..otherwise it wouldn't work. You can disable backups when you setup your phone.
Android saves wifi passwords in plaintext to the cloud
31–40 of 172 posts
Re: Android saves wifi passwords in plaintext to the cloud
#32What key are you going to encrypt these passwords with? If you were to encrypt passwords in the cloud with a key that's stored on the device, you can't unlock the passwords on a different device (or the same device after flashing), which is the whole point of backing it up in the cloud. If you were to encrypt them with the user's Google Accounts password, the device would need to ask for that password on every startu…
Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device.
Google's scheme allows them to harvest the passwords to a vast number of wireless networks.
Google has harvested the location, name and signal strength of many millions of wireless networks across the world - an act which can be in no way cast as user convenience.
The very best possible light for this nexus is that it only appears to be a very very bad thing.
Re: Android saves wifi passwords in plaintext to the cloud
#33What key are you going to encrypt these passwords with? If you were to encrypt passwords in the cloud with a key that's stored on the device, you can't unlock the passwords on a different device (or the same device after flashing), which is the whole point of backing it up in the cloud. If you were to encrypt them with the user's Google Accounts password, the device would need to ask for that password on every startu…
Re: Android saves wifi passwords in plaintext to the cloud
#34This reply "This report applies to a mobile Google application or service, and the issue tracker where you reported it specializes in issues within the Open Source source code of the Android platform." is a bit off, IMO. The developer reported a bug found on Android to the Android forum. The reply he gets sounds like a dismissal, which is quite strange given that the problem is not only related to Android but also wi…
The thing about AOSP is exactly what JBQ said: It's meant for reports about open source parts of Android, not reports about Samsung's skin on top of it, etc.
Most of the bugs submitted are not AOSP bugs (I know it's hard to believe, but i've done triage on it). They are bugs in some vendor's patches or changes to AOSP, which, for the most part, Google can do nothing about.
It would be worse if these bugs were left open, giving people the false hope that Google can solve their problem, or that the bug got to the right place.
If this bug/feature is somewhere in the AOSP code, great, reopen the bug and point it out.
Re: Android saves wifi passwords in plaintext to the cloud
#35But to a layperson, the lack of a secure private channel to personal data storage remains an infeasibility. So laypeople embrace third-party "cloud" storage offerings, this one included. These services offer omnipresence of data. They don't offer personal control, but many people are willing to concede control because omnipresence is such a convenience.
Putting all of that aside, however, and accepting the world as it is, with VPNs the tragedy of user experience that they are... An open question remains: why not ask the user to create a passphrase for use in encrypting the device's data before storing it at the GoogleCloud + NSACloud?
The seemingly obvious answer to the rhetorical question is a worry about user experience pain ("woe is me, I need to remember another passphrase now"). So perhaps the user would be instructed to provide a passphrase if and only if they are concerned about their backup being stored on the NSACloud. If they are not concerned, they can leave the field empty.
Re: Android saves wifi passwords in plaintext to the cloud
#36Let [this](http://cl.ly/image/1X0o212T3B0Y) be your reminder to do so.
Re: Android saves wifi passwords in plaintext to the cloud
#37Earlier quoted context omitted.
Convenience isn't an excuse to not encrypt security data, it does not matter if it is a limited to a few areas where it could be exploited. If Google (any companies, including Apple) can not be trusted to protect such information, they should not be offering it in the first place. If it can be exploited, it should be protected as much as it can be. We all saw what happened with Google's StreetView cars capturing the…
It's more than "unlikely", it's ridiculous. It's the longest way around and possibly the stupidest route to get onto someone's Wifi network.
From a governmental law enforcement perspective, that's an incredibly valuable trove of data. Instant network backdoors, likely with no physical entry required.
Even if you're not using the data to sniff networks, you can use it to build detailed relationship graphs between people and places.
Re: Android saves wifi passwords in plaintext to the cloud
#38This reply "This report applies to a mobile Google application or service, and the issue tracker where you reported it specializes in issues within the Open Source source code of the Android platform." is a bit off, IMO. The developer reported a bug found on Android to the Android forum. The reply he gets sounds like a dismissal, which is quite strange given that the problem is not only related to Android but also wi…
This. I recently found the same irksome behaviour by Goog on another important issue: https://code.google.com/p/android/issues/detail?id=56803
The Location Services API is not part of AOSP (or at least, this implementation isn't) IIRC
You should rephrase the bug report to make clear you are talking about the google play services location API.
As for the complaint on that bug report that google should file and track these issues for folks, AOSP is an open source project, and like most open source projects, prefers folks file upstream/downstream issues directly.
Re: Android saves wifi passwords in plaintext to the cloud
#39With the street view wifi scandal, this on going encryption problem and the revelations about prism this looks very bad.
(for others like myself who had not heard of this)
Re: Android saves wifi passwords in plaintext to the cloud
#40What key are you going to encrypt these passwords with? If you were to encrypt passwords in the cloud with a key that's stored on the device, you can't unlock the passwords on a different device (or the same device after flashing), which is the whole point of backing it up in the cloud. If you were to encrypt them with the user's Google Accounts password, the device would need to ask for that password on every startu…
Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…