Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 | 5 | 6
5434 posts

Uber Geek


  # 1885641 18-Oct-2017 12:40
Send private message

The open VPN android app just seems to be a client.   I need something that works from my phone when I'm out and about. 

 

Nord seems to be consistently rated highly by experts and play store users so I think I'll try it. 





Mike

2862 posts

Uber Geek


  # 1885670 18-Oct-2017 12:50
Send private message

MikeAqua:

 

The open VPN android app just seems to be a client.   I need something that works from my phone when I'm out and about. 

 

Nord seems to be consistently rated highly by experts and play store users so I think I'll try it. 

 

 

Yes, the app is just the client. You would need to install an open VPN server at your home/premises. This can be installed on many different kinds of devices, including some routers.


 
 
 
 


2862 posts

Uber Geek


  # 1885674 18-Oct-2017 12:52
Send private message

I've gone and updated my iPhone and iPad to iOS 11.1 public beta 3, which is apparently patched (I can't find any specific comment from Apple saying that this specific release is patched, but they have said that their latest betas are - so I assume this includes the public beta 3).


2460 posts

Uber Geek


  # 1885680 18-Oct-2017 13:00
Send private message

This includes devices sold by Spark

 

Spark are going to have to pull finger, how many of their Android phones are even on the October Security patch level? (Google are apparently including the patch in the November Patches)

 


2952 posts

Uber Geek

Trusted
Lifetime subscriber

  # 1885695 18-Oct-2017 13:31
2 people support this post
Send private message

Watched this explanation which tried it's hardest to be explainable for non-technical people.

 





and


2862 posts

Uber Geek


  # 1885783 18-Oct-2017 16:12
One person supports this post
Send private message

BarTender:

 

Watched this explanation which tried it's hardest to be explainable for non-technical people.

 

 

Still over my head!


1979 posts

Uber Geek


  # 1885890 18-Oct-2017 19:13
Send private message

My brief understanding of it is that a malicious person could trigger a reset of the sequenced encryption process on a vulnerable device and because the encryption data gets repeated, some simple math could applied between the two lots of data to get the key.

 

 


 
 
 
 




/dev/null
9028 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  # 1885917 18-Oct-2017 19:24
One person supports this post
Send private message

Paul1977:

 

BarTender:

 

Watched this explanation which tried it's hardest to be explainable for non-technical people.

 

 

Still over my head!

 

I think this one may be better:

 





2862 posts

Uber Geek


  # 1885966 18-Oct-2017 21:14
Send private message

I’m most interested in how vulnerable unpatched iOS and Windows are (particularly iOS which is not yet patched in the latest general release 11.03).

The paper shows they are the least vulnerable, but I’m finding it difficult interpreting what the specific risks are for these devices.

1976 posts

Uber Geek


  # 1886095 19-Oct-2017 09:44
One person supports this post
Send private message

My understanding was that WPA2 was 'crackable'  2+ years ago , so not secure regardless. (?)

 

Give all the non patchable androids out there, and there are millions, as mid/low price Androids will NEVER get any patches & updates (I have 2 samsungs that will never get any updates)
- should companies close down internal wifi competely , or change the pass & only let patched devices connect
- Many companies have a guest wifi , should that be shut down as well, just to mitigate any liability (as vistors often are give access to guest wifi)
- is closing down company wifi a necessary reaction, necessary to mitigate any possible liability of either IT or the company itself ?

 

most company ph's & laptops could hardly be considered secure regardless , unless completely locked down & install of any apps blocked

 

 

 

 


463 posts

Ultimate Geek


  # 1886125 19-Oct-2017 10:42
Send private message

Paul1977: I’m most interested in how vulnerable unpatched iOS and Windows are (particularly iOS which is not yet patched in the latest general release 11.03).

The paper shows they are the least vulnerable, but I’m finding it difficult interpreting what the specific risks are for these devices.

 

As I read it they are only vulnerable to the group key attacks - CVE-2017-13080 and CVE-2017-13081. As these are used for transmitting broadcast and multicast frames, the amount of sensitive information you could decrypt would be negligible.


5434 posts

Uber Geek


  # 1886162 19-Oct-2017 11:14
One person supports this post
Send private message

1101:

 

- Many companies have a guest wifi , should that be shut down as well, just to mitigate any liability (as vistors often are give access to guest wifi)

 

 

If someone tried to assert liability on the company's part in relation to our guest WiFi,  I would simply argue there is no scope for liability because: -

 

- Guest Wifi is free;
- Therefore, the company has received no consideration;
- Therefore, the company has no duty of care.

 

The solution is an Accept page which includes a waiver the user must agree to.





Mike

1599 posts

Uber Geek

Subscriber

  # 1886168 19-Oct-2017 11:22
Send private message

MikeAqua:

 

If someone tried to assert liability on the company's part in relation to our guest WiFi,  I would simply argue there is no scope for liability because: -

 

- Guest Wifi is free;
- Therefore, the company has received no consideration;
- Therefore, the company has no duty of care.

 

The solution is an Accept page which includes a waiver the user must agree to.

 

 

As a general proposition, in respect to whether one entity owes a duty of care to another for the purpose of liability in tort for negligence, the first three matters are either not decisive or even irrelevant. The last idea will help but only if the Ts&Cs are properly drafted, which pretty much 95% of NZ companies will fail at. 

 

 

 

 


820 posts

Ultimate Geek


  # 1886622 20-Oct-2017 07:51
Send private message

Patch for Grandstream fw confirmed to be released asap.





- ISP1: T-OneBox FTTH modem, 1/.5G, full DS, VLAN7, VoIP + ipTV streaming flat

 

- ISP2: 4G/LTE USB modem + TL-MR3020, 100/40M data plan (wireless fallback)

 

- NET: ZBOX nano router, 2 C2960X-48TS-L, 2 GWN7630, 1 GWN7610, 2 UPS

 

- SVR: E3C236 32G/20T, 2 H2 16G/500G, HC1 5T, N2 128G | HC2 14T, HC2 1T

 

- USR: DeskMini 310, NUC8i7HVK, Aspire E5, EliteBook 840, Galaxy Tab, 2 4K TVs

 

- IoT: 4 LoRaWAN public gateways, CCU3 (openHAB, MQTT, Grafana), ESP32

 

- 3D: Ender-3, Ender-3 Pro, Ultimaker 2E+, Ultimaker 3, Ultimaker S5, MP-CNC

 

- ipPBX: GRP2613, GO-Box 100, SPA112 (Fax and W-48, a 1948 Siemens phone)


2862 posts

Uber Geek


  # 1886702 20-Oct-2017 09:22
Send private message

MikeAqua:

 

If someone tried to assert liability on the company's part in relation to our guest WiFi,  I would simply argue there is no scope for liability because: -

 

- Guest Wifi is free;
- Therefore, the company has received no consideration;
- Therefore, the company has no duty of care.

 

The solution is an Accept page which includes a waiver the user must agree to.

 

 

It's also not uncommon for guest wifi to not even use WPA2 and just be unencrypted (with a guest portal login and a disclaimer), potentially more commonplace in cafes, hotels, etc than at businesses. This type wifi network is unaffected by KRACK as they were never secure in the first place.

 

But assuming your guest wifi is using WPA2 and APs are patched or not affected then it is the vulnerability in THEIR phone that is being exploited, not your network. IANAL, but I don't see how you could be held liable for that.


1 | 2 | 3 | 4 | 5 | 6
View this topic in a long page with up to 500 replies per page Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Netflix releases 21 Studio Ghibli works
Posted 22-Jan-2020 11:42


Vodafone integrates eSIM into device and wearable roadmap
Posted 17-Jan-2020 09:45


Do you need this camera app? Group investigates privacy implications
Posted 16-Jan-2020 03:30


JBL launches headphones range designed for gaming
Posted 13-Jan-2020 09:59


Withings introduces ScanWatch wearable combining ECG and sleep apnea detection
Posted 9-Jan-2020 18:34


NZ Police releases public app
Posted 8-Jan-2020 11:43


Suunto 7 combine sports and smart features on new smartwatch generation
Posted 7-Jan-2020 16:06


Intel brings innovation with technology spanning the cloud, network, edge and PC
Posted 7-Jan-2020 15:54


AMD announces high performance desktop and ultrathin laptop processors
Posted 7-Jan-2020 15:42


AMD unveils four new desktop and mobile GPUs including AMD Radeon RX 5600
Posted 7-Jan-2020 15:32


Consolidation in video streaming market with Spark selling Lightbox to Sky
Posted 19-Dec-2019 09:09


Intel introduces cryogenic control chip to enable quantum computers
Posted 10-Dec-2019 21:32


Vodafone 5G service live in four cities
Posted 10-Dec-2019 08:30


Samsung Galaxy Fold now available in New Zealand
Posted 6-Dec-2019 00:01


NZ company oDocs awarded US$ 100,000 Dubai World Expo grant
Posted 5-Dec-2019 16:00



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.