Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

61–70 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#61
post #32
post #6

Earlier quoted context omitted.

Do we know that's not happening? The article says "they can decrypt them, given only a Gmail address and password" which implies that it would be encrypted with your password.

The article states that Google has refused to comment on whether the data is encrypted on their servers. So it seems fair to assume it isn't.

No, it is fair to assume nothing without any information.

Re: Google knows nearly every Wi-Fi password in the world

#62

Are wifi passwords considered a security issue? I treat it the same way as a flimsy lock on a garden shed - I'd prefer both the shed and wifi to be open, but there's a formal "lock" to keep out teenage pranksters and drunks.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it.

Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying.

Since it's probably personal information it's also probably covered by data protection laws in some countries.

Re: Google knows nearly every Wi-Fi password in the world

#63
post #35

What's wrong in it.It's not a bank account rite.

It could be like leaving your bank account password in the open. Your bank account password could be sniffed probably very easily by someone who is connected to your network. Now imagine somebody exposes some way to get the password of your home network from the google servers.

With all these NSA revelations and Richard Stallman being right all along. there is no such thing as being secure or encrypted unless you have encrypted it yourself.

Re: Google knows nearly every Wi-Fi password in the world

#64
post #16

And in addition to that they have the audacity to not make them accessible to the user! No way to look up your own wireless password in your phone, i.e. to tell a guest, thats just ridiculous.

On (jailbroken) iOS there is an app which displays all saved WIFI passwords. I am sure there are something similar to Androids.

On Android(rooted) we can see all the saved WIFI passwords in /data/misc/wifi/wpa_supplicant.conf file.

Re: Google knows nearly every Wi-Fi password in the world

#66

Earlier quoted context omitted.

I agree that it's unlikely Google as a whole would decide to read/use confidential data. on the other hand, the idea that someone w/in Google might abuse their position is completely plausible. if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data? edit: to be clear, I use Google servic…

> on the other hand, the idea that someone w/in Google might abuse their position is completely plausible. > if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data? Already happened: http://gawker.com/5638874/david-barksdale-wasnt-googles-firs...

exactly. fill the most solipsistic company in the world w/ self-exalting geeks & you're bound to get more than a few creeps who don't understand social boundaries.

Re: Google knows nearly every Wi-Fi password in the world

#67
post #27
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

> Just out of curiosity, how would we know even if a secret was let out to, say, the NSA

And the smartest thing to do, whether you are the NSA or some other foreign government or any entity that holds that information, is to keep quiet about it. The less others know that you know something, the more power you have.

For that reason, it is unlikely that we will see these powers used by the NSA, or other government. It is in their best interest to hold on to that data as secretly as possible and as restrictively as possible, to avoid the chance of others getting a hold of the data. Snowden if anything has only given the NSA and all others who hold the information that we do not know about reason to be careful open even mentioning that they have the data, to anyone.

Re: Google knows nearly every Wi-Fi password in the world

#68
post #27
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

Is this Googles failure or are goverments the issue?

You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices.

Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic options for any of the mayor tech players right now, when they face a data request from the US goverment other than fighting it in the courts? (which they do)

Moving all Google employees to Iceland or some asian country and closing all offices in the US/Western Europe? Closing down any service that collects private data?

Re: Google knows nearly every Wi-Fi password in the world

#69
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

I agree that it's unlikely Google as a whole would decide to read/use confidential data. on the other hand, the idea that someone w/in Google might abuse their position is completely plausible. if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data? edit: to be clear, I use Google servic…

You should all read "the silicon jungle". It's by an ex-googler, and it's amazing.

Re: Google knows nearly every Wi-Fi password in the world

#70
post #3

when i read the title, i though "really?! how?" then i read the article and realized any time i have restored my android phone, then entered my Google account, it automagically connects to all access points i usually use (home, work, other office, etc)...

But they didn't have to design it in such a way as to share the passwords with google. All your data could be encrypted with your google account's password (or some other secret derived from it) on the device and backed up encrypted. When you enter your account password on a new device, it then downloads the encrypted data and decrypts and restores it. Same user experience without exposing private data.

> Same user experience without exposing private data.

Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. They probably already store your wifi password encrypted -- it's just when the device asks for it, Google decrypts it and sends it back to you. So in all likelihood, they're already doing what you want.

They could have done it by asking the user to provide a new unique password that would have to be entered on each new device. That would provide additional security as only the device could decrypt the password. However, (a) because such a password would only be used once or twice a year at most, no one would remember it and the whole feature would be useless, and (b) you still have to trust Google to not send the password after the device decrypts it, and if you trust the OS vendor to not backdoor the OS, you might as well trust them to not backdoor their own servers to access the same data.

Post reply on HN