Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

181–190 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#181
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

These are all great points but let us know for God's sake. You trust them, and I sure trust them with a lot of secrets. But they have to ask. I would have no idea if not for Hacker News.

CyanogenMod is on my list.

EDIT: Oh, and "backing up" my contacts without asking me. That made me livid, that's the height of arrogance. And yet I still use Android.

Re: Google knows nearly every Wi-Fi password in the world

#182
post #170
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Do you have a citation for that claim about WPS and home users? While it certainly could be the crowd I hang out with (not all of which are techies, mind you), but I've never met anyone who uses WPS.

"In December 2011, researcher Stefan Viehböck reported a design and implementation flaw that makes brute-force attacks against PIN-based WPS feasible to perform on WPS-enabled Wi-Fi networks. A successful attack on WPS allows unauthorized parties to gain access to the network. The only effective workaround is to disable WPS.[4]"

- http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup#Security

[4] http://www.kb.cert.org/vuls/id/723755

Re: Google knows nearly every Wi-Fi password in the world

#183
post #142

Earlier quoted context omitted.

Honestly, I use WEP encryption because I know that WiFi security is a house of cards in general. As you've said, it's enough to prevent the typical user from leeching bandwidth. The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.

- Until they link this post back to you, and argue that you knowingly weakened your security. - Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level. - Until they argue that your technical background means that you should have known better that WEP is crackable.

Unfortunately, I have had to enable WEP a few times for certain OS / network card / router configurations, so there are or can be compelling reasons to do this. Pretty sure it was XP though my wife's XP box is working fine with WPA2 on my current router.

However, I try to treat even my home WIFI as if it were a coffee shop. The password is there to keep leechers out, but I still vpn into a more secure location for some tasks, use SSL when connecting to sensitive services, and keep my ports locked down.

Re: Google knows nearly every Wi-Fi password in the world

#185
post #142

Earlier quoted context omitted.

- Until they link this post back to you, and argue that you knowingly weakened your security. - Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level. - Until they argue that your technical background means that you should have known better that WEP is crackable.

Unfortunately, I have had to enable WEP a few times for certain OS / network card / router configurations, so there are or can be compelling reasons to do this. Pretty sure it was XP though my wife's XP box is working fine with WPA2 on my current router. However, I try to treat even my home WIFI as if it were a coffee shop. The password is there to keep leechers out, but I still vpn into a more secure location for so…

You may find sshuttle interesting [1]. It's essentially VPN implemented via SSH tunnel.

[1]: https://github.com/apenwarr/sshuttle

Re: Google knows nearly every Wi-Fi password in the world

#186
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

I'd like to point out that Google also has devices that they control within 100 feet of almost every WiFi hotspot in the world.

Re: Google knows nearly every Wi-Fi password in the world

#187
post #180
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

Aren't most wi-fi networks trivial to crack anyway?

wondered this as well. I've heard numerous time that there are super simple programs out there that give you the password within minutes. No idea if there is any truth in it though.

Re: Google knows nearly every Wi-Fi password in the world

#188
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

While I don't like at all the idea of government surveillance without court order, I find the idea of corporate surveillance even more horrifying. Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not f…

I dont really see your logic, Gubment can put you in prison, take your rights away, companies targeting ads can't. It makes sense that one would be outraged at the former.

Re: Google knows nearly every Wi-Fi password in the world

#190
post #114

It's troubling to see this, but I've always used MAC Filtering on my home network on top of WPA2 to limit what devices can connect to my network.

MAC filtering is useless, even in combination with WPA2. An attacker only has to sniff for a MAC your AP is happy to talk to and then changes theirs.

Is there a way to lock down a router in a way that can't be so easily spoofed?
Post reply on HN