encrypted and therefore secure) connection to this particular website is being used. If someone attempts to use SSLstrip against you, the browser will be forced to use HTTP versions of websites, and the lock will disappear. If the lock is in place, your connection is still secure.
https://www.kaspersky.com/blog/krackattack/19798/

 

3. Don’t use public Wi-Fi to handle sensitive information. Consider using a trusted wired connection or mobile data network.

 

For enquiry please contact ITSO hotline at 3190 6640 or email to itso@twc.edu.hk.

 

Regards,
Information Technology Service Office

 

Tung Wah College
Tower B, 9F, 98 Shantung St., Mongkok, Kowloon, Hong Kong
Rm1004, 31 Wylie Road, Homantin, Kowloon, Hong Kong




Tung Wah College Logo
King’s Park Campus
31 Wylie Road, Homantin, Kowloon, Hong Kong
Mongkok Campus
Nos. 90A & 98, Shantung Street, Mongkok,
Kowloon, Hong Kong
Telephone
(852) 3190 6678
Email
enquiry@twc.edu.hk