Is the Acer Aspire 5750-9668 wireless LAN card affected by the "KRACK" attack?

penalvch
penalvch Member Posts: 5 New User
edited March 2023 in 2017 Archives
*Environment*
  • Model: Acer Aspire 5750-9668
  • OS: Windows 10 x64
  • Wireless Card: Qualcomm Atheros AR5B97 Wireless Network Adapter
  • Driver Hardware ID: PCI\VEN_168C&DEV_002E&SUBSYS_E034105B&REV_01
  • Driver option 1: The Acer Wireless LAN driver for the laptop https://www.acer.com/ac/en/US/content/support-product/3474?b=1&pn=LX.RGK02.001 is for Windows 8 x64. I am open to trying to install it in Windows 10 if confirmed not vulnerable.
  • Driver option 2: The latest one that comes by default from Windows Update (Driver Provider: Microsoft, Driver Date 1/29/2016, Driver version 3.0.2.202).
*Question*

I need an official response from an Acer representative regarding if the "KRACK" attack as documented below affects my Acer laptop wireless LAN card with either of the previously provided driver versions:
https://www.kb.cert.org/vuls/id/228519

While the below CERT Vendor Information list does not presently include Acer, CERT has been contacted recently to have Acer placed on the list. Also, the list does include Qualcomm and Atheros, the wireless LAN card manufacturer that came with the laptop:
https://www.kb.cert.org/vuls/byvendor?searchview&Query=FIELD+Reference=228519&SearchOrder=4

In addition, Acer has no documentation regarding the status of this vulnerability in relationship to their equipment as per:
https://www.acer.com/ac/en/US/search?q=krack

Despite this, as per the Qualcomm/Atheros website https://www.qualcomm.com/contact "Please note: we are unable to provide support for OEM devices, including drivers. If you're experiencing issues with your consumer device (mobile phone, tablet, laptop, camera, drone, router, access point, etc.) you will need to contact the OEM of your equipment directly as we are unable to support our chips once the manufacture has modified them for their particular use. Please refer to the manufacturer’s website, as they typically offer a variety of technical support options, including drivers."

As per Microsoft, while I reported this specific issue to them, their default response is seek support from Acer and/or Qualcomm/Atheros.

Unfortunately, my warranty has ended, and I'm not able to obtain official chat support. Despite this, forcing me pay for the answer to this question when I want to "Contact Technical Support" isn't fair here, given serious security vulnerabilities.

Thank you for your time and consideration in this matter, and I look forward to your response.

Answers

  • JackE
    JackE ACE Posts: 44,897 Trailblazer
    Not sure about a Krack attack. But Win10 downgrades often result in driver issues like this. Your machine is listed as being originally shipped with Win7 installed and that's the OS it was originally warranted for. So it must've been previously downgraded once before to Win8. You can try two things. First, open Device Manager and uninstall the current driver. Then cold boot and let Win10 try to automatically search for and install the best driver it can find on your system. If that doesn't resolve the issue, and if the Win10 and Win8 downgrades haven't already wiped out the HDD's hidden recovery partition, you might be able to upgrade back to Win7 again. Jack E/NJ   

    Jack E/NJ

  • penalvch
    penalvch Member Posts: 5 New User
    JackE:
    JackE said:
    Not sure about a Krack attack.
    Then you should have stopped right there before posting. As per my original post, the scope isn't about general technical support, need basic suggestions on how to change my OS which I'm not doing, etc. Instead, it requires a response only from an employee of Acer to advise if their driver is affected or not by the "KRACK" attack security vulnerability.




























  • JackE
    JackE ACE Posts: 44,897 Trailblazer
    Sorry. Haven't seen or heard of any such vulnerability issue for the original factory-installed Win7 version driver updates or the Win8 upgrade driver updates from the ACER website. Jack E/NJ

    Jack E/NJ

  • penalvch
    penalvch Member Posts: 5 New User
    JackE said:
    Sorry. Haven't seen or heard of any such vulnerability issue for the original factory-installed Win7 version driver updates or the Win8 upgrade driver updates from the ACER website. Jack E/NJ
    This post *only* needs an official Acer employee confirming/denying the device is or isn't affected. Hence, please refrain from posting/replying further on this.
  • penalvch
    penalvch Member Posts: 5 New User
    Acer has now been added to the CERT Vendor Information list regarding this vulnerability:
    h t t p s : / / w w w . k b . c e r t . o r g / v u l s / i d / J L A D - A S W K 4 3

    Sorry for the spaces in the URL but I keep getting the silly error message "You have to be around for a little while longer before you can post links."
  • penalvch
    penalvch Member Posts: 5 New User
    Update: I talked with a representative from Acer America, who said he would contact Taiwan engineers for an update, and get back to me early next week.