The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
Google knows nearly every Wi-Fi password in the world
121–130 of 312 posts
Re: Google knows nearly every Wi-Fi password in the world
#122Re: Google knows nearly every Wi-Fi password in the world
#123Earlier quoted context omitted.
For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it. That's ridiculous. The risk isn't institutionalized abuse, the threat is an unscrupulous guy in the Ventures group who has a buddy who works in the gmail (or other) groups. Calls him up…
You make the false assumption that people in different divisions of a very large company would be more likely to help each other outside of the corporate reward structure than they would be to help someone outside the company, who they might just happen to have personal or social obligations to. If there were an unscrupulous person in the gmail group, he would be more likely to break company policy (and, I think, the…
I'm assuming that people within a company are more likely to know each other and know what areas they work on versus simply "working at google." They have all kinds of opportunities to rub shoulders - previous projects they've worked on together, company social events, even just riding the google bus to work each day.
While outsiders are also a risk, working for the same company substantially increases the opportunities.
Re: Google knows nearly every Wi-Fi password in the world
#124Earlier quoted context omitted.
Why is google having my Wifi password a bad thing? I'd be happy to let EVERYONE have it, and the only thing I fear is neighbour teenagers overloading the connection with torrents so that it's not usable for me. As long as I expect them not to overload my wifi too much, I'm perfectly happy with google or FBI or KGB or friends or random strangers to use have that wifi password. If wifi routers were good at traffic shap…
I'm unsure, but doesn't WPA2 password knowledge allows to decrypt your traffic? (Possibly with an active attack to re-initiate handshake?) I.e. someone who knows your password could drive by your home, listen to the air and see what you're doing online.
If I use https/ssh, then my traffic is safe even if wifi is open; if I don't, then my traffic is unsafe even if WPA2 is used.
Re: Google knows nearly every Wi-Fi password in the world
#125Or, in other words, Google remembers the things that we agree to have it remember.
The operative question is: when someone signs into a Google account on an Android device, and without any notification whatsoever the device sends his passwords to Google - which is what happens - has there been a meeting of the minds? Are both parties in agreement about what the deal is here?
Re: Google knows nearly every Wi-Fi password in the world
#126The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?
The problem is with the PSK variety, mainly that it's susceptible to offline dictionary attack: about 5% of actual WPA2-PSKs can be easily guessed [1].
There is stuff in the works to fix this though. My favorite is EAP-PWD [2]. It's resistant to offline dictionary attacks, it has perfect forward secrecy and it's already supported by Android. Basically, it's what WPA2-PSK should have been.
In the mean time, if you're security conscious just set a long random PSK or configure e.g. EAP-TLS. Both will give you strong security against pretty much any attacker.
Re: Google knows nearly every Wi-Fi password in the world
#127Earlier quoted context omitted.
Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?
The problem isn't limited to WPA2. As far as I know, in and of itself it's actually fairly secure. Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.
Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.
Re: Google knows nearly every Wi-Fi password in the world
#128The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
Re: Google knows nearly every Wi-Fi password in the world
#129The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
Yeah and those locks on your doors are a joke! Why are you pretending your home has an expectation of privacy? So dumb! Of COURSE anybody can just come into your house any time they want.
Re: Google knows nearly every Wi-Fi password in the world
#130The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…
The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.