Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

111–120 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#111

Earlier quoted context omitted.

Blamed and shamed for what? I suspect most people are more than happy that they can carry their existing settings across to a new 'phone and it Just Works™...

It's convenient for the owner of the Android phone, but the wifi password is not necessarily theirs to give away. That's the problem. It's not because your friends and family have given you their wifi password that they intended to give that password to Google as well. You're trading their security for your convenience.

It's certainly a problem. I don't think Google will, or indeed should, do anything about it though.

I'd like to see routers using the passphrase to generate a long lived authentication token. "Good netizens", as the phrase goes, could ensure their routers / client devices didn't store passphrases without inconveniencing the end user.

Re: Google knows nearly every Wi-Fi password in the world

#112
post #21

Earlier quoted context omitted.

> "As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again." I used to think this but now I'm not so sure. With the way services like FB and others slowly change settings, Sony gets hacked and other data breaches, news about govt spying etc, I wonder whether the mass public is suffering from Learned Helplessness [1]. After all, what alternatives do mo…

From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee... . >In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an incident this spring involving a 15-year-old boy who he'd befriended, Barksdale tapped into call logs from Google Voice, Google's Internet phone service, after the boy refused to tell him the name of his ne…

Wish I had more upvotes.

Re: Google knows nearly every Wi-Fi password in the world

#113
post #37

This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust. The reason people don'…

Although both are American companies operating under the same rules, there is a fundamental difference between Apple and Google's business models.

Apple makes its money from selling you new hardware every year or two - they need to make you lust after slick, shiny things every keynote.

Google makes its money from knowing about you, mining that data and converting that into advertising clicks - they need to collect as much information about you as possible.

Which means that the same pieces of data have different value to the two companies.

(Of course, Facebook follows a similar model to Google)

Re: Google knows nearly every Wi-Fi password in the world

#114

It's troubling to see this, but I've always used MAC Filtering on my home network on top of WPA2 to limit what devices can connect to my network.

MAC filtering is useless, even in combination with WPA2. An attacker only has to sniff for a MAC your AP is happy to talk to and then changes theirs.

Re: Google knows nearly every Wi-Fi password in the world

#117
post #87

Earlier quoted context omitted.

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

apriorixWasxTotallyxWrongxAboutxThis

is a really good password that people can remember easily.

Re: Google knows nearly every Wi-Fi password in the world

#118
post #87
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

WPA2 is probably ok with a long passwor(d|phrase). The problem is nto WPA2 per se but another bundled technology in many rounters. WPS -- that is crack-able very easily. Many routers that even say they disable it don't really do it.

Search for it there is a list of routers that are better than others. With WPA+WPS we are mostly back to WEP days where any kid with a laptop and some googling skills can get access to many wireless networks.

Re: Google knows nearly every Wi-Fi password in the world

#119
post #62

Earlier quoted context omitted.

Google having all the WIFI passwords is about as worrying as a government having a 3 day cache of everything - not very worrying unless they do stuff with it. Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying. Since it's probably personal information it's also probably covered by data protection laws in some countries.

Why is google having my Wifi password a bad thing? I'd be happy to let EVERYONE have it, and the only thing I fear is neighbour teenagers overloading the connection with torrents so that it's not usable for me. As long as I expect them not to overload my wifi too much, I'm perfectly happy with google or FBI or KGB or friends or random strangers to use have that wifi password. If wifi routers were good at traffic shap…

I'm unsure, but doesn't WPA2 password knowledge allows to decrypt your traffic? (Possibly with an active attack to re-initiate handshake?)

I.e. someone who knows your password could drive by your home, listen to the air and see what you're doing online.

Re: Google knows nearly every Wi-Fi password in the world

#120
post #77

Earlier quoted context omitted.

What stuff could they do? Log into your AP to torrent Breaking Bad episodes?

Grab some confidential client documents that a not-so-clever employee dropped in their shared folder? Your example is at one end of the scale, my example is at the other end and there's lots between.

If you think your example is on one end of the scale you got too little imagination =)
Post reply on HN