The Krack hack – is it the end of the world, or worse: is WPA2 dead?

The Krack hack – is it the end of the world, or worse: is WPA2 dead?

So here we go…

I recently read rather a lot of articles entitled “WPA2 is dead” or “The end of wireless security” and so on, online, and actually saw stuff on the news (TV news channels).

What happened then?

Well let’s spread some truth in the vast world of “exciting” news cycles, and dramatic news bulletins.

What I am going to do, is to tell you some truths about the Krack virus (actually got an email from a family member, someone who was worried about this, because they saw this Krack virus on British news!)

 

Is it a Hack? Is it a Virus? No it’s a Potential Vulnerability!

So, first of all, it is NOT a virus, nor is it a hack. It is a potential vulnerability in the current implementations of some vendors’ WPA/WPA2 protocol stacks.

What does that mean?

So, for the wifi-and-cybersecurity-is-magic folks (basically anyone who isn’t an uber-geek and is quite happy for wifi to “just work” – i.e. 99% of the population), what this means is that there is a potential problem/loophole that can be exploited or used to possibly break into the encrypted stream of one or some of your wireless clients. Basically, a couple of guys (and gals) have played around with vendors’ implementations of the WPA and WPA2 modes of operation. They found, under certain circumstances, that these vendors equipment is susceptible to being manipulated to give away secrets that can help bad guys (and gals) abuse and maybe break into networks.

Now these are good guys (and gals) who have “outed” this problem, and they have done it so we can make the world a better place.

It’s important to understand that it is a potential vulnerability and that no code has been written (as of late October 2017) to take advantage of this that we know about. The problems with the statement I just made is “that we know about”. Hackers are probably busy at this moment writing code to do just this. So we have to treat this seriously.

So, what happened next? Well the folks that discovered this, regard themselves as “good guys (and gals)”. They responsibly notified vendors about this potential hack, well before releasing it to the public. Vendors started to work on and release patches that protect from this vulnerability. Good on you vendors, it is the right and responsible thing to do. Our vendors have our backs here and have released, or are releasing, fixes for these potential problems. Our advice is to check with your vendor, see what they say, and take it from there.

Now I was going to spend some time digging into this and writing a lovely blog for you all on this subject. But my good friend Heather Williams at Ruckus has done such a great job, I will refer you to her blog entry on this:
https://theruckusroom.ruckuswireless.com/wired-wireless/technologytrends/commonsense-approach-uncommon-problem/

Heather goes into great detail, in her blog entry, about the vulnerability, what it does, and that it is, in fact, NOT the end of the world.

Heather even includes a link to an article by Kevin Beaumont that includes the original document released by our friendly good guys (and gals), who discovered the vulnerability.

Heather also includes a link to a blog entry by Peter Mackenzie which gives follow up links to much more information and details on the Krack vulnerability. (By the way, Peter’s post is on the WLA website – WLA is a great resource and community to get involved with for WiFi engineers, we highly recommend you take a look at the site).

So is WPA2 Dead?

I don’t think so. Let us know what you think.

 

That’s it for now. I will include the follow up links from Heather’s site for reference and include a link to the WLA. Stay safe and see you next month.

 

If you are looking to make your mark in the IT Industry, then NC-Expert offers excellent training courses aimed at relevant IT industry certifications – contact us today to get started.

NC-Expert Blog

By Rie Morgan July 30, 2026
Every new Wi-Fi generation arrives with a wave of excitement: faster speeds; lower latency; more efficient use of the spectrum; and better handling of dense environments. Wi-Fi 7 is no exception. It brings some genuinely impressive technological advances but, unfortunately, it also brings a familiar myth: "If we upgrade to Wi-Fi 7, all of our wireless problems will disappear." If only wireless engineering were that simple. Wi-Fi 7 is an outstanding technology, but it isn't a magic wand. Poor design, interference, bad client behavior, and unrealistic expectations don't suddenly vanish because the APs have a shiny new logo on the box. Let's bust another myth...
By Rie Morgan July 23, 2026
Few phrases trigger a knowing smile from experienced Wi-Fi engineers quite like this one, "It's the client's fault." Someone's video call drops while walking through the office or a warehouse scanner pauses between aisles, voice handsets crackle as users move from one floor to another... then, almost immediately, someone points at the device and confidently declares, "Well... clients decide when to roam." Technically, they're correct. But, practically, that's only part of the story. Roaming is one of the most fascinating aspects of Wi-Fi because it isn't controlled by a single device or a single setting. It's a partnership between the client, the infrastructure, and the RF environment. When that partnership breaks down, blaming one side rarely tells the whole story. Let's bust another myth... Yes, Clients Make the Decision Let's start with the important truth: in almost every Wi-Fi deployment, the client device ultimately decides when to leave one AP and join another. Laptops, smartphones, tablets, barcode scanners, medical devices, and countless IoT products all use their own roaming algorithms. Some roam aggressively whereas some cling to their current AP for far too long. Others seem convinced that losing the connection entirely is preferable to switching. Every Wi-Fi engineer has encountered at least one stubborn client that appears almost “emotionally attached” to a particular AP. :) Client behavior matters, but that's not where the story ends.
By Rie Morgan July 17, 2026
Every Wi-Fi engineer has heard some version of it, "Can't we just install the access points where the old ones were?" Or perhaps, "The floorplan looks straightforward. Let's save some time and skip the survey." Occasionally, someone even says the dangerous words, "We've done hundreds of these buildings. They're all basically the same." That's usually the point where experienced wireless engineers quietly smile, knowing that the building is about to teach everyone a valuable lesson because: buildings don't read design guides, concrete doesn't care about your deployment schedule, metal doesn't respect your project budget, and radio waves have never once agreed to cooperate, simply because everyone wanted them to. Let's talk about why a site survey isn't an optional luxury... it's one of the most valuable engineering tools available. Every Building Is Different At first glance, two office buildings may appear identical: same square footage, same number of floors, similar room layouts, yet their wireless behavior can be dramatically different: one may have reinforced concrete walls, another may contain extensive glass partitions, the warehouse may be filled with moving inventory, a hospital may have elevators, imaging equipment, and countless reflective surfaces, a manufacturing facility may contain machinery that wasn't mentioned on any floorplan, and remember: even furniture changes RF behavior! Anyone who has performed enough surveys eventually develops a healthy respect for one simple fact: the building always gets a vote, too!