Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

221–230 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#221
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

While I don't like at all the idea of government surveillance without court order, I find the idea of corporate surveillance even more horrifying. Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not f…

I think most of your repliers are forgetting about Blackwater. (/tinfoil-hat)

Re: Google knows nearly every Wi-Fi password in the world

#222

Earlier quoted context omitted.

While I don't like at all the idea of government surveillance without court order, I find the idea of corporate surveillance even more horrifying. Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not f…

I dont really see your logic, Gubment can put you in prison, take your rights away, companies targeting ads can't. It makes sense that one would be outraged at the former.

Sure, but the government is subject to popular pressures. They can't imprison or otherwise hassle even a substantial fraction of the population in any meaningful way. Corporations are not subject to popular pressure. They can hassle millions of Americans and get away with it.

As a practical matter, you have a lot more to fear from corporations misusing your private data to deny you jobs, mess up your credit, etc, than you do from government misusing your private data to shut down your anarchist political movement.

Re: Google knows nearly every Wi-Fi password in the world

#223
post #170
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Do you have a citation for that claim about WPS and home users? While it certainly could be the crowd I hang out with (not all of which are techies, mind you), but I've never met anyone who uses WPS.

WPS is enabled by default on practically every wifi router sold in the last 7ish years.

Re: Google knows nearly every Wi-Fi password in the world

#224

Earlier quoted context omitted.

That depends on the router and configuration. There's a flaw in WPS that makes it possible to quickly crack a router that has it enabled, even if it's using WPA/WPA2.

Wow. I was curious what flaw you were talking about... It seriously verifies the first 4 digits? That deserves a face palm.

Yeah, reporting the two halves separately is extremely bizarre. It's like they bent over backwards specifically to add a security flaw for no obvious reason. It's surprising that nobody noticed it before it was standardized and shipped.

Re: Google knows nearly every Wi-Fi password in the world

#225
Why all the NSA crap in this thread? You don't need to add in a government agency to make this treasure trove of passwords valuable or dangerous. One day, this data will leak out, and then there will be trouble.

Just having a reliable set of millions of real world passwords is invaluable - they'd be useful for brute-forcing other hashed password files.

Re: Google knows nearly every Wi-Fi password in the world

#226
post #7

Earlier quoted context omitted.

yes, but to be fair, this issue deserves to be more well known. it wont be fixed if google isn't blamed and shamed for it repeatedly.

Blamed and shamed for what? I suspect most people are more than happy that they can carry their existing settings across to a new 'phone and it Just Works™...

you really think its normal that google has direct access to various different PERSONAL passwords. I don't. 99% of the users don't even realize this is being done.

Then people go crazy about the NSA having the same access.. you guys don't make the link or ... ?

Re: Google knows nearly every Wi-Fi password in the world

#227

Earlier quoted context omitted.

That depends on the router and configuration. There's a flaw in WPS that makes it possible to quickly crack a router that has it enabled, even if it's using WPA/WPA2.

Wow. I was curious what flaw you were talking about... It seriously verifies the first 4 digits? That deserves a face palm.

http://www.neowin.net/news/the-wps-wifi-protected-setup-flaw...

(Quick search, seems a good explanation, if anyone else is curious.)

Re: Google knows nearly every Wi-Fi password in the world

#228
post #204

Earlier quoted context omitted.

What?

He's probably talking about Android.

It's basically true, though. Google install arbitrary Android apps on nearly any Android phone without user interaction.

Source: If you log in to https://play.google.com from a desktop computer, you can install apps on your phone. You get the permissions dialog on the website (on your desktop computer), not on your phone.

Re: Google knows nearly every Wi-Fi password in the world

#229
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

i'd like you to come and crack my WPA2 password. its not because wifi has had various bad issues, that current wifis with a proper configuration aren't secure.

Heck, in many countries, wifi routers actually use WPA2 with a pregenerated shared key, which is a good 24 chars long and fully random. Incredibly easy to guess or crack! (its very, very hard to crack.)

Re: Google knows nearly every Wi-Fi password in the world

#230
post #220

Earlier quoted context omitted.

If you lose your Apple ID password and reset it, are all your WiFi passwords gone?

That depends on the meaning of "reset". If you create a new password for the same user ID, then no -- the stored WiFi passwords are retained. If you create a new user ID and password, then yes.

OK so in the case of a "normal" lost password then how is it that it's safe on Apple's servers? That is, if it's not encrypted with a key derived from your password, then Apple can still decrypt.
Post reply on HN