Live data from Hacker News

Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

news.ycombinator.com

101–110 of 116 posts

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#101
post #64
post #54

Isn't this the definition of "unauthorized access", as far as the law is concerned? I'd be less uncomfortable if you had to deliberately choose which friends to share a certain network with. "Share with this person", or something.

You'd think - because presumably this could come about without you ever signing up to 'WiFi Sense' or any such EULA, if you give one Win10 friend the password, all his friends have it without you even realising WS exists?

>if you give one Win10 friend the password, all his friends have it

Only if he opts _in_ to sharing it.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#102
post #61

Earlier quoted context omitted.

> Give your neighbor your Wi-Fi password and they can share it with hundreds of their friends automatically. Give your neighbor your Wi-Fi password, and they can trumpet it on the streets, distribute on pamplets, post it on HN, and update their Facebook status with it. I am a little shocked at the HN reaction here. I've had a Windows Phone since January and I've thought the feature was not only useful, but a great id…

The problem is that it is automatic , it spreads without confirming anything and without any deliberate action.

The problem (with this post in HN) is that it _isn't_ actually automatic. Your device being receptive to automatically-shared networks is default-on/opt-out. Your device automatically _sharing_ a network is default-off/opt-in, as well as (I think) being on a per-network basis.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#103
post #102
post #61

Earlier quoted context omitted.

The problem is that it is automatic , it spreads without confirming anything and without any deliberate action.

The problem (with this post in HN) is that it _isn't_ actually automatic. Your device being receptive to automatically-shared networks is default-on/opt-out. Your device automatically _sharing_ a network is default-off/opt-in, as well as (I think) being on a per-network basis.

This is correct. None of this is automatic. It's all opt-in.

I don't believe Wi-Fi Sense is on at all by default (I am pretty sure I had to turn it on), and it explicitly shares only Wi-Fi networks you select, not all of them. You have to go in to your saved Wi-Fi networks and share each one individually. You also have to individually check each list of contacts (Outlook, Skype, Facebook, etc.)

It is absolutely not sharing all your networks automatically with all your Facebook friends.

Here are screenshots (note I'm 99% sure I turned on Wi-Fi Sense):

http://i.imgur.com/bzaK2aT.png http://i.imgur.com/vnbDkdj.png

I suppose it's ironic the FUD is directed against Microsoft now.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#104

Earlier quoted context omitted.

Agreed. At my house, we have three laptops, a desktop, three tablets and two smart phones. I don't want to have to change the wireless settings of nine devices because of Microsoft. If this features truly works as stated, it is an incredibly arrogant thing for MS to do.

It doesn't work as stated. Users have to opt to share the password when they connect to wifi router. This checkbox is empty by default meaning you don't share the password by default.

It doesn't make it much different whether that checkpoint is off or not, I basically see two problems with it:

1) Wi-fi access point owner is absent from that decision about sharing the password or not, other than the SSID name (thus, I suggested that Microsoft should have made this ins option basis. This way, at least that it would show that the owner of the AP is WILLING to participate in that.)

2) People do very stupid things. They may not even see a single implication before they "check" it. I've seen a lot of people enabled certain feature "because it sounds useful" without seeing further implication. Especially when they are not that tech-inclined, they may flip that switch "because everyone else's doing it," "that's the way I do in my home," or "I didn't know that's what it meant." I'd know if he/she is sharing my wi-fi password on Facebook by that person writing on their timeline (which I'll pick up my phone and start screaming at that person) but this seems to be much more discreet than that.

Again, it doesn't really matter if that checkbox is checked or not. It's a bit of a different story if they had to drill down to several layers of menu (which I wouldn't change my opinion that it is still a bad idea) -- but it sounds like this option is presented right in their face everytime they are connecting to new networks.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#105
post #88

Earlier quoted context omitted.

Even if people opt into it, why should this happen automatically? If one of my friends told every single Facebook friend of theirs the password to my wifi I would have a very strong conversation with them and probably never invite them into my home or even consider them a friend anymore. Just because they _can_ share the password doesn't mean they _should_ share the password. I don't see why this kind of automatic sh…

This solves the problem of asking people the wifi password whenever you go over to their house. To a lot of people it's just a pain. When you tell your friends your password, just tell them not to share it. Done! I would wager it helps the windows phone users and doesn't hurt other people. Also it's coming to windows 10 I believe.

> This solves the problem of asking people the wifi password whenever you go over to their house.

A little bit off-topic, but:

What would be nice is if NFC tags with the WiFi datatype/field would actually work out of the box.

I bought a bunch of NFC stickers online they're pretty cool (and real cheap, 25-50 cents a piece depending on how many you get). You can easily write data into them with an app called "NFC Tagwriter" (by a company called NXP)[0].

You can put roughly the same fields into an NFC tag as you can put into QR-codes: plain text, URL, email address, contact info, etc. But the cool thing is that I haven't seen any phone that came with a QR-scanner app pre-installed (which is I think one of a couple of big reasons why QR-codes aren't really taking off). However, it turns out that any phone with NFC capability can read NFC-tags without any additional software, you just need to enable it in the settings (like Bluetooth or WiFi, except that NFC hardly uses any battery at all because it's so close range).

A curious thing about using NFC is that when enabled, in many cases it does its "thing" without any prompt or confirmation. Plain text immediately pops up a message (that you can't copypaste, share or save, only dismiss). An URL immediately opens your default browser and goes there!! Only prompt you may get (on some phones) is to ask which browser to use (but it often seems to just pick Firefox, for some reason).

So far, best uses I came up with are silly pranks (but that may just be me).

Except the WiFi-network datatype. That one seemed really quite useful (as well as hilarious, like sticking the tag into a bible or such, "to get my WiFi password, put your phone on the bible and swear to not abuse my network").

... if it weren't for the fact that, out of all types of field that just seem to work reasonably well, the WiFi datatype just pops up a message with a MIMEtype-like string, no password, nothing. I tried a whole bunch of my friends' phones (mainly Android, though), and only a single Sony phone seemed to get it, while a very similar but slightly newer Sony phone did not.

On my own phone I can use the NFC Tagwriter app and configure the NFC settings to do the right thing with the WiFi datatype tags, but that puts you in the same place as QR-codes, having to get an app, and even change the settings. It would have been so cool if the WiFi datatype would work as frictionless as NFC tags with plaintext or URL fields on them.

Ah well, maybe next year's technology :)

[0] Sidenote/tip: my Samsung S4 phone is rooted, running Cyanogenmod. A few months ago the NFC Writer app autoupdated and told me it couldn't run on a rooted phone (not the app's fault, but the NFC library it uses). This was easily remedied with the Xposed framework and the "Rootcloak" module. After all I am root, which means I can also tell the app that I am not.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#106
post #98

Earlier quoted context omitted.

On the contrary, dealing with captive portals is quite annoying, especially since they just generate browser warnings with HTTPS. You have to go out of your way to open a plain-HTTP website so that it can be intercepted properly, just so you can click "I accept" again. Additionally, these things have short memories - if you're at a coffee shop you frequent, you might be clicking through the captive portal for the 150…

There is a long standing technical solution, though it's not widely implemented, WPA-enterprise. With WPA-enterprise I have my own personal key and I am automatically logged in. In the UK, "The Cloud" service offers this, which is many coffee shops and similar public places.

There is overhead. WPA2 Enterprise does not have a signup mechanism; you'd neee to run that on a separate SSID. Now you have to get people to join the appropriate SSID for what they want. Also unless you have a corporate managed device with the company CA installed, you have to click through scary certificate warnings.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#107

There's a lot of FUD & frankly inaccurate information floating around here. When connecting to a password protected router you are given an UNCHECKED BY DEFAULT option to share the password with your friends. What this means is, the user can deliberately share the password they know. This is just as secure as any other system because once you give a user a password they could share it if they chose. Nothing here is "…

Few major issues I see:

- Sharing is binary, it's all of the contacts or none. This is not what people really expect when thinking about a feature like this.

- The password really only has to be typed once. I don't have thousands of people coming over and even if I did, they put in the password the first time and it's saved locally. The benefit in skipping those few seconds in exchange for sharing with everyone else doesn't make sense.

- The FAQ also states that any public wifi spots that have been shared will be automatically connected to, including accepting the terms and even sharing some personal info like name, email, etc.

- The way it's worded is dangerous, mainstream users who don't know how this works will just go ahead and click this thinking its so much more convenient (and it is) but it doesnt properly reveal what's happening.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#108
post #81

After thinking about it for a bit, couldn't a worm with fake Facebook accounts that are friends-of-friends with a high percentage of the population use this to spread virtually unimpeded? I suspect that the API is such that all of the friends of the fake accounts will relay to the fake accounts all of their respective friends passwords (given they had connected to said friend's network at least once), and that two st…

If they derive the PTK on the server from the stored PMK and sending that instead, this attack would not allow decryption of transmitted packets (other than group key broadcasts) because of the ANonce generated by the AP on each connection used in the key derivation. And the PSK uses PBKDF2 to generate the PMK, making mass cracking expensive.

For the usage I was thinking of, it doesn't need to decrypt mass packets, but rather, join a massive number of networks.

My idea was simply a way to accelerate the spread of a worm through consumer wifi gear by using the set of fake profiles to always be friends-of-friends with the owner of the network (and thus friends with someone who has connected, thus allowing you to connect).

The process would be something like this:

1. Find a vulnerability in consumer wifi gear, such that insecure default allow the default config to accept new code from only inside the LAN. (These types of vulnerabilities with default passowords are common; however, remote access is often disabled.)

2. Upload code to one router.

3. Infected routers look for neighbors who they can connect to the network of, then upload the attack code once they're masquerading as a device on the LAN.

4. Repeat 3.

Normally, the reason that this attack doesn't really work is that there are simply too few open or insecure LANs of the same hardware type for the attack to have an effective spread rate, thus it's only a thin weak network and breaks quickly in the face of customers fixing, upgrading, or simply turning off their gear.

However, in allowing friends-of-friends to get access to a LAN, Microsoft has removed this barrier to worms spreading across consumer networking gear for anyone that can amass a stock set of profiles with decent geographical coverage, making it a viable way to accelerate the spread of a worm through networking gear.

Ed: Of course, once the routers themselves are infected, and you have good geographical coverage, the infected routers can be used as a platform to launch attacks. Again, the reason that we don't see this in practice is that it's too hard to get access to all of those LANs because of even the weak security that exists. Microsoft removed that, making the attack viable if people can infiltrate the Facebook social graph.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#109

There's a lot of FUD & frankly inaccurate information floating around here. When connecting to a password protected router you are given an UNCHECKED BY DEFAULT option to share the password with your friends. What this means is, the user can deliberately share the password they know. This is just as secure as any other system because once you give a user a password they could share it if they chose. Nothing here is "…

Looks like the Microsoft shills are back.

Nobody outside the Redmond bubble could possibly thing this is a sane thing to do.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#110

How do features like these even get thought up, planned out, implemented then released without anyone in such a massive company wondering if there might be some issues? Or building it as opt-in or at the very least giving easy settings to disable it. Automation like this is dangerous, I'm not sure saving 10 seconds is worth this kind of massive trust and security breach. When I give someone my wifi password, I know t…

From my experience at big companies, plenty of people do bring things up, but the security minded people rarely have authority.
Post reply on HN