How can we help?


**WiFi WPA2 "KRACK" patch

Implemented

Comments

19 comments

  • Official comment
    Avatar
    RainMachine Nicholas (Edited )

    Hi,

          We are in process of evaluating the impact of this vulnerability on our devices. Since we aren't using the same versions and the software deemed vulnerable we must investigate in the source code if this vulnerability applies to any of our devices without an existing exploit being available.

         The vulnerability would allow an attacker to see the traffic between the user access point and the RainMachine device. There is no sensitive data being exchange by RainMachine and without considering the Remove Access service  RainMachine only *receives* data from the well known weather providers by secure HTTPS. No data is *sent*.

    For optional Remote Access this is encrypted by SSL but doesn't use HTTPS and it's not vulnerable to a HTTP downgrade attack exemplified in this vulnerability. This connection for remote access is authenticated by our servers on both ends, client and server certificates and it's always encrypted.

    On top of all these we have another layer of security by device password and tokens which are required for any actions.

        Without minimizing the possible impact of this vulnerability the attacker must be in range of device and emulate your access point and then disconnect the device from the user access point. The attacker must also know the MAC address of the device. After this sequence is successful the attacker could be able to manipulate the packages being *sent*.

    Comment actions Permalink
  • Avatar
    Matt Greco

    +1.  please patch this immediately.

    0
    Comment actions Permalink
  • Avatar
    Mitch Mitchell

    Can someone from Rain Machine tell us what the plan is to deal with this vulnerability?

    Thanks!

    1
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    I am not sure I agree with RainMachine's assessment that they may not be affected. The vulnerability affects ANY device using WPA2. Period. Therefore a RainMachine device is affected, and can therefore compromise other devices on the network. So, trying to cop out of a fix is misleading to the end users.

    Please update the firmware ASAP.

    Thank you.

    1
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas

    Pierre,

      I'm sorry that I left that impression but it wasn't our intention to "cop out", but I wanted to reassure the users that even being vulnerable, there are still other security considerations that offer protection. As you mention, most likely all devices using WPA2 are affected in one way or another.

    0
    Comment actions Permalink
  • Avatar
    Shrinks

    "As you mention, most likely all devices using WPA2 are affected in one way or another."

    Should say: "most likely, all UNPATCHED devices..." 

    I'm with the rest: please patch ASAP.  (Or better yet, provide a wired interface).

    1
    Comment actions Permalink
  • Avatar
    Pierre Darmon (Edited )

    It's been 2 months and not a peep from RainMachine. The manufacturers for all my devices have provided a patch except ..... RainMachine. Does RainMachine understand the urgency of providing a patch for a security vulnerability? Two months is plenty of time to write a patch, unless of course you don't understand programming. Do we have to resort to social media? I am sure that would get the attention of RainMachine's executives.

    0
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas (Edited )

    Hi Pierre,

       We have the patch ready,  included in the next update which should be released in beta channel this week. This update has been extensively tested but since there are many new features along with the WIFI stack change we will keep it in beta for at least 2 weeks to get a better coverage on different WIFI access points the customers use.

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    Hi Nicholas,

     

    Great to hear the patch is ready. How will users be notified when you release it? Could you reply to this thread again when it is ready to be downloaded? Thanks in advance.

    0
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas

    Yes, the users that had enabled Beta Channel Updates will receive a notification on their phone. I will also mention it here once it's ready.

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon (Edited )

    Thanks Nicholas. Looking forward to the announcement.

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    Hi Nicholas,

    Happy New Year to the RainMachine team. Any news on the release of the patch?

    0
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas

    Hi,

    The beta version for the next update is now available and includes the WPA KRACK vulnerabilities fixes: https://support.rainmachine.com/hc/en-us/articles/230333608

    If you encounter any WIFI issues with this beta please let us know.

     

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    Oh, er...., I thought it was going to be the real thing, I thought it was in beta for the past 2 weeks. How long until it comes out of beta and be generally available?

    Thanks.

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon (Edited )

    Hi Nicholas,

    3 more weeks have passed, but I didn't hear back from you. How long until users can get the real thing? I.e. not the beta.

    Thanks.

    0
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas

    Hi Pierre,

    Current beta is being updated and released as stable but we are restricting how may users can get a stable update at once, then we stop the stable release and evaluate the updated units. Since we are changing the WIFI stack we don't want to risk releasing the update to all users at once.

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    Hi Nicholas,

    Can you give a time frame for a public release? Are we talking 6 days, 6 weeks, or 6 months?

    0
    Comment actions Permalink
  • Avatar
    Pierre Darmon

    Hi Nicholas,

    Any update for the public release?

    Also, last week there was an update to the phone app. Is it in any way related to the KRACK patch? I doubt it but I have to ask.
    Thanks.

    0
    Comment actions Permalink
  • Avatar
    RainMachine Nicholas

    Hi Pierre,

    Yes, the update is public, you should have received a notification, if not just check for an update using Settings -> About.

    The phone update it's not related to KRACK vulnerability it mostly contain general improvements.

    0
    Comment actions Permalink

Please sign in to leave a comment.