Live data from Hacker News

Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

news.ycombinator.com

111–116 of 116 posts

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#111
post #88

There's a lot of FUD & frankly inaccurate information floating around here. When connecting to a password protected router you are given an UNCHECKED BY DEFAULT option to share the password with your friends. What this means is, the user can deliberately share the password they know. This is just as secure as any other system because once you give a user a password they could share it if they chose. Nothing here is "…

Even if people opt into it, why should this happen automatically? If one of my friends told every single Facebook friend of theirs the password to my wifi I would have a very strong conversation with them and probably never invite them into my home or even consider them a friend anymore. Just because they _can_ share the password doesn't mean they _should_ share the password. I don't see why this kind of automatic sh…

I have some friends in California who use the combination of their kids' names for wifi password. It would seem to be an easy one to remember. But in reality it's only the idea that stays remembered because it's not just names but Russian nicknames formed with suffixes and transliterated into English using inconsistent rules.

California is an awesome place! I'm always happy to visit my friends over there. Manage to do it once or twice every year. So far, wifi password never stayed saved in my phone for one reason or other. Failing to enter it correctly several times and asking for help has been a consistently awkward experience.

So I perfectly understand why this would be a nice feature. The drawbacks? Someone using your access point for something shady? How would they do that, parking on someone else's driveway in a residential district? That's too suspicious and would probably attract more unwanted attention than doing that from your own access point at home.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#112

https://www.windowsphone.com/en-gb/how-to/wp8/connectivity/u... >... WiFi Sense can do a lot of things for you to get you connected to the Internet using WiFi, so you don't have to do them on your own. These include:... > - Accepting a WiFi network's terms of use on your behalf... That doesn't seem appropriate.

Only if you've already accepted the terms of use initially, this is fine.

I'd love this feature - connecting to all the open wifi connections around downtown and then letting my phone/laptop log me in through their terms of use acceptance pages (looking at you Tim Horton's) seamlessly.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#113
post #42

Earlier quoted context omitted.

There's a pretty big difference between "it was too long and I didn't read it so I just clicked Agree at the bottom" and "I had no idea the thing was even there because Microsoft's software hid it from me." If there was no reasonable way for you to even know the terms were there at all, I don't think any court is going to consider them to be binding. That's why these places show them to you when you try to use their…

Accessing a computer network that is secured by requiring authentication by bypassing authentication via technical means might be a computer crime. It's quite possible that using the Microsoft software to bypass a captive portal without agreeing to the terms will land you in jail for a felony. Is Microsoft going to indemnify you against being the trial case of that legal theory?

>It's quite possible that using the Microsoft software to bypass a captive portal without agreeing to the terms will land you in jail for a felony.

How do you define "quite possible"? I'd estimate that this is exceedingly unlikely to happen.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#114
post #81

Earlier quoted context omitted.

If they derive the PTK on the server from the stored PMK and sending that instead, this attack would not allow decryption of transmitted packets (other than group key broadcasts) because of the ANonce generated by the AP on each connection used in the key derivation. And the PSK uses PBKDF2 to generate the PMK, making mass cracking expensive.

For the usage I was thinking of, it doesn't need to decrypt mass packets, but rather, join a massive number of networks. My idea was simply a way to accelerate the spread of a worm through consumer wifi gear by using the set of fake profiles to always be friends-of-friends with the owner of the network (and thus friends with someone who has connected, thus allowing you to connect). The process would be something like…

Didn't think of exploiting routers themselves before.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#115

There's a lot of FUD & frankly inaccurate information floating around here. When connecting to a password protected router you are given an UNCHECKED BY DEFAULT option to share the password with your friends. What this means is, the user can deliberately share the password they know. This is just as secure as any other system because once you give a user a password they could share it if they chose. Nothing here is "…

Few major issues I see: - Sharing is binary, it's all of the contacts or none. This is not what people really expect when thinking about a feature like this. - The password really only has to be typed once. I don't have thousands of people coming over and even if I did, they put in the password the first time and it's saved locally. The benefit in skipping those few seconds in exchange for sharing with everyone else…

it also doesn't give the standard home user the ability to deny people the ability to share. This is a huge failure on Microsoft's part. Simply connecting to a wifi network should never give you the option to propogate that connection to unlimited number of other users automatically via digital methods unless you are also a network administrator. This is something that only the person with the router password should even be prompted to be able to do if they so choose. It's a violation of security to ask anyone that's connecting if they want to share the connection settings with all of their friends. Like you might as well just mark your network as public at this point if you're allowing anyone to connect with a windows 10 phone.

Re: Windows 10 “WiFi Sense” automatically leaks your wifi password to strangers

#116

There's a lot of FUD & frankly inaccurate information floating around here. When connecting to a password protected router you are given an UNCHECKED BY DEFAULT option to share the password with your friends. What this means is, the user can deliberately share the password they know. This is just as secure as any other system because once you give a user a password they could share it if they chose. Nothing here is "…

Actually it IS an opt-in by default because the option is given to the user connecting except when Network Admin has forced their SSID to _optout. So now I have to force a stupid SSID change on my network, something that I don't want to do, just to prevent users of my network from being able to auto-share the connection with everyone they know.
Post reply on HN