Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

151–160 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#151
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

While I don't like at all the idea of government surveillance without court order, I find the idea of corporate surveillance even more horrifying.

Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not from my non-US perspective) is revealed to snoop on people illegally and people rage. I don't actually question the rage – but I see the complacent acceptance of the private companies using the same data as amusing.

A large part (not whole, though) of what NSA does is taking your stuff from the place it already shouldn't have been. We're complaining about a fireplace in a burning forest.

Re: Google knows nearly every Wi-Fi password in the world

#152
post #133

Earlier quoted context omitted.

All these secrets have been sent in plaintext between Google data-centres over 'dark fibre' we now suspect the NSA has been wholescale recording. There are belated efforts by google to encrypt the traffic between its data centres, but its basically too late.

It's not 'dark fibre' if you're using it.

He's just talking about the time between the bits.

Re: Google knows nearly every Wi-Fi password in the world

#153
post #27

Earlier quoted context omitted.

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…

> You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices.

You could encrypt the data locally before sending it to the server. You might also question whether this model of computing is in fact sensible. There are at least partial alternatives, for instance holding all data locally on a smartphone, and then plugging that in to use as a desktop, tablet etc. We should be asking whether the advantages of the Google model outweigh its (significant) disadvantages.

Re: Google knows nearly every Wi-Fi password in the world

#154
post #131

Earlier quoted context omitted.

Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.

until you buy an apple TV (and don't want to cable it). Fun ensues.

Bluetooth keyboard. Used it to enter my 63 character wifi password just last night on my Apple TV.

Re: Google knows nearly every Wi-Fi password in the world

#155
post #131

Earlier quoted context omitted.

until you buy an apple TV (and don't want to cable it). Fun ensues.

I use a random 63 character WPA2 password, and my solution was to cable it initially, and then set up the WiFi password using the iPhone remote app.

And if all else fails, entering 63 characters is not really that hard either (unless the Apple TV has one of these weird on-screen letter-choosing wheels you sometimes encounter in videogame consoles and the like).

Re: Google knows nearly every Wi-Fi password in the world

#156
post #128
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Yeah and those locks on your doors are a joke! Why are you pretending your home has an expectation of privacy? So dumb! Of COURSE anybody can just come into your house any time they want.

Most people aren't even wearing bullet-proof helmets when they sit next to a window leaving them totally vulnerable to snipers. They get what they deserve.

Re: Google knows nearly every Wi-Fi password in the world

#157
post #131

Earlier quoted context omitted.

Fortunately, it is entirely unnecessary to remember your Wifi password (provided that you trust your devices…). Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.

until you buy an apple TV (and don't want to cable it). Fun ensues.

Or Roku or a nest... Tons of devices use wifi but lack cameras or copy/paste.

Re: Google knows nearly every Wi-Fi password in the world

#158
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

While I don't like at all the idea of government surveillance without court order, I find the idea of corporate surveillance even more horrifying. Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not f…

current government is irrelevant. The data captured now will exist likely forever. If at any point there's a new leader who wants to wipe out a race, he'll have much easier time than checking everyone's papers.

I don't mind getting targeted ads, I prefer them to spam ads.

Re: Google knows nearly every Wi-Fi password in the world

#159
> backing up Wi-Fi passwords along with other assorted settings. And, although they have never said so directly, it is obvious that Google can read the passwords.

That's not obvious. It's possible, common, and dare I say a "best practice" to store stuff like this encrypted. To be decrypted only on the device.

Also, wifi passwords, Oh my!!! Security wise you should treat your wifi network as open whether it is or not. I.e. isolate it, firewall it, do not trust it.

Re: Google knows nearly every Wi-Fi password in the world

#160
post #142

Earlier quoted context omitted.

Honestly, I use WEP encryption because I know that WiFi security is a house of cards in general. As you've said, it's enough to prevent the typical user from leeching bandwidth. The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.

- Until they link this post back to you, and argue that you knowingly weakened your security. - Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level. - Until they argue that your technical background means that you should have known better that WEP is crackable.

That's all well and good, but I have still not given authorization for the use of my network to the malicious user. An open network invites legal dispute as to whether the lack of encryption constitutes implicit permission to use the network [1]. By having encryption, even if easily cracked, I have let the malicious user that they are not welcome on my network and have absolved myself of any responsibility for their actions.

Following your reasoning, my background means that I should know that I shouldn't have a wireless network at all. There are vulnerabilities for just about any method I would use to secure a wireless network.

My important stuff is firewalled within the network. I use WEP because it's the easiest way to give network access to folks I've authorized to use my network while still letting unauthorized users know they're not welcome.

[1]: http://en.wikipedia.org/wiki/Legality_of_piggybacking

Post reply on HN