Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

131–140 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#131

Earlier quoted context omitted.

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.

until you buy an apple TV (and don't want to cable it). Fun ensues.

Re: Google knows nearly every Wi-Fi password in the world

#132
post #27

Earlier quoted context omitted.

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…

Is this Googles failure or are goverments the issue?

Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did.

To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power.

Snowden is a significant outlier... hiring policies are intended to prevent the hire of the kind of person who would do what he did. The scary thing is that Google's hiring practices achieve the same thing.

Re: Google knows nearly every Wi-Fi password in the world

#133
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

All these secrets have been sent in plaintext between Google data-centres over 'dark fibre' we now suspect the NSA has been wholescale recording. There are belated efforts by google to encrypt the traffic between its data centres, but its basically too late.

It's not 'dark fibre' if you're using it.

Re: Google knows nearly every Wi-Fi password in the world

#135
post #131

Earlier quoted context omitted.

Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.

until you buy an apple TV (and don't want to cable it). Fun ensues.

I use a random 63 character WPA2 password, and my solution was to cable it initially, and then set up the WiFi password using the iPhone remote app.

Re: Google knows nearly every Wi-Fi password in the world

#136

Earlier quoted context omitted.

Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…

Is this Googles failure or are goverments the issue? Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did. To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power. Snowden is a significant outlier... hiring policies are intende…

You are unlikely to find anyone at management level who feels so strongly opposed to lawful government surveillance that he'd risk his personal freedom over it.

Re: Google knows nearly every Wi-Fi password in the world

#137
post #110

Earlier quoted context omitted.

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

> passwords are either easy for computers to crack or hard for humans to remember Obligatory xkcd comic: https://xkcd.com/936/

I loathe whenever people post that comic for one simple reason.

Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination.

Crackers will simply start using wordlist rules to generate large lists of meshed together dictionary words and use them if they have good reason to believe you're using this pattern (pretty sure it's simple with tools like Crunch). Whether they'll guess the proper order is unknown, but as with any other case people will use certain permutations and combinations more than others.

Re: Google knows nearly every Wi-Fi password in the world

#138
post #128
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Yeah and those locks on your doors are a joke! Why are you pretending your home has an expectation of privacy? So dumb! Of COURSE anybody can just come into your house any time they want.

He isn't advising you don't need to lock your house because the locks are insecure. He's just pointing out that you probably shouldn't lose sleep over if someone can break in or not, especially when windows are easily broken.

Re: Google knows nearly every Wi-Fi password in the world

#139
post #117

Earlier quoted context omitted.

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

apriorixWasxTotallyxWrongxAboutxThis is a really good password that people can remember easily.

Added to dictionary.

Re: Google knows nearly every Wi-Fi password in the world

#140
post #21

Earlier quoted context omitted.

> "As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again." I used to think this but now I'm not so sure. With the way services like FB and others slowly change settings, Sony gets hacked and other data breaches, news about govt spying etc, I wonder whether the mass public is suffering from Learned Helplessness [1]. After all, what alternatives do mo…

From http://gawker.com/5637234/gcreep-google-engineer-stalked-tee... . >In at least four cases, Barksdale spied on minors' Google accounts without their consent, according to a source close to the incidents. In an incident this spring involving a 15-year-old boy who he'd befriended, Barksdale tapped into call logs from Google Voice, Google's Internet phone service, after the boy refused to tell him the name of his ne…

In any organization of Google's size, there are bound to be a few bad apples. The organization can still see that as totally wrong and do its best to remove them, whether out of professional integrity or simple self-preservation instinct.

This happens in major, respected newspapers. It happens in an extremely disciplined and well-trained superpower's military. Small town telephone operators were sometimes known to spy on the communications of people they knew, and post office workers would sometimes gossip about postal metadata. Organizations can still have integrity (ok, well, maybe not telecoms) when there are a handful of swiftly punished incidents. I'd be concerned if there was a culture of disregard for privacy or a lack of internal controls, unrestricted access for everyone (Barksdale was a Site Reliability Engineer with a legitimate need to access production data, I believe), or no punishment, but this case doesn't invalidate Google's products.

Post reply on HN