Dragonblood: Analysing WPA3’s Dragonfly Handshake

Dragonblood: Analysing WPA3’s Dragonfly Handshake

The first category consists of downgrade attacks against WPA3-capable devices, and the second category consists of weaknesses in the Dragonfly handshake of WPA3, which in the Wi-Fi standard is better known as the Simultaneous Authentication of Equals (SAE) handshake. The discovered flaws can be abused to recover the password of the Wi-Fi network, launch resource consumption attacks, and force devices into using weaker security groups. We also discovered a downgrade attack against the WPA3’s Dragonfly handshake itself, where the victim can be forced to use a weak security group.

Source: wpa3.mathyvanhoef.com