Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

211–220 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#211
post #187
post #180

Earlier quoted context omitted.

Aren't most wi-fi networks trivial to crack anyway?

wondered this as well. I've heard numerous time that there are super simple programs out there that give you the password within minutes. No idea if there is any truth in it though.

The WPS flaw has been patched in a bunch of routers however the program Reaver was able to exploit it rather quickly.

Re: Google knows nearly every Wi-Fi password in the world

#212

Earlier quoted context omitted.

Why is google having my Wifi password a bad thing? I'd be happy to let EVERYONE have it, and the only thing I fear is neighbour teenagers overloading the connection with torrents so that it's not usable for me. As long as I expect them not to overload my wifi too much, I'm perfectly happy with google or FBI or KGB or friends or random strangers to use have that wifi password. If wifi routers were good at traffic shap…

I'm unsure, but doesn't WPA2 password knowledge allows to decrypt your traffic? (Possibly with an active attack to re-initiate handshake?) I.e. someone who knows your password could drive by your home, listen to the air and see what you're doing online.

This isn't the case. The WPA2 handshake involves the computation of a session key for each client, so clients on the network can't read the plaintext of each other's traffic. The session key is established with a nonce generated by the access point as well as the MAC addresses of the access point and client.

Re: Google knows nearly every Wi-Fi password in the world

#213
post #142

Earlier quoted context omitted.

Honestly, I use WEP encryption because I know that WiFi security is a house of cards in general. As you've said, it's enough to prevent the typical user from leeching bandwidth. The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.

- Until they link this post back to you, and argue that you knowingly weakened your security. - Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level. - Until they argue that your technical background means that you should have known better that WEP is crackable.

Buy a Nintendo DS Lite, some prefer the form factor to the newer models :)

Re: Google knows nearly every Wi-Fi password in the world

#214

Earlier quoted context omitted.

There's nothing seriously wrong with WPA2 itself. I'd consider it as secure as pretty much anything else out there that uses 128bit AES (given that your key exchange is secure of course - read on below). The problem is with the PSK variety, mainly that it's susceptible to offline dictionary attack: about 5% of actual WPA2-PSKs can be easily guessed [1]. There is stuff in the works to fix this though. My favorite is E…

Is there a way to authenticate that you are connecting to your AP?

Yes, and even WPA-PSK (with a strong pass phrase) has trustworthy mutual authentication: your device will (or should) not connect to a rouge AP that doesn't know the PSK.

Re: Google knows nearly every Wi-Fi password in the world

#215
post #192

Earlier quoted context omitted.

Probably not, even for inexperienced users. WEP was flawed but it's been rolled out already and most ISPs configure routers with proper WPA-PSK and long passphrases.

That depends on the router and configuration. There's a flaw in WPS that makes it possible to quickly crack a router that has it enabled, even if it's using WPA/WPA2.

Wow. I was curious what flaw you were talking about... It seriously verifies the first 4 digits? That deserves a face palm.

Re: Google knows nearly every Wi-Fi password in the world

#216

Does MAC filtering at the router level help at all? If the backup option is turned on, does Google also save your MAC addresses? If not, that seems like a good start to prevent someone from connecting to your network, even if they know the password. Obviously this won't help for public hot spots, but I always assume that public hot spots are already open to anyone. What if you are connecting to a Wi-Fi network using…

MAC filtering is trivially defeated by anyone who knows something about netsec.

MSCHAP is not good enough anymore either.

Re: Google knows nearly every Wi-Fi password in the world

#217
post #37

This very same point could be made against Apple, for instance, but there hasn't been a single comment to that effect in any discussion of this article. I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust. The reason people don'…

No, the same point can't be made against Apple. Apple encrypt WiFi passwords and never store them in plain text – not on their servers and not on the device. The encryption requires your login password to decrypt which Apple also don't store in plain text on their servers (although it is accessible on the device if you don't use a PIN or password, it is not backed up to iCloud). The reason why this allegation is leve…

If you lose your Apple ID password and reset it, are all your WiFi passwords gone?

Re: Google knows nearly every Wi-Fi password in the world

#219
post #110

Earlier quoted context omitted.

> passwords are either easy for computers to crack or hard for humans to remember Obligatory xkcd comic: https://xkcd.com/936/

I loathe whenever people post that comic for one simple reason. Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination. Crackers will simply start using wordlist rules to generate large lists of meshed…

[deleted]

Re: Google knows nearly every Wi-Fi password in the world

#220

Earlier quoted context omitted.

No, the same point can't be made against Apple. Apple encrypt WiFi passwords and never store them in plain text – not on their servers and not on the device. The encryption requires your login password to decrypt which Apple also don't store in plain text on their servers (although it is accessible on the device if you don't use a PIN or password, it is not backed up to iCloud). The reason why this allegation is leve…

If you lose your Apple ID password and reset it, are all your WiFi passwords gone?

That depends on the meaning of "reset". If you create a new password for the same user ID, then no -- the stored WiFi passwords are retained. If you create a new user ID and password, then yes.
Post reply on HN