Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

301–310 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#301
IM(Paranoid)O, it puts the "inadvertent" collection of SSIDs while driving down every street taking pictures for Google View into a new context. They gave a simply implausible explanation that this data was recorded "inadvertently". (No, fitting all those vehicles with the equipment and software would cost serious money!)

Marry the Geo-location, SSID, phone owner and passwords and you've got real information for the authorities. On Everyone.

Re: Google knows nearly every Wi-Fi password in the world

#302
post #104
post #80

Security is about tradeoffs. How bad would it be if someone else got this information? How helpful is it to me to give it to this third party? Wireless passwords are a huge pain: visit someone's house, ask them for their password, and then feel guilty while they look through various papers to find a long string of hex digits which are so annoying to enter on the phone. This pain makes the tradeoff well worth if for m…

QR codes could make entering secure keys in to mobile devices easier. Variations of Wi-Fi quick set-up can also be made reasonably secure, implementations just suck.

In a world of unlimited bandwidth, I'd prefer to leave my wi-fi open (I won't live in fear of terrorists war-driving on my specific block), but I saw this framed QR code for wi-fi password idea on Pinterest: http://www.apartmenttherapy.com/share-your-wifi-password-wit...

Re: Google knows nearly every Wi-Fi password in the world

#303
post #76

Ehem, and later this year Apple gets your finger print!

... and you think Android phone makers are not in mad rush to get a finger print sensor as early as possible ?

It didn't do much to boost sales of the Atrix. The fingerprint reader doesn't do much to boost security when passwords are ultimately still being used. You don't need someone's finger when the account you are signing into still has inadequate security measures to begin with.

Re: Google knows nearly every Wi-Fi password in the world

#304
post #299

Earlier quoted context omitted.

The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.

The best human rememberable password is 4-5 words from a dictionary + a special character. Assuming that most people have roughly 20k words vocabulary and that most keyboards can type easily say 60 characters, you get 20,000^4 60 or 9.6 10^18 passwords. This means that if you were to crack at a rate of one billion (with a b) passwords per second (unrealistic) you would still take on average of 9,000 years or 18,000 y…

Even so, of you assume that average person knows 20k words but would only use about 2,000 words in day to day life, and thus in his or her password. That still means that at one billion passwords per second (which is completely unrealistic, unless you are NSA) it would take 1.8 years to crack the password. Who would invest that much time and electricity into a wifi password, unless, again, you are the NSA :)

Re: Google knows nearly every Wi-Fi password in the world

#305

Earlier quoted context omitted.

I have, at length, in the past, and it's very disingenuous of you to pretend that you don't know that. Most people who accuse Google of being a tool of NSA have the excuse that they got the idea from the Guardian, which later retract^H^H^H^H^H^H^Hcontradicted itself out of the accusation. But you know that already. You accuse Google of being a tool of NSA because you want them to be, because you believe that by repea…

You are partially right. All of my beliefs are provisional and I'm waiting to be proven wrong. I'd very much prefer to believe that Google acted properly (not necessarily legally) with respect to its cooperation with NSA. To date I am still not convinced. How is it possible to feel comfortable with Google's answers when you consider that companies are forbidden from disclosing some information? I'm equally skeptical…

"How is it possible to feel comfortable with Google's answers when you consider that companies are forbidden from disclosing some information?"

Because you are implicitly claiming that not a single VP, SVP, well known person, etc, would be ethical enough to quit over this if Google had done it wrong. Given who those people are, it seems far fetched.

Re: Google knows nearly every Wi-Fi password in the world

#306
post #284

Earlier quoted context omitted.

That's all well and good, but I have still not given authorization for the use of my network to the malicious user. An open network invites legal dispute as to whether the lack of encryption constitutes implicit permission to use the network [1]. By having encryption, even if easily cracked, I have let the malicious user that they are not welcome on my network and have absolved myself of any responsibility for their…

> Following your reasoning, my background means that I should know that I shouldn't have a wireless network at all. It would be argued that you should have taken 'reasonable' measures to prevent unauthorized access. It could then be argued that using WEP is not reasonable, especially it you know it is easily crackable.

Should we lock our doors with bank-vault locks, since we know how easily most common door locks are picked? The fact that an attacker would have to actively bypass the security should be enough for legal purposes. It is not like an attacker could accidentally crack a WEP-protected network and not know they were doing it.

Re: Google knows nearly every Wi-Fi password in the world

#308
post #284

Earlier quoted context omitted.

> Following your reasoning, my background means that I should know that I shouldn't have a wireless network at all. It would be argued that you should have taken 'reasonable' measures to prevent unauthorized access. It could then be argued that using WEP is not reasonable, especially it you know it is easily crackable.

Should we lock our doors with bank-vault locks, since we know how easily most common door locks are picked? The fact that an attacker would have to actively bypass the security should be enough for legal purposes. It is not like an attacker could accidentally crack a WEP-protected network and not know they were doing it.

No, nor should we uninstall the default deadbolt that comes with the house and replace it with a simple gate-style lock (you know, the kind you can reach over and unhook).

We should use the default standard method of locking our doors. And our Wi-Fi access points.

Re: Google knows nearly every Wi-Fi password in the world

#309

Earlier quoted context omitted.

You are partially right. All of my beliefs are provisional and I'm waiting to be proven wrong. I'd very much prefer to believe that Google acted properly (not necessarily legally) with respect to its cooperation with NSA. To date I am still not convinced. How is it possible to feel comfortable with Google's answers when you consider that companies are forbidden from disclosing some information? I'm equally skeptical…

"How is it possible to feel comfortable with Google's answers when you consider that companies are forbidden from disclosing some information?" Because you are implicitly claiming that not a single VP, SVP, well known person, etc, would be ethical enough to quit over this if Google had done it wrong. Given who those people are, it seems far fetched.

I hope you're right. That is certainly what I thought before the Snowden revelations. To date I don't think Google has offered sufficient transparency into the process to adequately restore trust. If the NSA (via secret laws or dictums) is preventing this from happening, it is at the expense of Google's reputation.

Further, the recent revelations that the NSA deploys agents as employees of various tech companies (like Google) indicates that Google's internal security processes have been breached and the careful (and likely reasonable) way that cooperation with law enforcement has been crafted may be largely irrelevant.

The above may be wild speculation, and I hope it's incorrect. But considering the Snowden revelations I don't think Google has done enough to make a person or firm that explicitly didn't want the NSA to have access to data its feel comfortable using Google's network and services to store/transmit it.

And, since Google's core business is ads, Google has designed its own systems so that data from any Google service (analytics, dns, gmail, doubleclick) can be used for targeting and behavioral profiling. The scope of it is really quite impressive. Thus I think it's sobering to think about all the data being readily available to the NSA, as Snowden suggests it is.

Re: Google knows nearly every Wi-Fi password in the world

#310

Earlier quoted context omitted.

Should we lock our doors with bank-vault locks, since we know how easily most common door locks are picked? The fact that an attacker would have to actively bypass the security should be enough for legal purposes. It is not like an attacker could accidentally crack a WEP-protected network and not know they were doing it.

No, nor should we uninstall the default deadbolt that comes with the house and replace it with a simple gate-style lock (you know, the kind you can reach over and unhook). We should use the default standard method of locking our doors. And our Wi-Fi access points.

Except he's enabled WEP because it's "more convenient" for him. It's still a strong signal that he doesn't want outsiders on the network.

A better door analogy is replacing the deadbolt with a slightly crappier one that unlocks whenever you're in bluetooth range (for "convenience"). Just because the system is "easily broken into" doesn't mean that you're not "breaking and entering" when you break the security and enter the house.

Post reply on HN