BramBonne / privacypolice

Source code for Wi-Fi Privacy Police, available on Google Play at https://play.google.com/store/apps/details?id=be.uhasselt.privacypolice
GNU General Public License v2.0
159 stars 17 forks source link

Broadpwn #49

Closed smitsohu closed 7 years ago

smitsohu commented 7 years ago

Does Wifi Privacy Police defend against the Broadpwn exploit?

Having skimmed through the Broadpwn blog post and your papers, this seems to be the case to me, but I would highly appreciate a confirmation.

I understand that Wifi Privacy Police in any case can't provide a complete defense and merely would raise the bar for a successful attack.

BramBonne commented 7 years ago

Hi @smitsohu,

You are correct in assuming that Wi-Fi Privacy Police will make it slightly more difficult for an attacker to mount a successful Broadpwn attack. However, it should not be considered as a complete defense against the attack, as the vulnerability lies in the parsing of IE's by the Broadcom firmware. These IE's can also be included in normal Beacon or Probe Response packets, which will be parsed by the firmware irregardless.

Kind regards, Bram