Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

91–100 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#91
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

By that logic Google wouldn't encrypt the data between servers, in response to NSA revelations either. Yet, they're doing that. The point is it should at least be secure from outsiders/internal spies.

Re: Google knows nearly every Wi-Fi password in the world

#92
post #71
post #41

> And, although they have never said so directly, it is obvious that Google can read the passwords. This is not necessarily true - they could encrypt this data so that it requires a user password to read, and transmit these settings for client-side decryption. They probably don't though, and in all likeliness can read your WiFi password.

This fails if the user forgets their password.

Good point.

Re: Google knows nearly every Wi-Fi password in the world

#93
post #70

Earlier quoted context omitted.

But they didn't have to design it in such a way as to share the passwords with google. All your data could be encrypted with your google account's password (or some other secret derived from it) on the device and backed up encrypted. When you enter your account password on a new device, it then downloads the encrypted data and decrypts and restores it. Same user experience without exposing private data.

> Same user experience without exposing private data. Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. They probably already store your wifi password encrypted -- it's just when the device asks for it, Google decrypts it and sends it back to you. So in all likelihood, they…

Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained.

Probably, but not necessarily. All they need to know is the hash of your password. When you set up a new device, it can call out to Google to authenticate without sending a cleartext password (similar to HTTP's Digest auth). Once you've authenticated and retrieved your encrypted settings, the password can be used locally to decrypt the settings. The password never has to leave the device.

If they haven't done it this way (and unless the article's author knows something, I don't think you can tell if they're doing it this way or not from observed behavior) they're either (a) lazy or (b) nefarious. I'm guessing lazy, since that's the reason for most developers who implement poor security... they just don't spend enough time thinking about security of the features they're working on.

Re: Google knows nearly every Wi-Fi password in the world

#94
post #79
post #25

Earlier quoted context omitted.

People secure their Wi-Fi for more than just their connection. There is likely to be file servers, media centres, printers, scanners, radios, TVs, tablets, phones, computers with shared folders, security cameras etc all connected to the local network.

They should be protected by additional means anyway.

Disregarding the fact that this would completely bypass the border routers.

Devices in an internal network maybe protected, but they are never as protected as they are from requests coming from the internet.

Re: Google knows nearly every Wi-Fi password in the world

#95
post #21
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

> "As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again." I used to think this but now I'm not so sure. With the way services like FB and others slowly change settings, Sony gets hacked and other data breaches, news about govt spying etc, I wonder whether the mass public is suffering from Learned Helplessness [1]. After all, what alternatives do mo…

From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee.... >In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an incident this spring involving a 15-year-old boy who he'd befriended, Barksdale tapped into call logs from Google Voice, Google's Internet phone service, after the boy refused to tell him the name of his new girlfriend, according to our source. After accessing the kid's account to retrieve her name and phone number, Barksdale then taunted the boy and threatened to call her. In other cases involving teens of both sexes, Barksdale exhibited a similar pattern of aggressively violating others' privacy, according to our source. He accessed contact lists and chat transcripts, and in one case quoted from an IM that he'd looked up behind the person's back. (He later apologized to one for retrieving the information without her knowledge.) In another incident, Barksdale unblocked himself from a Gtalk buddy list even though the teen in question had taken steps to cut communications with the Google engineer.

I guess there are similar incidents happening at almost all cloud providers, but even if detected by the company, we don't hear about them because they're really bad PR. All they come up with is, "trust us, things are secured". And no one cares anyway because Gmail, Docs and Outlook.com are slick and convenient.

Re: Google knows nearly every Wi-Fi password in the world

#96
post #70

Earlier quoted context omitted.

> Same user experience without exposing private data. Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. They probably already store your wifi password encrypted -- it's just when the device asks for it, Google decrypts it and sends it back to you. So in all likelihood, they…

Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. Probably, but not necessarily. All they need to know is the hash of your password. When you set up a new device, it can call out to Google to authenticate without sending a cleartext password (similar to HTTP's Digest auth).…

With your design, a user with a lost password also loses all their data. While that might be better from a security perspective, I can't remember the last time I used a system that did not keep all my data when I set a new password, without having the old one. Such a thing would annoy many users.

Re: Google knows nearly every Wi-Fi password in the world

#97
post #72

Earlier quoted context omitted.

> This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. See a couple of months ago (the context is iMessages but the level of implicit trust is the same): https://news.ycombinator.com/item?id=5943778

Acknowledged. I still argue that Google's getting more than its fair share of abuse, though.

Fair share? Abuse? It is a criticism made against a corporation. It deserves scrutiny and a critical eye whenever it fails, regardless of what it's competitors do.

I hate to say it because I abhor the word, but this reeks of fanboyism.

Re: Google knows nearly every Wi-Fi password in the world

#98
post #87
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure.

Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

Re: Google knows nearly every Wi-Fi password in the world

#99
post #70

Earlier quoted context omitted.

> Same user experience without exposing private data. Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. They probably already store your wifi password encrypted -- it's just when the device asks for it, Google decrypts it and sends it back to you. So in all likelihood, they…

Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. Probably, but not necessarily. All they need to know is the hash of your password. When you set up a new device, it can call out to Google to authenticate without sending a cleartext password (similar to HTTP's Digest auth).…

True, but I was thinking more along the paranoid lines of someone who would think it was a huge scandal that Google might know your wifi password. If you distrust Google enough to be really worried about that, then I'm not sure why you'd trust an Android phone or a Chrome browser to not capture your plaintext password. There are all sorts of ways that Google might have access to your password, but those are a couple of ways in which they must. It's only trust that lets most of us not worry about it.

Re: Google knows nearly every Wi-Fi password in the world

#100
post #87
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

WPA2 is fine for what it's intended, provided you're using a long random key, otherwise the number of key-strengthening iterations could use some beefing up.

There are a few problems with all PSK schemes that make internal attacks problematic. Anyone who sniffs your initial handshake and knows the master PSK can read your traffic. There's a lack of mutual authentication. Having a scheme where each device registers its own password with the AP would probably be better.

Other than that, it's generally a good solution, why do you feel it needs replacing?

Post reply on HN