What is happening?
We will keep this at a high level, if you want the technical details please read the well written paper published by the researcher who found the issue (listed in the resources section).
Background
Wireless networks work by broadcasting your network communications openly using radio waves. These radio waves are susceptible to people listening in on them, and even talking over them. Through the years a series of security protocols were developed to help secure this communication. Originally, it was WEP (wired equivalency protocol) which was found to have problems and replaced by WPA (Wi-Fi Protected Access), and then by a second revision called WPA2. Ultimately, WPA2 has been thought of as a secure way of communicating over wireless networks.
This summer a researcher named Mathy Vanhoef, from imec-DistriNet, KU Leuven, discovered the vulnerability while doing some review of code for wireless networking. After realizing the scope of the vulnerability, he chose to do a responsible disclosure and worked with the CERT team to involve the companies that develop wireless products. A timeline was put in place that on October 16 the information would be opened up for public release. This vulnerability utilizes a series of Key Reinstallation AttaCKs, hence the name KRACK Attack.
To take our free risk assessment visit www.mytech.com/krack-attack-risk-assessment