Earlier quoted context omitted.
The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.
Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.
Google knows nearly every Wi-Fi password in the world
131–140 of 312 posts
Re: Google knows nearly every Wi-Fi password in the world
#132Earlier quoted context omitted.
> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…
Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…
Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did.
To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power.
Snowden is a significant outlier... hiring policies are intended to prevent the hire of the kind of person who would do what he did. The scary thing is that Google's hiring practices achieve the same thing.
Re: Google knows nearly every Wi-Fi password in the world
#133Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…
All these secrets have been sent in plaintext between Google data-centres over 'dark fibre' we now suspect the NSA has been wholescale recording. There are belated efforts by google to encrypt the traffic between its data centres, but its basically too late.
Re: Google knows nearly every Wi-Fi password in the world
#134Re: Google knows nearly every Wi-Fi password in the world
#135Earlier quoted context omitted.
Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.
until you buy an apple TV (and don't want to cable it). Fun ensues.
Re: Google knows nearly every Wi-Fi password in the world
#136Earlier quoted context omitted.
Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…
Is this Googles failure or are goverments the issue? Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did. To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power. Snowden is a significant outlier... hiring policies are intende…
Re: Google knows nearly every Wi-Fi password in the world
#137Earlier quoted context omitted.
The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.
> passwords are either easy for computers to crack or hard for humans to remember Obligatory xkcd comic: https://xkcd.com/936/
Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination.
Crackers will simply start using wordlist rules to generate large lists of meshed together dictionary words and use them if they have good reason to believe you're using this pattern (pretty sure it's simple with tools like Crunch). Whether they'll guess the proper order is unknown, but as with any other case people will use certain permutations and combinations more than others.
Re: Google knows nearly every Wi-Fi password in the world
#138The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
Yeah and those locks on your doors are a joke! Why are you pretending your home has an expectation of privacy? So dumb! Of COURSE anybody can just come into your house any time they want.
Re: Google knows nearly every Wi-Fi password in the world
#139Earlier quoted context omitted.
The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.
apriorixWasxTotallyxWrongxAboutxThis is a really good password that people can remember easily.
Re: Google knows nearly every Wi-Fi password in the world
#140Earlier quoted context omitted.
> "As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again." I used to think this but now I'm not so sure. With the way services like FB and others slowly change settings, Sony gets hacked and other data breaches, news about govt spying etc, I wonder whether the mass public is suffering from Learned Helplessness [1]. After all, what alternatives do mo…
From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee... . >In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an incident this spring involving a 15-year-old boy who he'd befriended, Barksdale tapped into call logs from Google Voice, Google's Internet phone service, after the boy refused to tell him the name of his ne…
This happens in major, respected newspapers. It happens in an extremely disciplined and well-trained superpower's military. Small town telephone operators were sometimes known to spy on the communications of people they knew, and post office workers would sometimes gossip about postal metadata. Organizations can still have integrity (ok, well, maybe not telecoms) when there are a handful of swiftly punished incidents. I'd be concerned if there was a culture of disregard for privacy or a lack of internal controls, unrestricted access for everyone (Barksdale was a Site Reliability Engineer with a legitimate need to access production data, I believe), or no punishment, but this case doesn't invalidate Google's products.