Live data from Hacker News

Android saves wifi passwords in plaintext to the cloud

code.google.com

111–120 of 172 posts

Re: Android saves wifi passwords in plaintext to the cloud

#111
post #85

Earlier quoted context omitted.

Encrypt the data on the device. Backup encrypted version in the cloud. Download encrypted backup to new device. Unencrypt on new device. Merge versions on the device. No need for plaintext on Google servers. No way for monetization by Google. Or to put my alternative another way, how much is a data set mapping WiFi passwords to networks for the city of Bejing worth to a foreign intelligence agency or other state-leve…

You're providing innuendo and "exercises for the reader", not an argument. That's pretty weak. What would such a data set of Redmond be worth to Google? Nothing. Because accessing those networks for industrial espionage (if I read your innuendo right) would be illegal and immoral. It would drag Google's name in the mud, lose them customers, credibility, and most likely a decent chunk of talented employees. The liabil…

I look at the money.

Google made $10 billion last year.

In a cyber-war, how much would the Kremlin pay to disrupt every Chinese WiFi network to which an Android device has a current password?

In a shooting war, how much would the US pay? Keep in mind that the modern battlefield increasingly uses ordinary data devices particularly in counter-insurgency operations.

Jim McDonnell, Donald Douglas, Jack Northrup and Leroy Grumman did not start out as defense contractors. They diversified their corporations when voluntarily seizing the opportunity was a good alternative to the threat of compulsion during the Second World War.

This may in fact be the one time that the rules are different. But there's very little historical precedent upon which to premise such a belief. GM produces military vehicles. Westinghouse and GE produce powerplants for ballistic missile submarines.

[edit] The question of how plaintext leads directly to Google profits remains unaddressed. It is not as if Android users can recover their passwords by calling up Google customer service. On the other hand, storing passwords in plain text is usually a decision made to facilitate requests from a company's customers. Asking who constitutes Google's customers is a reasonable place to start when inferring motives.[/edit]

Re: Android saves wifi passwords in plaintext to the cloud

#112
post #99
post #51

Earlier quoted context omitted.

If you're going to dismiss an argument as "horseshit", you should perhaps offer a compelling alternative. Because your idea of what is going on is frankly ridiculous. It's easy to see the user-experience story for this. Upgrade your phone, buy a tablet, etc, and as by magic all 10 wifi networks you use work without any configuration. No need to type that 32-character nuisance of a WPA2 password again, etc. How lovely…

> Because your idea of what is going on is frankly ridiculous. Really? > It's easy to see the user-experience story for this. It's even easier to see how handy millions of wifi passwords might come in handy if you already have the information about the wifi networks you got from war-driving (street view). You now have access to millions of (private) networks all over the world which you previously had not.

  It's even easier to see how handy millions of wifi
  passwords might come in handy if you already have the 
  information about the wifi networks you got from
  war-driving (street view).
Do you have any idea what you're talking about?

Talk to a real live Googler (they exist!). Any one of them will tell you that:

(a) the war driving thing was one engineer's massive fuckup that was never wanted for any product, and the data was quickly quarantined (and only kept alive due to legal proceedings), and

(b) anything remotely close to nefarious conspiracy theories being posed for this .. sync protocol .. would never, ever pass peer review internally (let alone the flames of eng-misc).

User data confidentiality is one of (if not the most) serious topics within Google. Again, don't take my word for it, ask someone else.

To suggest that Google is collecting customer passwords for the express purpose of future network intrusion, or to share with spy agencies, is just ignorant.

Re: Android saves wifi passwords in plaintext to the cloud

#113

What key are you going to encrypt these passwords with? If you were to encrypt passwords in the cloud with a key that's stored on the device, you can't unlock the passwords on a different device (or the same device after flashing), which is the whole point of backing it up in the cloud. If you were to encrypt them with the user's Google Accounts password, the device would need to ask for that password on every startu…

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

>Google has harvested the location, name and signal strength of many millions of wireless networks across the world - an act which can be in no way cast as user convenience.

Improved location data on wifi is one way.

Re: Android saves wifi passwords in plaintext to the cloud

#114
post #51

Earlier quoted context omitted.

If you're going to dismiss an argument as "horseshit", you should perhaps offer a compelling alternative. Because your idea of what is going on is frankly ridiculous. It's easy to see the user-experience story for this. Upgrade your phone, buy a tablet, etc, and as by magic all 10 wifi networks you use work without any configuration. No need to type that 32-character nuisance of a WPA2 password again, etc. How lovely…

I agree that trusting google with wifi passwords is about as benign as it gets (especially if you already trust them with everything else) but the reason we encourage password encryption isn't because we don't trust the service provider, it's because we don't trust hackers or unethical employees. There are a lot of people who would love to get their hands on that data.

Not benign at all. Read the story about how some Facebook administrator challenged Facebookers to hack into Facebook. The way they did it was to drive by his home and impersonate his home wireless router. My understanding is that once you do that, you can do man in the middle attacks.

Example: Oh you thought you were accessing Facebook, bank, stock, tax... oh you are... but first you are passing along your password to a third party.

Also, once you gain access to the network, what percentage of networks allow administrator access over wi-fi? I would bet a good percentage. What percentage of these have the default password? Again, a good percentage. So basically, you can hijack quite a few networks this way. Do you know what most routers keep a log of? Your entire browsing history. Do you know what else you can do to the network? Open up inbound ports.

Note: The impersonation attack may work even without passwords. Figure out what his/her network name is. Give your network the same name. Scramble the signal coming from the other router. Have him/her enter in a password to your network. Voila.

Re: Android saves wifi passwords in plaintext to the cloud

#115
post #85

Earlier quoted context omitted.

You're providing innuendo and "exercises for the reader", not an argument. That's pretty weak. What would such a data set of Redmond be worth to Google? Nothing. Because accessing those networks for industrial espionage (if I read your innuendo right) would be illegal and immoral. It would drag Google's name in the mud, lose them customers, credibility, and most likely a decent chunk of talented employees. The liabil…

I look at the money. Google made $10 billion last year. In a cyber-war, how much would the Kremlin pay to disrupt every Chinese WiFi network to which an Android device has a current password? In a shooting war, how much would the US pay? Keep in mind that the modern battlefield increasingly uses ordinary data devices particularly in counter-insurgency operations. Jim McDonnell, Donald Douglas, Jack Northrup and Leroy…

  I look at the money.

  In a cyber-war, how much would the Kremlin pay to
  disrupt every Chinese WiFi network to which an Android 
  device has a current password?
Do you think Larry Page can be bought?

I'm serious: You need to consider the way Google is run before deciding if any of these theories are plausible.

This is a company which has a history of spurning money-making opportunities in favor of some higher ideal (often times to the chagrin of business-minded types within the company). To give a few examples: Licensing Android, complying with China, accepting paid placements, etc.

You can argue each of those decisions was actually more profitable for Google in the end. And that's the point: Google would not make $10B next year if they sold out their users to the Kremlin this year.

Re: Android saves wifi passwords in plaintext to the cloud

#117
post #86

Earlier quoted context omitted.

> Setting up a password for an Android device only needs to be done once for each device->network pairing. So you want _yet another_ password between the user and his magical experience or whatever ? I see myself as a "privacy enthusiast", and even I recognize that wanting to encrypt wifi passwords in this way would only appeal to ~0.01% of android users. You could argue that google could make this an option hidden u…

>> So you want _yet another_ password between the user and his magical experience or whatever ? I find this a pretty weak objection. Do you really want to trade all your stored passwords for the convenience of not having to enter 1 additional password ('my Android backup password') once every one or two years when you activate a new or additional device?? I wonder how this objection rhymes with having logins on 20+ d…

You missed the central part of my argument, so I'll reiterate it here: users don't care about this stuff, and passwords are user-hostile. Google chose to implement this a certain way that works for 99.99% of people.

Now, in the 0.01% case, your counter argument still doesn't hold, in my opinion:

> Do you really want to trade all your stored passwords for the convenience of not having to enter 1 additional password ('my Android backup password')

Yes.

Even strong wifi passwords can be brute-forced within minutes from the curb by anybody with an unmarked van and a measly few GPUs. At this point in the technology race, wifi passwords are really just keeping the honest people out. If you want something stronger, you're going to have to go to machine certificates on each laptop / mobile device.

> once every one or two years when you activate a new or additional device??

Even worse, passwords that aren't used often exit my fingers' memory and are thus lost to time (unless I write them down and store them in my safe deposit box or keepassdroid or whatever, but "hardly anybody" does this, so Google would get phone calls from users every year or two saying "can you give me the password that I'm supposed to be using to keep from giving you my passwords? kthx").

Re: Android saves wifi passwords in plaintext to the cloud

#118
post #51

Earlier quoted context omitted.

If you're going to dismiss an argument as "horseshit", you should perhaps offer a compelling alternative. Because your idea of what is going on is frankly ridiculous. It's easy to see the user-experience story for this. Upgrade your phone, buy a tablet, etc, and as by magic all 10 wifi networks you use work without any configuration. No need to type that 32-character nuisance of a WPA2 password again, etc. How lovely…

Most people really have 10 different WiFi networks? I have two. Home and work. Who has 10? Apple solved this by supporting local backups. My phone backs up to my computer. When I restore to a new device, the backup goes with it. When I set up a completely new device -- which happens only once every couple of years -- I set up WiFi again. I've never, ever, ever thought "oh wow, setting up WiFi is just So Hard! I wish…

- Home - Brother's house - Other brother's house - Sister's house - Brother-in-law's house - Work #1 - Work #2 - Cafe #1 - Cafe #2 - Cafe #3 - School

And these are just the ones that I remember.

Re: Android saves wifi passwords in plaintext to the cloud

#119
post #112
post #99

Earlier quoted context omitted.

> Because your idea of what is going on is frankly ridiculous. Really? > It's easy to see the user-experience story for this. It's even easier to see how handy millions of wifi passwords might come in handy if you already have the information about the wifi networks you got from war-driving (street view). You now have access to millions of (private) networks all over the world which you previously had not.

It's even easier to see how handy millions of wifi passwords might come in handy if you already have the information about the wifi networks you got from war-driving (street view). Do you have any idea what you're talking about? Talk to a real live Googler (they exist!). Any one of them will tell you that: (a) the war driving thing was one engineer's massive fuckup that was never wanted for any product, and the data…

So the NSA knows that Google has access to this information. I bet they have ALREADY forced Google to give this information up even if only on a warrant basis (but perhaps not).

Re: Android saves wifi passwords in plaintext to the cloud

#120
No need to belabor the point given the many examples beyond this one. If you want security, you're not going with Android. If you want configurability, you're not going with iOS.

Android: slurping phone numbers, texting behind the scenes on your behalf, etc...

iOS: no access to apps that Apple doesn't approve, no replacement of built-in apps with third-party apps, etc...

These systems were not built exactly with your benefit in mind. Android was built to prevent Apple domination of mobile and thus continue selling ads by providing services. Apple has several services that would be much more useful cross platform but are not: Facetime, iMessage, etc... and that reinforce platform lock-in.

Post reply on HN