Paul1977: So, the consensus is that patching the AP only plugs a small part of the hole, and no matter what you do with your AP (short of turning it off) the client devices are vulnerable even when connected to a patched AP?
My understanding is a patched AP will not reissue a key but an unpatched client is capable of receiving one, which is what the attacker does - sends a zero (0) key to the client. Whether or not the patched AP would recognise this has occurred and refuse further comms I'm not sure.


