Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

71–80 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#71
post #41

> And, although they have never said so directly, it is obvious that Google can read the passwords. This is not necessarily true - they could encrypt this data so that it requires a user password to read, and transmit these settings for client-side decryption. They probably don't though, and in all likeliness can read your WiFi password.

This fails if the user forgets their password.

Re: Google knows nearly every Wi-Fi password in the world

#72
post #37

This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust. The reason people don'…

> This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. See a couple of months ago (the context is iMessages but the level of implicit trust is the same): https://news.ycombinator.com/item?id=5943778

Acknowledged. I still argue that Google's getting more than its fair share of abuse, though.

Re: Google knows nearly every Wi-Fi password in the world

#73
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

[deleted]

Re: Google knows nearly every Wi-Fi password in the world

#74
post #37

This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust. The reason people don'…

> "The reason people don't seem to be ganging up on Facebook, Apple, etc. in a similar way is because they never really earned that faith. Take Facebook: from the very start their founder was known to consider their users "dumb fucks" for entrusting him with their privacy."

Not really. We only learned of FB's attitude to privacy when they started changing defaults and were being sued by the Winklevoss bros. Otherwise, we may never have known what he thought of his early users.

Apple never claimed "Don't be evil" as a motto and they do appear to care more about security. There is encryption in some of their products (even though they can likely still gain access - a point that is made in the article). Arguably, they've done more than Google to demonstrate that they care about my data.

Re: Google knows nearly every Wi-Fi password in the world

#75
post #37

This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust. The reason people don'…

No, the same point can't be made against Apple.

Apple encrypt WiFi passwords and never store them in plain text – not on their servers and not on the device. The encryption requires your login password to decrypt which Apple also don't store in plain text on their servers (although it is accessible on the device if you don't use a PIN or password, it is not backed up to iCloud).

The reason why this allegation is levelled against Google: they don't encrypt backups and they don't encrypt WiFi passwords on the device.

A little more specifically about iOS WiFi passwords: the Keychain (which is where WiFi passwords are backed up on iOS and the Mac) is AES encrypted and requires your login password (or your Apple ID password) to decrypt. Unless Apple is also stealing plain text versions of your login passwords (there's no indication that they are) then it is not possible for Apple to read your WiFi password. Yes, theoretically, they could steal your Apple ID password too but there's no indication that they do (and they've talked about the exact security on Apple IDs following the developer.apple.com breach recently).

Re: Google knows nearly every Wi-Fi password in the world

#77
post #62

Are wifi passwords considered a security issue? I treat it the same way as a flimsy lock on a garden shed - I'd prefer both the shed and wifi to be open, but there's a formal "lock" to keep out teenage pranksters and drunks.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

What stuff could they do? Log into your AP to torrent Breaking Bad episodes?

Re: Google knows nearly every Wi-Fi password in the world

#79
post #25
post #20

I am not sure why is this such a problem. OK, when NSA goes physically near my home, they can connect to my WiFi and secretly use my internet connection. That's not really what I am concerned about.

People secure their Wi-Fi for more than just their connection. There is likely to be file servers, media centres, printers, scanners, radios, TVs, tablets, phones, computers with shared folders, security cameras etc all connected to the local network.

They should be protected by additional means anyway.

Re: Google knows nearly every Wi-Fi password in the world

#80
Security is about tradeoffs. How bad would it be if someone else got this information? How helpful is it to me to give it to this third party? Wireless passwords are a huge pain: visit someone's house, ask them for their password, and then feel guilty while they look through various papers to find a long string of hex digits which are so annoying to enter on the phone. This pain makes the tradeoff well worth if for me (and I suspect for nearly everyone) when balanced against the low risk of Google doing something nasty with the saved passwords.

(Disclaimer: I work for Google, but if I had an iPhone I'd want the same functionality.)

Post reply on HN