Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

1–10 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#4
Not sure what the author is after here. I mean he's not breaking any news, he admits as much, he also links to some of the articles that were published weeks ago that do a better job of discussing the security/convenience trade offs. Seems like he missed the furore at the the time and decided to compensate with a woefully inaccurate and baiting headline.

Re: Google knows nearly every Wi-Fi password in the world

#5
post #3

when i read the title, i though "really?! how?" then i read the article and realized any time i have restored my android phone, then entered my Google account, it automagically connects to all access points i usually use (home, work, other office, etc)...

But they didn't have to design it in such a way as to share the passwords with google. All your data could be encrypted with your google account's password (or some other secret derived from it) on the device and backed up encrypted. When you enter your account password on a new device, it then downloads the encrypted data and decrypts and restores it. Same user experience without exposing private data.

Re: Google knows nearly every Wi-Fi password in the world

#6
post #3

when i read the title, i though "really?! how?" then i read the article and realized any time i have restored my android phone, then entered my Google account, it automagically connects to all access points i usually use (home, work, other office, etc)...

But they didn't have to design it in such a way as to share the passwords with google. All your data could be encrypted with your google account's password (or some other secret derived from it) on the device and backed up encrypted. When you enter your account password on a new device, it then downloads the encrypted data and decrypts and restores it. Same user experience without exposing private data.

Do we know that's not happening? The article says "they can decrypt them, given only a Gmail address and password" which implies that it would be encrypted with your password.

Re: Google knows nearly every Wi-Fi password in the world

#7

Not sure what the author is after here. I mean he's not breaking any news, he admits as much, he also links to some of the articles that were published weeks ago that do a better job of discussing the security/convenience trade offs. Seems like he missed the furore at the the time and decided to compensate with a woefully inaccurate and baiting headline.

yes, but to be fair, this issue deserves to be more well known. it wont be fixed if google isn't blamed and shamed for it repeatedly.

Re: Google knows nearly every Wi-Fi password in the world

#9
Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for.

Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publish videos saying that no-one can ever walk out of a Google data centre with a hard drive.

I continue to use the services I use because I find the benefit I gain from them, more useful than the potential risk of exposure.

Should these secrets be encrypted? If they were, it would be possible for Google to steal your key if they wanted to. This is the same kind of perception problem that led to the Chrome team being hauled over the coals in public for not encrypting saved passwords. They have to be available to be useful, but people would rather perceive they weren't available.

Re: Google knows nearly every Wi-Fi password in the world

#10
For convenience, most people won't opt out of it. Most people won't bother at all. Google employees(or even NSA if you don't do anything illegal) coming to your home/office to use your WiFi is a joke! Only the paranoid ones are perturbed by these kinds of revelations, and they are ready to face the inconvenience caused.

I didn't use last pass until recently when keeping a difficult password on every site became a major pain given that countless numbers of password enforcing rules are there on the web some requiring at least one caps, some enforcing using at least one symbol but not using a ~ or a # yeda yeda. I gave up on it. Every damn time I had to reset password on services I use less frequently. But now I don't. Although LastPass claims that they keep the passwords encrypted and they themselves can not read them. But I don't believe them. Login to lastpass.com. Click your vault on top right corner. Click the pencil against any site in the list. Click the 'show' link in front of password field. And your password is staring at you in plain text. And it has been accessed at lastpass.com. Once they start storing master passwords, or once someone cracks their hash you are done with. But there is no simple and easy alternative. To get the job done we need to make these sacrifices.

Post reply on HN