Slashdot Mirror


Every Patch For 'KRACK' Wi-Fi Vulnerability Available Right Now (zdnet.com)

An anonymous reader quotes a report from ZDNet: As reported previously by ZDNet, the bug, dubbed "KRACK" -- which stands for Key Reinstallation Attack -- is at heart a fundamental flaw in the way Wi-Fi Protected Access II (WPA2) operates. According to security researcher and academic Mathy Vanhoef, who discovered the flaw, threat actors can leverage the vulnerability to decrypt traffic, hijack connections, perform man-in-the-middle attacks, and eavesdrop on communication sent from a WPA2-enabled device. In total, ten CVE numbers have been preserved to describe the vulnerability and its impact, and according to the U.S. Department of Homeland Security (DHS), the main affected vendors are Aruba, Cisco, Espressif Systems, Fortinet, the FreeBSD Project, HostAP, Intel, Juniper Networks, Microchip Technology, Red Hat, Samsung, various units of Toshiba and Ubiquiti Networks. A list of the patches available is below. For the most up-to-date list with links to each patch/statement (if available), visit ZDNet's article.
Apple: The iPhone and iPad maker confirmed to sister-site CNET that fixes for iOS, macOS, watchOS and tvOS are in beta, and will be rolling it out in a software update in a few weeks.

Arris: a spokesperson said the company is "committed to the security of our devices and safeguarding the millions of subscribers who use them," and is "evaluating" its portfolio. The company did not say when it will release any patches.

Aruba: Aruba has been quick off the mark with a security advisory and patches available for download for ArubaOS, Aruba Instant, Clarity Engine and other software impacted by the bug.

AVM: This company may not be taking the issue seriously enough, as due to its "limited attack vector," despite being aware of the issue, will not be issuing security fixes "unless necessary."

Cisco: The company is currently investigating exactly which products are impacted by KRACK, but says that "multiple Cisco wireless products are affected by these vulnerabilities."

"Cisco is aware of the industry-wide vulnerabilities affecting Wi-Fi Protected Access protocol standards," a Cisco spokesperson told ZDNet. "When issues such as this arise, we put the security of our customers first and ensure they have the information they need to best protect their networks. Cisco PSIRT has issued a security advisory to provide relevant detail about the issue, noting which Cisco products may be affected and subsequently may require customer attention.

"Fixes are already available for select Cisco products, and we will continue publishing additional software fixes for affected products as they become available," the spokesperson said.

In other words, some patches are available, but others are pending the investigation.

Espressif Systems: The Chinese vendor has begun patching its chipsets, namely ESP-IDF and ESP8266 versions, with Arduino ESP32 next on the cards for a fix.

Fortinet: At the time of writing there was no official advisory, but based on Fortinet's support forum, it appears that FortiAP 5.6.1 is no longer vulnerable to most of the CVEs linked to the attack, but the latest branch, 5.4.3, may still be impacted. Firmware updates are expected.

FreeBSD Project: There is no official response at the time of writing.

Google: Google told sister-site CNET that the company is "aware of the issue, and we will be patching any affected devices in the coming weeks."

HostAP: The Linux driver provider has issued several patches in response to the disclosure.

Intel: Intel has released a security advisory listing updated Wi-Fi drives and patches for affected chipsets, as well as Intel Active Management Technology, which is used by system manufacturers.

Linux: As noted on Charged, a patch is a patch is already available and Debian builds can patch now, while OpenBSD was fixed back in July.

Netgear: Netgear has released fixes for some router hardware. The full list can be found here.

Microsoft: While Windows machines are generally considered safe, the Redmond giant isn't taking any chances and has released a security fix available through automatic updates.

MikroTik: The vendor has already released patches that fix the vulnerabilities.

OpenBSD: Patches are now available.

Ubiquiti Networks: A new firmware release, version 3.9.3.7537, protects users against the attack.

Wi-Fi Alliance: The group is offering a tool to detect KRACK for members and requires testing for the bug for new members.

Wi-Fi Standard: A fix is available for vendors but not directly for end users.

140 comments

  1. Linux Mint by Trax3001BBS · · Score: 1

    I just updated the WiFi exploit and Adobe flash for it. They have my back covered.

    1. Re:Linux Mint by Anonymous Coward · · Score: 0

      My Windows update took care of this automagically. No worries.

    2. Re:Linux Mint by Anonymous Coward · · Score: 0

      We filthy Linux users have automatic updates too. Except our filthy OS uses package repos that allow us to patch everything automagically not just Adobe Flash and the OS...which granted is a large chunk of bugs.

    3. Re:Linux Mint by Anonymous Coward · · Score: 0

      The coverage on this issue is interesting. The paper detailing the vulnerabilities clearly states all WiFi clients implementing WPA/WPA2 are affected by these key reinstallation attacks-iOS 10.3.1, Windows 7, and Windows 10 being more difficult to exploit than others. This gets conflated into "Windows is generally safe" in the ZDnet article, though it looks like it's really only safe if the October 10 update was applied. I've yet to find any evidence it's not a concern for those still using Windows 8, or (god help us--there's still tons of them out there) Vista or XP. Surely there are bigger problems lurking for anyone using these, but there seems to be a misleading "Windows is safe" mantra emerging among web comments.
      I use Debian, and happened to have the security update automatically applied through a cron task before I read about the problem. But I would like to know: how does Windows handle these wireless connections, anyway? That is, are they handled at a fairly low level in the operating system? Because I can't remember the last time a relative got a new Windows laptop and I didn't have to help them mediate an epic struggle between the Windows' network controls and some god awful OEM or Intel supplied utility that tries to manage wireless connections. On *nix, everything I've used lately has wpasupplicant, but in theory we could use another package to handle WPA2 connections. Is it the same on Windows? Are these OEM installed utilities potentially problematic wireless clients? Or do they just slap a branded gui over the OS controls?

    4. Re:Linux Mint by Zontar+The+Mindless · · Score: 1

      Looks like OpenSUSE also has updates for both issues now available.

      --
      Il n'y a pas de Planet B.
    5. Re: Linux Mint by Anonymous Coward · · Score: 0

      And yet, somehow, it is still one of the best disros out there.

    6. Re:Linux Mint by r1348 · · Score: 1

      Same on Fedora.

    7. Re:Linux Mint by Gr8Apes · · Score: 1

      AFAIK, they're GUI controls ontop of the OS libraries, usually. Sometimes, they slap an additional configuration library ontop to control their hardware, but generally this is not needed. In fact, whenever a relative mentions they've installed the latest sadistic utility, my first move is to remove said "utility" and just go through whatever their version of windows pain inflicts. I should note that none of these folks run Win10, so I have close to 0 experience with that version's wireless connectivity.

      --
      The cesspool just got a check and balance.
  2. Better list by Anonymous Coward · · Score: 0

    There's a more complete list on Bleeping Computer. Too lazy to share the link. Saw it earlier today

    1. Re:Better list by olsmeister · · Score: 5, Informative
  3. Open BSD Linux ... WTF by Zero__Kelvin · · Score: 2

    I love how the section on Linux patch availability talks about one of the BSDs. Always good to hear about your mission critical patches from people who don't know the difference.

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    1. Re:Open BSD Linux ... WTF by iggymanz · · Score: 2

      well I do love how OpenBSD already fixed this months ago

    2. Re:Open BSD Linux ... WTF by Anonymous Coward · · Score: 5, Informative

      well I do love how OpenBSD already fixed this months ago

      The discoverer of the vulnerability states on his website that openbsd (Theo Radt) broke the embargo in July. Not much to love with that, since it reduced the security of everybody else. You will notice that most everybody else (Google seems to have been asleep), had patches ready _today_. This was when the embargo was lifted.

      Going to the discoverer's site ( https://www.krackattacks.com/ ) last night got you a page that said, "just a test that domain name and webserver are working." Unlike Theo, he was honoring the embargo-- this morning, he posted info about the exploit on that website.

    3. Re: Open BSD Linux ... WTF by Anonymous Coward · · Score: 0

      Theo The Rat is a known asshole.

    4. Re:Open BSD Linux ... WTF by AmiMoJo · · Score: 1

      I guess it's hard to patch a vulnerability in an open source project without advertising that it exists. In the case of other OS projects with zero-day fixes they kept the patches quieter, but I'm sure people who were paying attention noticed.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    5. Re: Open BSD Linux ... WTF by Anonymous Coward · · Score: 1

      Yeah, a 4 month embargo.
      At least they had time to make a cool Krack logo.

      I suggest the next person that find a vulnerability just drops it and runs.

    6. Re:Open BSD Linux ... WTF by CrAlt · · Score: 2

      Not much to love with that, since it reduced the security of everybody else.

      Why should Theo wait around for everyone else and leave his users vulnerable? An embargo for a few business days after notifying sure. But for MONTHS?

      Does anyone really think this flaw didn't leak out to the bad guys from one of the vendors the second they where notified?

      --
      I have to return some videotapes...
    7. Re:Open BSD Linux ... WTF by swillden · · Score: 1
      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    8. Re:Open BSD Linux ... WTF by thegarbz · · Score: 1

      Why should Theo wait around for everyone else and leave his users vulnerable?

      The whole point of an embargo is to maximize security. OpenBSD users weren't vulnerable. Until yesterday only a very select few people even knew how to perform the attack. On the flip side Theo by breaking the embargo not only made other users vulnerable, but also his own given that most of them probably wouldn't have considered the urgency of patching before it hit international news.

      But for MONTHS?

      You're not talking about a bug in Chrome here. We're talking about a but in WiFi affecting every OS and many millions of embedded devices as well as network devices. Again the length of time was chosen to maximise safety for users, not the other way around.

      Does anyone really think this flaw didn't leak out to the bad guys from one of the vendors the second they where notified?

      Well yes, unless the bad guys were using OpenBSD in which case we all know exactly who to blame.

    9. Re:Open BSD Linux ... WTF by swillden · · Score: 1

      well I do love how OpenBSD already fixed this months ago

      The discoverer didn't love it. In fact, in the Q&A on his web site he says: "To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo."

      If OpenBSD doesn't honor embargoes, OpenBSD will not be informed of vulnerabilities until shortly before the public release. Hopefully, researchers are able to accurately guess how long it will take OpenBSD to release a fix. If they find guessing accurately to be too hard, they'll just have to be conservative -- possibly not giving OpenBSD any advance notice at all.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    10. Re:Open BSD Linux ... WTF by Anonymous Coward · · Score: 0

      If OpenBSD doesn't honor embargoes,

      "Hey I found a flaw in your OS. I am also telling shittons of other people about it. Please respect my embargo and not fix it for 6 months. ok thanks"

    11. Re:Open BSD Linux ... WTF by swillden · · Score: 2

      If OpenBSD doesn't honor embargoes,

      "Hey I found a flaw in your OS. I am also telling shittons of other people about it. Please respect my embargo and not fix it for 6 months. ok thanks"

      Yep.

      The alternative is "Hey I found a flaw in your OS six months ago and told shittons of other people about it. I'm publishing it tomorrow. I didn't tell you earlier because you don't honor embargoes."

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    12. Re:Open BSD Linux ... WTF by jofas · · Score: 2

      The _real_ point of an embargo is to allow those businesses participating in the embargo to save face. The embargo does not serve the user. Theo could have specifed that his patch was simply good practice, which is true. He did not advertise the reason for the patch either.
      Besides, patching one system does not magically make the others vulnerable. They were already vulnerable.
      On all counts, your argument has no leg to stand on, and yet we continue to allow this horseshit that vendors release vuln information like it's a fucking media event with previews and trailers.

      Stop encouraging the koolaid-drinking.

    13. Re:Open BSD Linux ... WTF by Anonymous Coward · · Score: 0

      Month-long embargoes don't seem like they would be viable to me at all. Whoever tries to set up something like that should expect to be sued by anyone who is compromised during the embargo period.

    14. Re:Open BSD Linux ... WTF by Anonymous Coward · · Score: 0

      Chances are OpenBSD would have found out about it anyways since its hard to keep a secret when shittons of people know. Look at all the people they notified in July. This was in the wild on day 1.
      Being held up on a security patch for months because of majors dragging their feet is ridiculous.
      Its not like criminals would honer any "embargo".

    15. Re:Open BSD Linux ... WTF by epine · · Score: 1

      The alternative is "Hey I found a flaw in your OS six months ago and told shittons of other people about it. I'm publishing it tomorrow. I didn't tell you earlier because you don't honor embargoes."

      Only not if five months beforehand, Theo already issues a patch without having been on the original distribution list, via a thumb-sized hole in the shitton dike.

      He can't be the only security professional out there convinced to his very marrow that six months is a total crock.

    16. Re:Open BSD Linux ... WTF by swillden · · Score: 1

      The alternative is "Hey I found a flaw in your OS six months ago and told shittons of other people about it. I'm publishing it tomorrow. I didn't tell you earlier because you don't honor embargoes."

      Only not if five months beforehand, Theo already issues a patch without having been on the original distribution list, via a thumb-sized hole in the shitton dike.

      He can't be the only security professional out there convinced to his very marrow that six months is a total crock.

      Six months is long, but probably a good idea in this case, because a lot of affected systems are hard to patch.

      But regardless of what you think of the duration, violating embargoes is a very good way to get actively excluded from notification.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    17. Re:Open BSD Linux ... WTF by iggymanz · · Score: 1

      no, you have defective logic. bug fixes that don't happen for months lessen security, you are a shill for the lazy and incompetent. no one has to respect the wishes of such

  4. Gibberish by Anonymous Coward · · Score: 0

    Linux: As noted on Charged, a patch is a patch is already available and Debian builds can patch now, while OpenBSD was fixed back in July

    Makes mental note to never even look up what 'Charged' is.

  5. You only need to patch the CLIENT by Anonymous Coward · · Score: 4, Interesting

    Just to be clear, you probably only need to patch the client devices, not the wireless access points. In particular, https://www.krackattacks.com says the following:

    Our main attack is against the 4-way handshake, and does not exploit access points, but instead targets clients. So it might be that your router does not require security updates. ... For ordinary home users, your priority should be updating clients such as laptops and smartphones.

    1. Re:You only need to patch the CLIENT by billrp · · Score: 2, Informative

      Or patch the router to protect those clients that have not yet been patch.

    2. Re:You only need to patch the CLIENT by Anonymous Coward · · Score: 1

      Yeah. I wouldn't spread this idea about not patching the APs. For people with older Android phones it may be their best[only] option.

    3. Re:You only need to patch the CLIENT by Anonymous Coward · · Score: 2, Informative

      NO! Read what you responded to (and the link): the exploit does not target access points, only clients. Patching the access point doesn't do anything unless the AP itself is a client to another AP. An unpatched client on a patched AP is still 100% vulnerable.

      Patch your clients!

    4. Re:You only need to patch the CLIENT by Anonymous Coward · · Score: 1

      NO! Read what you responded to (and the link): the exploit does not target access points, only clients. Patching the access point doesn't do anything unless the AP itself is a client to another AP. An unpatched client on a patched AP is still 100% vulnerable.

      Patch your clients!

      I thought if either the client or the AP is patched, then neither is vulnerable. Where are you getting that unpatched clients on a patched AP are still vulnerable?

    5. Re:You only need to patch the CLIENT by Anonymous Coward · · Score: 0

      Ideally you patch both, but in the circumstance it isn't possible to patch clients (e.g., no longer supported by the vendor), and the access point is patchable, is it actually useless to patch your AP? I know the vulnerability still exists in the client and could be exploited, but if you're only connecting to a given AP (e.g., at home), and that AP is patched, won't *that* connection be safe? Or is there still a way to highjack the client?

    6. Re: You only need to patch the CLIENT by Anonymous Coward · · Score: 0

      You cant patch the router to keep the client from doing something stupid.

    7. Re:You only need to patch the CLIENT by Anonymous Coward · · Score: 0

      easier to patch the routers if you have any firmware updates. In the end you need to make sure all devices are patched.

  6. What about your APs, Apple? by Anonymous Coward · · Score: 1

    So when is Apple going to patch their router hardware?

    Tim Cook may have forgotten that Apple sells wifi APs, but I haven't.

    1. Re: What about your APs, Apple? by Anonymous Coward · · Score: 0

      Why don't you ask Apple.

    2. Re: What about your APs, Apple? by Anonymous Coward · · Score: 0

      It takes courage to leave your hardware unpatched.

    3. Re: What about your APs, Apple? by Anonymous Coward · · Score: 0

      According to imore.com the Apple routers were not vulnerable to begin with.

  7. Re: Trump is affected by CRACK vulnerability by Anonymous Coward · · Score: 0

    My labor belongs to nobody but me.

  8. What about DD-WRT, Tomato and the others by williamyf · · Score: 2

    Yup, what about them?

    Well, in a reasonably quality article (on windows central), linked from the Crappy article linked on the front page of Slashdot (as ussual), they had the info for DD-WRT and LEDE (OpenWRT). It turns out that the Source has been modified already, but no firmware images produced yet.

    Now, is just wait and see.

    Here is the more decent article:
    https://www.windowscentral.com...

    --
    *** Suerte a todos y Feliz dia!
    1. Re:What about DD-WRT, Tomato and the others by Anonymous Coward · · Score: 0

      There was a comment about this on the DDWRT forum. apparently there is already a patch committed. so whenever they get to running the script to compile the new build for every router most likely

    2. Re:What about DD-WRT, Tomato and the others by Anonymous Coward · · Score: 0

      http://svn.dd-wrt.com/changeset/33525

      My guess with something this high profile they are probably in the building process now.

      Keep an eye on ftp://ftp.dd-wrt.com/betas/2017/ for an updated release

    3. Re:What about DD-WRT, Tomato and the others by drinkypoo · · Score: 1

      Hooray for OpenWRT. My WRT1200AC awaits a build.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    4. Re:What about DD-WRT, Tomato and the others by fisted · · Score: 1

      Sorry to break it to you, but the general consensus seems to be "Migrate to LEDE, OpenWRT is dead". Your APs better have enough RAM and storage.
      (That said, I'm running 15 OpenWRT APs myself, fun times ahead...)

    5. Re:What about DD-WRT, Tomato and the others by Morris+von+Habsburg · · Score: 1

      For people on LEDE:
      As the issue is mainly client side (such as when a router acts as a client of another router), two of the three fixes are in packages that can be updated without updating the whole firmware (or even rebooting the router). Updating wpad and hostapd should update them to version xxx-5 which fixes the issue.

      There is also a kernel level fix that is going through the motions and will most likely mean 17.01.4 is out soon.

      https://forum.lede-project.org...

    6. Re:What about DD-WRT, Tomato and the others by drinkypoo · · Score: 1

      Sorry to break it to you, but the general consensus seems to be "Migrate to LEDE, OpenWRT is dead". Your APs better have enough RAM and storage.

      336 Linksys WRT1200AC v1 (caiman), v2 (caiman) 17.01.3 https://wiki.openwrt.org/toh/l...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    7. Re:What about DD-WRT, Tomato and the others by fisted · · Score: 3, Informative

      From your link:

      Official OpenWrt support for the WRT AC Series began under Chaos Calmer, with the LEDE Branch being the recommended Branch for the WRT AC Series

      OpenWrt has not been actively maintained for the better part of a year and is no longer recommended for utilization.
      Last major commits for OpenWrt were close to a year ago, and as such, LEDE is recommended for utilization.

    8. Re:What about DD-WRT, Tomato and the others by drinkypoo · · Score: 1

      My snippet was copied from https://lede-project.org/toh/s... so I'm doing OK here. I just haven't updated to lede yet. I am currently using an unofficial fork which has been updated more recently than two years ago, but not much.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    9. Re:What about DD-WRT, Tomato and the others by eguaj · · Score: 1

      Looks like OpenWRT will release a Chaos Calmer 15.05.1a (or 15.05.2) with fixes for dropbear, *ssl, dnsmasq, and hostapd binaries : https://forum.openwrt.org/view...

    10. Re:What about DD-WRT, Tomato and the others by fisted · · Score: 1

      Awesome, thank you SO much for that information!

      (I spent the better part of today repeatedly bricking and unbricking a WRT1900ACS v2 in the attempt to migrate it from OpenWRT to LEDE and was literally just looking for my TTL-UART and JTAG programmer to bring in to work tomorrow to take it to the next level.)
      You saved me a bunch of work!

  9. Mitigation by manu0601 · · Score: 1

    One information I did not find is the status when the WPA supplicant is vulnerable and the AP is fixed. Is attack possible in that setup?

    Also, WPA enterprise often use EAP/TTLS for authentication. KRACK seems unable to compromise what happens inside the TLS tunnel. Is that the case?

    1. Re:Mitigation by Morris+von+Habsburg · · Score: 1

      An attack is still possible. The attack is on vulnerable clients that are tricked into connecting to a rogue AP that is made to look exactly like your existing AP. Whether your AP is fixed or not doesn't matter as it can't stop the rogue AP from showing up. Once your vulnerable client connects to the rogue AP it can be attacked.

      Considering your AP is not often a client too (client side is where the real issue is) and you rarely take your AP to other public places they are not the highest priority. The highest priority at the moment are clients like phones, tablets and laptops. They are more likely to go to places where someone might be running a rogue AP.

    2. Re:Mitigation by Anonymous Coward · · Score: 1

      The AP's can listen in on the rogues and figure out what's going on. At that point that can issue deauth's to disrupt it and force re-auths.

    3. Re:Mitigation by manu0601 · · Score: 1

      When using EAP-TTLS, there is a TLS handshake where the WPA supplicant has the opportunity to validate the authenticating server through a x509 certificate. That extra layer is not easy to break.

  10. I've always had the cure here... apk by Anonymous Coward · · Score: 1, Informative

    See subject: I don't USE that shit here @ home - wireless is for those who are NOT security-conscious or just ignorant of its track-record (like encryption is) - sooner or later, it's permeable, period.

    * Am I bullshitting anyone here?

    APK

    P.S.=> I trust CABLES (shielded if/when possible) over 'wireless' by far (besides, copper's a FAR better conduit for signal than aerial beaming (wireless drops packets like mad vs. hardwired)- especially on TCP/IP protocols (TCP part demands 2-way handshakes, UDP doesn't) & TCP is in use - think about all this & decide for yourself (I did - & I don't need laptops/tablets etc. in every room so why use something KNOWN to be 'shaky' & on BOTH security + reliability of signal concerns for? So it made no sense to me @ all using it)... apk

    1. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 1

      Yeah but it's pretty safe to say that if anyone did tap your wires, they'd hit the disconnect button in a matter of seconds.

      Then facepalm realizing they could have simply logged on to /. and browsed at -1 to see your life history...

    2. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 0

      Yes, your are spreading BS i think. Last 6 years ago I have the same mentality as yours, to use cables instead of WiFi until I was bitten hard by IME. Didn't notice my machine can be attacked once I am wired directly to my routers. 2 Laptops were bricked by someone who managed to take control of my machine at the IME level which goes lower than what my OS can handle. The technician who replaced my motherboard told me IME was responsible, after I explained that 2 of my machines was working properly until I disabled WiFi and used cables.

    3. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 0

      in every room

      "Every" is not hard to cover when it's a synonym for "one". LOL.

    4. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 0

      Yes, your are spreading BS i think. Last 6 years ago I have the same mentality as yours, to use cables instead of WiFi until I was bitten hard by IME. Didn't notice my machine can be attacked once I am wired directly to my routers. 2 Laptops were bricked by someone who managed to take control of my machine at the IME level which goes lower than what my OS can handle. The technician who replaced my motherboard told me IME was responsible, after I explained that 2 of my machines was working properly until I disabled WiFi and used cables.

      Sounds to me that you might have been hit by a bad case of the monkey virus. That being said, leaving remote management enabled in the bios of any computer while it is plugged straight into the internet is like covering your ass in honey next to a bear den in spring! Remote management and all access privileges are always password configurable the last time I looked, besides which your router addresses would have to be static for someone to target you over multiple machines. If you are working in the computer field I pity your company.

      Once past the bios check the bios firmware modification functions are not accessible remotely. Even then the remotely run working system would have to reboot and load a file from ram while still under power to flash a bios. in other words it is much more likely that you yourself screwed up the bios updates if the systems then bricked. I have seen many computers bricked by people trying to apply bios updates. Almost inevitably it is done by those who have no clue as to how a bios actually works and they bricked the thing by simply doing something like loading the wrong .bin or not waiting long enough for the load to complete. Asus started building boards that you could easily recover from a bad flash or experiment with release candidate .bins or customs for this very reason.

      The only time I bricked a board was when I was a little drunk and accidentally kicked a cord loose during the bios erase before it had time to load. 280 of my bucks later the client had a new machine and he didn't know the difference. Unfortunately it a was really cheap server board with a soldered down bios chip and no bios backup system. LOL

    5. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 0

      You should read properly. That incident happened 6 years ago when AMT/IME was not in mainstream IT news. During those days most IT programmers didn't even know it was there or that it is really a dangerous feature (or should i call it "a dangerous backdoor"?). I was monitoring tech news since 2005 and haven't heard of this AMT/IME feature between 2005 to 2012. Also, I remember all BIOS settings on those 2 machines by heart, and there's no such thing as REMOTE MANAGEMENT setting mentioned inside the BIOS of that machine. It was a 2009 machine where IME was hardcoded and soldered but is separate from the north bridge of CPU. If you're going wireless, that machine won't trigger the IME features. IME can only be access if you avoid wireless and go with wires directly to your router. You sound very confident and seem to know everything about AMT/IME, but are you sure you already have that knowledge before 2013? I doubt.
       

    6. Re:I've always had the cure here... apk by Anonymous Coward · · Score: 0

      edit: Modern CPU's from i3 to i7 including the latest generation version of these CPUs have no escape, both wired and wireless are infected by IME and cannot be unsoldered easily.

  11. Espressif's website by Anonymous Coward · · Score: 0

    Their website has a Google Maps link and they're located just south of Longdong Ave in Shanghai. Why aren't Americans more willing to memorialize porn stars with street names?

    1. Re:Espressif's website by Zontar+The+Mindless · · Score: 1

      Hate to disappoint you with facts, but lóngdông dàdáo means "East Dragon Highway". Lóng is "dragon", and dông is "East".

      I heard a rumour recently to the effect that this is the 21st Century.

      So why does Slashdot and Slashdot alone, of all the sites I visit, require me to use Pinyin instead of Hanzi? Even Ars Fucking Technica isn't afraid of legitimate uses for Unicode, but Slashdot...?

      --
      Il n'y a pas de Planet B.
    2. Re:Espressif's website by fisted · · Score: 1

      You must be new here.

    3. Re:Espressif's website by Hal_Porter · · Score: 1

      We're not allowed to use Chinese here because they fear us plotting against the corrupt dictatorship of the modmins in a language they bù huì kàn dông.

      --
      echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
  12. Google by Anonymous Coward · · Score: 0

    ...we will be patching any* affected devices in the coming weeks

    *For values of 'any' which do not include devices arbitrarily EOL'd by Google's bean-counting department.

  13. KRACK by Anonymous Coward · · Score: 0

    cocaine.

    1. Re:KRACK by Anonymous Coward · · Score: 0

      "Don't do crack, it's a ghetto drug"

          -- Jesse Jackson

    2. Re:KRACK by Anonymous Coward · · Score: 0

      If you wanna hang out you got to take her out
      Cocaine
      If you wanna get down, you got to get down to the ground
      Cocaine

      She don't lie, she don't lie, she don't lie...
      Cocaine

          --God, aka Eric Clapton

  14. how many products will be obsoleted by this? by Anonymous Coward · · Score: 4, Insightful

    due to manufacturers and vendors choosing NOT to fix this for whatever reason (they simply don't care, not cost effective, not enough users to justify the effort, product no longer sold, product too old, product is EOL, etc, etc)....

    vista and older are fucked, routers and access points older than about 3 years are fucked, wireless gear from lesser known companies are fucked, tablets from major vendors more than 3 years old are fucked, tablets from unknown vendors are fucked, phones that aren't current models are fucked.. there's a lot of gear that is going to be junk.. a LOT.

    1. Re:how many products will be obsoleted by this? by cerberusss · · Score: 1

      Really curious whether my girlfriend's iPhone 5 will get an update. It's now 5 years old, and didn't get the latest iOS 11 update from last month.

      --
      8 of 13 people found this answer helpful. Did you?
    2. Re:how many products will be obsoleted by this? by tlhIngan · · Score: 3, Informative

      due to manufacturers and vendors choosing NOT to fix this for whatever reason (they simply don't care, not cost effective, not enough users to justify the effort, product no longer sold, product too old, product is EOL, etc, etc)....

      In an ideal world, you'd patch both the client AND the AP. Doing so eliminates all the vulnerabilities.

      But even if you can't, updating the AP already eliminates a whole class of vulnerabilities. Updating the client by itself, the same.

      So the best results are had by updating everything. But even if you can't, updating the AP alone can help a lot.

      So update what you can, and the older stuff, well, it was already vulnerable anyways from other flaws so I wouldn't worry too much about this.

      My only question is where the UBNT stuff is... firmware 3.9 is supposed to fix it, but all I see for the Unifi stuff is 3.8.

    3. Re:how many products will be obsoleted by this? by Anonymous Coward · · Score: 0

      The Unifi stuff is in the link posted. It links to a forum post on Ubiquiti's website, its not on the main download page yet.

    4. Re:how many products will be obsoleted by this? by thegarbz · · Score: 1

      Zero. Having network access is only a single layer in a security system. The loss of encryption here should not cause you to be in any great risk.

      I mean you do still use SSL, passwords, and have up to date and patched OSes inside your network right?

      RIGHT!?!

    5. Re:how many products will be obsoleted by this? by Anonymous Coward · · Score: 0

      It allows the attacker to control which DNS server you use via DHCP (which most endpoints use), right? The attacker can also send bogus PACs. That looks like a huge attack vector.

    6. Re:how many products will be obsoleted by this? by thegarbz · · Score: 1

      It allows an attacker to MITM one specific machine on a network. The rest relies on phishing attacks or other attacks to mimic and take over a connection. Even then that's a HUUUUGE amount of effort to get at a single user.

      The attack vector gains access to attempt to exploit other vectors, nothing more. What this attack vector allows a person to do is anything they could previously do at any internet cafe, restaurant, airport, hotel, or any other place with open WiFi, and less. The "less" bit being the requirement to exploit each target individually rather than all of them at once.

      Despite the media coverage this is actually one huge yawn.

    7. Re:how many products will be obsoleted by this? by l20502 · · Score: 1

      obsoleted?
      Whos going to change hardware because of some software vulnerability other than large companies and paranoid people?

      Not going to replace teh almighty WRT54GL with 2.4-kernel based tomato

    8. Re:how many products will be obsoleted by this? by Anonymous Coward · · Score: 0

      yeah I just disabled automatic firmware updates in the controller and loaded the beta firmware that is on their blog post. Works fine. The only thing is it'll show you have an update because the firmware you are using is not available to the controller version you are using. Don't update until you can update the controller software or it'll revert to an older firmware.

    9. Re:how many products will be obsoleted by this? by Anonymous Coward · · Score: 0

      > tablets from major vendors more than 3 years old are fucked

      Why the "more than 3 years old" part? I've owned 3 tablets from Acer and Dell, and none of them have *ever* received any sort of OS update since I walked out of the store with them. All abandonware, while still brand new.

    10. Re:how many products will be obsoleted by this? by Anonymous Coward · · Score: 0

      Really curious whether my girlfriend's iPhone 5 will get an update. It's now 5 years old, and didn't get the latest iOS 11 update from last month.

      IOS11 was not supported on iPhone 5 because it drops all 32bit compatibility and libraries, it is officially 64bit only and the iPhone 5 is the last 32bit iOS device. However, there is likely to be an iOS 10.3.4. This has happened in the past with the iPhone 3GS getting an additional ios6 update long after ios7 had come out for a FaceTime bug.

    11. Re:how many products will be obsoleted by this? by thejynxed · · Score: 1

      Quite a few since it is only a matter of time before Intel's hardware backdoor that you can't disable (and AMD's equivalent) is fully compromised, if it hasn't been already. This exploit coupled with access to that thing means quite a few machines involving everyone from Apple and Dell to Linux mail servers and custom gaming rigs can be exposed. I think the risk is higher than it may first appear.

      --
      @Mindless Drivel: 100% of Twitter posts ever Tweeted.
  15. Good GOD by hattable · · Score: 1

    Stop naming exploits! KRACK is idiotic. I wish heartbleed and shellshock had not been as nameable and chic.

    --
    OMG facts!
    1. Re:Good GOD by freeze128 · · Score: 1

      Would you rather that the exploits are named like Star Wars droids? K2SO? BB8? IG-88? Gonk?

    2. Re:Good GOD by Anonymous Coward · · Score: 0

      https://www.theguardian.com/technology/2014/apr/24/heartbleed-why-did-a-computer-bug-have-a-name

    3. Re:Good GOD by Anonymous Coward · · Score: 0

      KRACK snapple POP!

    4. Re:Good GOD by cant_get_a_good_nick · · Score: 1

      Snap, Crackle, Mitch, and Pop....

      -- Mitch Hedberg

  16. WEP Safe by Anonymous Coward · · Score: 1

    I just switched to WEP, as it's not impacted. Much safer.

    1. Re:WEP Safe by Zontar+The+Mindless · · Score: 1

      Nice try, but that one's already been done to death.

      --
      Il n'y a pas de Planet B.
  17. Re: Trump is affected by CRACK vulnerability by Anonymous Coward · · Score: 0

    Your labor is presumably your own, but if you make any sort of profitable exchange with it, then that would be enabled by...wait for it...other people. In order to trade, you need things like stable ownership, which means that we agree not to take your stuff when you walk away from it. In exchange for enforcing your property rights, we tax your income (not your labor). Keep going though, I've got a Fallacy Bingo card I want to fill up.

  18. Can unpatched clients be blocked? by m0gely · · Score: 2

    On the krack attacks site, teh question is asked: "Do we now need WPA3?", and answered: "No". Yet the last sentence in that paragraph is: "Finally, although an unpatched client can still connect to a patched AP, and vice versa, both the client and AP must be patched to defend against all attacks"! So my question is, how do we block unpatched clients from our wireless networks? It seems as if I was a bad guy, I would keep an unpatched device handy to do bad deeds and there's nothing anyone can do to stop me?

    1. Re:Can unpatched clients be blocked? by Anonymous Coward · · Score: 0

      If they don't release WPA3 soon, maybe all future WPA2 routers should also include a malformed WPA2 handshake as a honeypot, and then block clients that fall victim to this exploit.

    2. Re:Can unpatched clients be blocked? by Zontar+The+Mindless · · Score: 2

      Obviously we need to migrate directly to WPA10. Or WPAX. Or WPA52.4.0. Or... What were we talking about, again, please?

      --
      Il n'y a pas de Planet B.
    3. Re:Can unpatched clients be blocked? by Anonymous Coward · · Score: 0

      The easiest way to do that is to follow the small cable from your AP over to where it plugs into the wall outlet, and remove the plug. This method will prevent 100% of unpatched clients connecting to the AP, with absolutely no possibility of hacking or workaround.

    4. Re:Can unpatched clients be blocked? by swillden · · Score: 1

      It seems as if I was a bad guy, I would keep an unpatched device handy to do bad deeds and there's nothing anyone can do to stop me?

      Having your own unpatched device would just allow you to break the security of the connection between your unpatched device and the AP. What you want is to break into the connection between someone else's device and the AP. If that other device is patched you can't do it.

      Note that patching of APs isn't necessary unless the AP in question also acts as a client. So repeaters and mesh network nodes needs to be patched.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    5. Re:Can unpatched clients be blocked? by dkman · · Score: 1

      Likewise, can I tell my client not to connect to unpatched APs?
      How do I tell if the hotel wifi is a trap or if it's OK?

      --
      I refuse to sign
  19. Re:Trump is affected by CRACK vulnerability by Anonymous Coward · · Score: 0

    American workers already work harder, longer, and for less in return than the workers of any other developed nation. Wealthy Americans and US corporations already pay less in taxes than wealthy individuals or corporations do in any other developed nation.

    So you're actually promising us more--HEAPS more--of the same.

    No, really.

  20. quick question by slashmydots · · Score: 1

    Do I need to patch my Windows PC, my router, both, or exactly one of the two but it's not important which.

    1. Re:quick question by Anonymous Coward · · Score: 0

      Disclaimer: I am no expert. I am basing this on this summary.

      Absolutely yes to the PC because the attack targets wifi client devices rather than access points. (Actually, your android phone is a higher risk.) Having said that, your advice for Windows 10 is ensure you have October 2017 updates installed. For most people, run winver from the search box and version 15063.674 or above is patched). (here is the relevant MS page - sadly it looks like device drivers should also be updated.)

      Yes to the router, because using 802.11r "fast roaming" or using the router as a repeater may expose you - but the risk is vastly lower as the router is a lot less likely to be vulnerable.. (Most home users don't use repeater configuration or fast roaming as they only have one access point.) It's possible that disabling repeater and fast roaming will be a work around for attacks against your router (APN).

      Summary: Worry about your Android phone, other devices, PC, and other client devices first. If you have a typical single router set up, do check your router vendor for new firmware, but focus on your client devices. Normal people with normal Windows 10 installs merely need to use windows update.

    2. Re:quick question by Binestar · · Score: 1

      Do I need to patch my Windows PC, my router, both, or exactly one of the two but it's not important which.

      The most important in regards to this is the client. But you should patch both.

      --
      Do you Gentoo!?
    3. Re:quick question by thomst · · Score: 1

      slashmydots inquired:

      Do I need to patch my Windows PC, my router, both, or exactly one of the two but it's not important which.

      If you're running Windows 9/10 and aren't blocking updates, your PC is already patched - so you're safe.

      But, when and as an update for your router becomes available, you really should patch it too. Remember: belt, suspenders, AND staples ...

      --
      Check out my novel.
    4. Re: quick question by Anonymous Coward · · Score: 0

      You must patch the client. If the AP can act like a client, then you must patch the AP.

  21. FreeBSD's official response by Anonymous Coward · · Score: 0
  22. Excellent ! by BESTouff · · Score: 1

    Microsoft: While Windows machines are generally considered safe, the Redmond giant isn't taking any chances and has released a security fix available through automatic updates.

    +5 Funny !

  23. I love that they put OpenBSD under "Linux" by blind+biker · · Score: 1

    From the article:

    Linux: As noted on Charged, a patch is a patch is already available and Debian builds can patch now, while OpenBSD was fixed back in July.

    --
    "The agriculture ministry is not in charge of Gundam" - Japanese ministry official.
  24. Ubiquiti F/W Still Not Available by Anonymous Coward · · Score: 0

    Ubiquiti firmware is still not available in the Unifi Control Panel. You have to install the Beta in order to push F/W to APs unless you want to do it manually, and who wants to install a Beta on a production system?

    It's a constant stream of crap from those guys... they pat themselves on the back for an incomplete job not well done at all.

  25. EAT YOUR WORDS (via proof) by Anonymous Coward · · Score: 0

    I've more than DOUBLED these upmods since I posted this years ago vs. KGIII proving him wrong https://it.slashdot.org/comments.pl?sid=3417867&cid=42749095/

    * EAT YOUR WORDS...

    (That link hits YOUR "disconnect button" troll & SHUTS YOU DOWN, easily...)

    APK

    P.S.=> YOURS is the price of being an UNIDENTIFIABLE anonymous trolling off-topic "ne'er-do-well" in yourself, lol... apk

  26. My avoiding WiFi & it's problems != bs by Anonymous Coward · · Score: 0

    See subject: I don't get problems in security like this OR performance issues of packet drop etc. WiFi gives - how is it bs?

    APK

    P.S.=> It's PURE FACT & you probably left the router's default password @ factory settings (easily found online & once someone has your IP address? They can do what was done to you (part of the reason I post here & elsewhere online via proxies - to avoid attacks by site webmasters etc. - as soon there will be a "hack back" law (NOT that I 'hack' doing proxies either, I just them to avoid tracking + to override posting limits)) YES - it's REALLY a bill (or being suggested as one for passing into law) in congress right now in fact... apk

  27. WRONG: My home has 14 rooms total... apk by Anonymous Coward · · Score: 0

    WRONG: My home has 14 rooms total so EAT YOUR WORDS unidentifiable off-topic "ne'er-do-well" troll!

    * Unbelievable - doesn't "your kind" have anything BETTER to do?

    (Apparently not!)

    APK

    P.S.=> Try doing something like this as I can easily show to my credit of /.ers liking & using my work complimenting it instead (it's a better way to use YOUR WASTED TIME but then again? I expect too much from "your kind", lol) https://news.slashdot.org/comments.pl?sid=11236647&cid=55377085/ ... apk

  28. Does it even matter any more? by KlomDark · · Score: 2

    With Windows 10 and other OSs saving WiFi passwords to the cloud and sharing with who knows, WiFi security has taken a dump anyway.

    Is there any way from the WiFi router to tell these OS incarnations "No, you do NOT have permissions to save these passwords!"?

  29. Cat 6 is still available by Neuronwelder · · Score: 1

    Use a weak transmitter at various points at your home. Like the old blue tooth. End of problem.

  30. Re: Trump is affected by CRACK vulnerability by Anonymous Coward · · Score: 0

    maybe stay away from that women's studies degree next time.

  31. lol by sootman · · Score: 1

    "While Windows machines are generally considered safe..."

    I've never read those words in almost 20 years of coming here.

    --
    Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
  32. Stop Intel AMT/ME easily... apk by Anonymous Coward · · Score: 0

    See subject: Stop it's ability to send info. outward via router port filtering ala ports 16992-16995 that Intel AMT/ME uses so filter those ports in a modem/router external to OS/PC. Intel ME/AMT operates from your mobo but has NO CONTROL OF YOUR MODEM/ROUTER!

    (This stops it cold talking in/out permanently OR being able to remotely 'patch' it to use other ports by Intel OR malicious actors/malware makers etc.!)

    Additionally, once you disable the AMT engine's software interface (ez via software these articles note)? A malware to 'repatch' this = impossible (bios updaters require it in usermode ware, e.g. ASUS).

    (I only allow 80, 8080 & 443 in/out here on a SINGLE stand-alone system (no home LAN but TCP/IP connected online in BOTH my modem or router port filters or software firewalls))

    HOWEVER - Be CERTAIN your modem/router's internal ware is "solid" as well (turn off things like UPnP etc. & CHECK router/modem HAS NO KNOWN BACKDOOR EXPLOITS (tons do unfortunately)) - get it patched ASAP if it's KNOWN exploited & TONS of routers, ARE https://it.slashdot.org/comments.pl?sid=9995967&cid=53488785/

    * GOOD ROUTERS/MODEMS HAVE PORT FILTERING OPTIONS (crappy ones do not)!

    APK

    P.S.=> Good luck - it's the BEST EASIEST & CHEAPEST DEFENSE using what you already have (hopefully, again as not ALL modems have port filtering but most do & certainly GOOD ONES DO) vs. this threat by stopping it being able to communicate in/out period, from OUTSIDE of the INTEL chipset external to it via a router/firewall hardware... apk

  33. FreeBSD security advisory by dagooncrn · · Score: 1
    --
    -- mg
  34. WRONG: This is your "out" vs. IME/AMT... apk by Anonymous Coward · · Score: 0

    See subject & this (it works vs. Intel AMT/IME) https://mobile.slashdot.org/comments.pl?sid=11242973&cid=55385281/

    * Enjoy!

    (No need to unsolder a damn thing - you just cut it's software update interface off (vs. it being changed by update so THIS part works ->) & then disallow communication via port filtering.

    APK

    P.S.=> Common-sense - control Intel IME/AMT from OUTSIDE your motherboard easily using a port filtering router/modem... apk

    1. Re:WRONG: This is your "out" vs. IME/AMT... apk by Anonymous Coward · · Score: 0

      Do you see my point now? You only posted about IME mitigations this year 2017, I was bitten by IME malicious actors last 2011 where no news and stories about this hidden feature was published. Calling someone a monkey just reflects on you.

  35. Three letters by Anonymous Coward · · Score: 0

    Ess Pee Aitch

    1. Re:Three letters by Anonymous Coward · · Score: 0

      Not sure what you mean. If that is a foreign language my bad. He did get upmodded so what is your problem or what are you trying to say?

  36. Who IS "Alex Trusk"?... apk by Anonymous Coward · · Score: 0

    Max from "Cube 2 - the HyperCub": "... Did she say 'Alex Trusk'? Oh Christ, we're dead..." Gov't. undercover agent 'mata hari' type: SEE SUBJECT Max again: "Alex Trusk? Hacker Extraordinaire?? He's a legend..."

    z* You WISH you were me unidentifiable anonymous off-topic puny TROLL... lol!

    APK

    P.S.=> "Alex Trusk doesn't exist" - but I? Do (more than exist - I constantly excel)... apk

  37. So they finally figured it out... by Anonymous Coward · · Score: 0

    I've been using a technique very similar to this for years. The use of a zero key is pretty slick though. WPA/2 have been flawed from the start. IMHO a proper radius WEP setup is still the hardest to crack.

  38. Ess Pee Aitch by Anonymous Coward · · Score: 0

    SPH is a short form mnemonic of the advice we have been advocating for apk for some time now. He himself is now conditioned enough that even mentioning "three letters" triggers his internal monologue to silently mouth "Seek Professional Help". It's unfortunate that he is only able to act sporadically in seeking treatment for his mental health condition.

    Slashdotters can help apk by reminding him of the three letters at every suitable opportunity. Moderators - don't moderate apk down, it just feeds his complex; instead, mod up the SPH responses. Apk will thank you for this charitable intervention.

  39. it leaked in july. by Anonymous Coward · · Score: 0

    The paper leaked in July. You have no way to control all the devs and all the hardware vendors around the world. One of them will end up leaking or selling the info sooner or later.

    https://www.theregister.co.uk/...

    Mathy Vanhoef and Frank Piessens of KU Leuven, the security researchers who discovered the flaw, alerted vendors in advance of going public on Monday. It appears developers and manufacturers got their first warning in July, around the time this unsigned paper [PDF] going over some of the KRACK techniques quietly emerged online.

    So months go by with vendors sitting on a patch and there are still larger vendors(Apple?!?) with no patch released yet.

    Notify, wait a week, then go public and let the chips fall where they may.

  40. I was modded up in case you didn't notice by Anonymous Coward · · Score: 0

    I was modded up in case you didn't notice, stupid troll. Don't you have anything better to do than be an off topic unidentifiable idiot who projects his OWN mental issues onto me giving away the fact you're mentally 'touched in the head' yourself?

    APK

    P.S.=> Seriously... apk

  41. I never called you a monkey... apk by Anonymous Coward · · Score: 0

    Uh, 1st, see subject (I never called you a monkey & was trying to HELP you). We had a guy here posting all about it for years in a HUGE post (with all sorts of really TOUGH things to try do to stop AMT/IME - I mean it. Methods that are a LOT more difficult than my blocking of it is, that's for sure). I actually read it & thought of what I put out to try help you here with & yes, it works (doesn't "kill" it but it does the next best thing, essentially paralyzing it by stopping AMT/IME's ability to communicate back & forth).

    APK

    P.S.=> Again, see subject - I never called you a monkey & really WAS trying to inform/help... apk

  42. You HAVE had treatment?! Well done by Anonymous Coward · · Score: 0

    I didn't read your post, but casting my eyes over it, it looks like you only used allcaps on one word and no bolding whatsoever - what progress! Well done, you are doing well, keep going with the treatment, it seems to be working.

  43. Then learn to read illiterate troll by Anonymous Coward · · Score: 0

    Then learn to read illiterate off-topic UNIDENTIFIABLE trolling worm: In case you hadn't noticed? I was upmodded for my post. +1 INFORMATIVE...

    (Bet the just KILLS you, now doesn't it? Yes, obviously... lol!)

    APK

    P.S.=> Keep projecting you've got 'issues' but don't try project them onto ME... apk

  44. UNIDENTIFIABLE lol by Anonymous Coward · · Score: 0

    Aw, and you used to claim you knew me

    1. Re:UNIDENTIFIABLE lol by Anonymous Coward · · Score: 0

      Lol lol lol

  45. Re:Then learn to read unidentfiabletroll by Anonymous Coward · · Score: 0
  46. Replying anonymously 6 days later? by Anonymous Coward · · Score: 0

    Replying anonymously (often to yourself) 6 days later, STILL? You truly have issues.

    * On this one I just said to myself "Let's see what the unidentifiable LOON does if I don't pay him any attention" & sat back watching... amazing - you're obsessively FIXATED on me STILL almost a week later trying to "get my attention" like some petulant child would!

    You should seek professional help (I suspect you already have postcard man... in fact, I KNOW you have).

    APK

    P.S.=> Unbelievable, lol... apk

  47. "Baby, you don't know a thing about me"... apk by Anonymous Coward · · Score: 0

    Just for you. Speaks my mind https://www.youtube.com/watch?...

    APK

    1. Re:"Baby, you don't know a thing about me"... apk by Anonymous Coward · · Score: 0

      I didnt read your post. SPH