Page 1 of 1

Key reinstallation attacks vulnerability

Posted: Wed Oct 25, 2017 5:24 pm
by Pio
Hi,

Is the current version of Micropython firmware for ESP8266 vulnerable to key reinstallation attacks (KRACK)? I noticed that espressif have released an update for some sdks on github.

Joe

Re: Key reinstallation attacks vulnerability

Posted: Fri Nov 03, 2017 12:47 pm
by jcea
I have the same question. Is Micropython 1.9.3 release safe?.

Re: Key reinstallation attacks vulnerability

Posted: Sat Nov 04, 2017 11:43 pm
by pfalcon
Alpha patches for building MicroPython with SDK version which vendor marked as resolving the key reinstallation vulnerability is available: https://github.com/micropython/micropyt ... -341937988 .