On Mon, 2017-10-16 at 17:51 +0100, Patrick O'Callaghan wrote: > wpa_supplicant (used in Linux and Android) is particularly bad. Just in case this point isn't getting enough emphasis: the specific vulnerability in wpa_supplicant allows the adversary to force the use of an all-0's encryption key. That could legitimately be called disastrous. Patched versions of wpa_supplicant should be installed as soon as they are available. poc _______________________________________________ users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx