Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

101–110 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#101

Earlier quoted context omitted.

It could be like leaving your bank account password in the open. Your bank account password could be sniffed probably very easily by someone who is connected to your network. Now imagine somebody exposes some way to get the password of your home network from the google servers.

With all these NSA revelations and Richard Stallman being right all along. there is no such thing as being secure or encrypted unless you have encrypted it yourself.

And built your own hardware and installed your own cell towers. And control all the servers, because even if they are made with 100% open-source code, someone could just modify it. Also you must be sure nobody else has read access to it, because being 100% open source does not mean "no-one can read it".

I don't see how trusted networking can be possible in stallmanic world.

Re: Google knows nearly every Wi-Fi password in the world

#102
post #62

Are wifi passwords considered a security issue? I treat it the same way as a flimsy lock on a garden shed - I'd prefer both the shed and wifi to be open, but there's a formal "lock" to keep out teenage pranksters and drunks.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

Why is google having my Wifi password a bad thing? I'd be happy to let EVERYONE have it, and the only thing I fear is neighbour teenagers overloading the connection with torrents so that it's not usable for me.

As long as I expect them not to overload my wifi too much, I'm perfectly happy with google or FBI or KGB or friends or random strangers to use have that wifi password.

If wifi routers were good at traffic shaping / quality of service tech, I'd put no passwords at all on wifi devices - if a neighbour wants to browse some web, then it's a good deed to make it easier.

Re: Google knows nearly every Wi-Fi password in the world

#104
post #80

Security is about tradeoffs. How bad would it be if someone else got this information? How helpful is it to me to give it to this third party? Wireless passwords are a huge pain: visit someone's house, ask them for their password, and then feel guilty while they look through various papers to find a long string of hex digits which are so annoying to enter on the phone. This pain makes the tradeoff well worth if for m…

QR codes could make entering secure keys in to mobile devices easier. Variations of Wi-Fi quick set-up can also be made reasonably secure, implementations just suck.

Re: Google knows nearly every Wi-Fi password in the world

#105
post #77
post #62

Earlier quoted context omitted.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

What stuff could they do? Log into your AP to torrent Breaking Bad episodes?

Or someone else could do something that lands you in trouble... https://news.ycombinator.com/item?id=6358837

Re: Google knows nearly every Wi-Fi password in the world

#107
post #77
post #62

Earlier quoted context omitted.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

What stuff could they do? Log into your AP to torrent Breaking Bad episodes?

Grab some confidential client documents that a not-so-clever employee dropped in their shared folder? Your example is at one end of the scale, my example is at the other end and there's lots between.

Re: Google knows nearly every Wi-Fi password in the world

#108
post #77
post #62

Earlier quoted context omitted.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

What stuff could they do? Log into your AP to torrent Breaking Bad episodes?

[deleted]

Re: Google knows nearly every Wi-Fi password in the world

#109
post #88

Earlier quoted context omitted.

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it. Google Ventures, no matter how spectacularly they might do as VCs, will always be several orders of magnitude less important to Google than Gmail. Google Ventures invests $300 million pe…

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it. That's ridiculous. The risk isn't institutionalized abuse, the threat is an unscrupulous guy in the Ventures group who has a buddy who works in the gmail (or other) groups. Calls him up…

You make the false assumption that people in different divisions of a very large company would be more likely to help each other outside of the corporate reward structure than they would be to help someone outside the company, who they might just happen to have personal or social obligations to.

If there were an unscrupulous person in the gmail group, he would be more likely to break company policy (and, I think, the law) with someone who does not work for Google than with someone who does, unless it were motivated by someone up the chain at Google itself.

Saying that someone at Gmail is sharing your secrets may be a worry. That they would share them with Google Ventures is far less likely than that they would share them with someone else entirely. And frankly, if someone were to try to profit from stolen information, they'd be looking at hedge fund manager emails and investment banker emails. The very slight edge you might get from seeing some VC's email is worth less than a cup of coffee at Starbucks, if you risk-adjust it and discount it back to the present.

Re: Google knows nearly every Wi-Fi password in the world

#110
post #87

Earlier quoted context omitted.

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

> passwords are either easy for computers to crack or hard for humans to remember

Obligatory xkcd comic: https://xkcd.com/936/

Post reply on HN