Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

161–170 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#162
post #110

Earlier quoted context omitted.

> passwords are either easy for computers to crack or hard for humans to remember Obligatory xkcd comic: https://xkcd.com/936/

I loathe whenever people post that comic for one simple reason. Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination. Crackers will simply start using wordlist rules to generate large lists of meshed…

The point is you're supposed to use truly random word combinations since those are at least memorable.

  $ wc -l /usr/share/dict/words
  119095
  $ python -c 'print(119095 ** 4)'
  201175048646341950625
  $ python -c 'print(85 ** 10)'
  19687440434072265625
So, even if your target is known to be using this scheme in pure form, this has more entropy than a completely random 10-digit password (assuming ~85 characters) -- and who would actually be using such a thing, except someone using a password management program - who could just as easily be using a 20-character random password?

So even if it becomes known, it's an improvement on what users are doing now.

Re: Google knows nearly every Wi-Fi password in the world

#163

Earlier quoted context omitted.

Blamed and shamed for what? I suspect most people are more than happy that they can carry their existing settings across to a new 'phone and it Just Works™...

It's convenient for the owner of the Android phone, but the wifi password is not necessarily theirs to give away. That's the problem. It's not because your friends and family have given you their wifi password that they intended to give that password to Google as well. You're trading their security for your convenience.

great observation; it leads to a possible new feature for home wifi routers such as "guest" passwords or temporary passwords that expire (yes, I see that's redundant).

Re: Google knows nearly every Wi-Fi password in the world

#164

Earlier quoted context omitted.

Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…

> You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. You could encrypt the data locally before sending it to the server. You might also question whether this model of computing is in fact sensible. There are at least partial alternative…

We should definitely ask those questions.

In fact it would probably be a good idea for Google to proactively report/describe some of the technical tradeoffs they have made when it is related to privacy.

Because what most people do is judge based on incomplete information - and Google has more and more problems with its public perception.

Regarding the idea of encrypting all data (I believe you mean that not even Google should be able to decrypt it) before sending it to the servers I see some issues, but my views on cryptography are probably pretty naive.

1) There are laws that force them to hand over data to governments when courts order it - I do not know if they would get away with only turning over encrypted data.

2) They also have business goals - like increasing ad revenue by matching ads to the personal preferences of its users.

3) They have social interactions in most of their products - I don't know how this could work with total encryption.

4) There are certainly some usability tradeoffs to make - like how many times does a user have to enter a password to access his data.

Re: Google knows nearly every Wi-Fi password in the world

#165
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

House? What about in a large office building in NYC?

Re: Google knows nearly every Wi-Fi password in the world

#166
post #87

Earlier quoted context omitted.

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

There's nothing seriously wrong with WPA2 itself. I'd consider it as secure as pretty much anything else out there that uses 128bit AES (given that your key exchange is secure of course - read on below). The problem is with the PSK variety, mainly that it's susceptible to offline dictionary attack: about 5% of actual WPA2-PSKs can be easily guessed [1]. There is stuff in the works to fix this though. My favorite is E…

Is there a way to authenticate that you are connecting to your AP?

Re: Google knows nearly every Wi-Fi password in the world

#167

Earlier quoted context omitted.

Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. Probably, but not necessarily. All they need to know is the hash of your password. When you set up a new device, it can call out to Google to authenticate without sending a cleartext password (similar to HTTP's Digest auth).…

With your design, a user with a lost password also loses all their data. While that might be better from a security perspective, I can't remember the last time I used a system that did not keep all my data when I set a new password, without having the old one. Such a thing would annoy many users.

Not all their data, necessarily, just sensitive stuff like passwords.

Re: Google knows nearly every Wi-Fi password in the world

#169

Earlier quoted context omitted.

Is this Googles failure or are goverments the issue? Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did. To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power. Snowden is a significant outlier... hiring policies are intende…

"Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did." We do not know this and it would be questionable if the risk associated with such an act would be worth it considering that Google can actually use its resources to move things in a legal way. (via courts, lobbying in Washington etc.) "To explain Google's behavior, classic diffusion of…

We do not know this and it would be questionable if the risk associated with such an act would be worth it considering that Google can actually use its resources to move things in a legal way. (via courts, lobbying in Washington etc.)

Google's legal initiatives are largely just naked lobbying for its own corporate interest. SOPA in particular. Nothing wrong with this but it's a lot different than using its legal team to fight government abuses. Google is reasonably scared and chastened by Microsoft's massive antitrust battle, and Eric Schmidt pragmatically ramped up lobbying and philanthropy when he took the helm.

They let you take all your data out of all Google products: http://www.dataliberation.org/takeout-products

Do you think this removes it from the system that the NSA has access to?

They fight governments data requests in courts (sometimes successfully) and release strongly worded statements when they are allowed to.

Strongly worded PR statements while being 100% cooperative. My guess is that the statements are run by the NSA for approval before they are published.

Suggesting that we ended up with an abusive goverment because Google slavishly followed orders seems unrealistic to me.

I did not argue this. But it's a very slow and gradual slide into tyranny, and Google has done nothing to prevent the obvious abuses. I again point to the Government's treatment of Microsoft as a significant driver of Google's supplication.

The survival of the NSA does not depend on public trust and a positive public image - Google does.

Only when the information is kept secret does the NSA's survival not depend on public trust. I'd argue that the NSA depends more on public trust than Google, since Google's motives are very clear, at least insofar as the shareholders are concerned. The NSA is there to protect US interests which generally are not documented and are subject to the whims of both high level and low level officials.

Re: Google knows nearly every Wi-Fi password in the world

#170
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Do you have a citation for that claim about WPS and home users?

While it certainly could be the crowd I hang out with (not all of which are techies, mind you), but I've never met anyone who uses WPS.

Post reply on HN