Live data from Hacker News

Android saves wifi passwords in plaintext to the cloud

code.google.com

51–60 of 172 posts

Re: Android saves wifi passwords in plaintext to the cloud

#51

What key are you going to encrypt these passwords with? If you were to encrypt passwords in the cloud with a key that's stored on the device, you can't unlock the passwords on a different device (or the same device after flashing), which is the whole point of backing it up in the cloud. If you were to encrypt them with the user's Google Accounts password, the device would need to ask for that password on every startu…

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

If you're going to dismiss an argument as "horseshit", you should perhaps offer a compelling alternative. Because your idea of what is going on is frankly ridiculous.

It's easy to see the user-experience story for this. Upgrade your phone, buy a tablet, etc, and as by magic all 10 wifi networks you use work without any configuration. No need to type that 32-character nuisance of a WPA2 password again, etc. How lovely!

Your conspiracy theory hinges on the idea that Google wants your precious wifi password for themselves, not for your convenience. That seems unlikely. Google doesn't care about your network. They might care about your web usage patterns insofar it makes it easier to provide better search results and improve ad targeting. Your network is worthless for that. Using the passwords to actually access these wifi networks would also be a massive legal and PR nightmare.

So on one side you have delighting users. On the other side you have a malicious attempt to gather useless data at massive risk. How can there even be a question of which explanation makes more sense?

Re: Android saves wifi passwords in plaintext to the cloud

#52
post #8
post #4

You can turn it off if you like: Settings > Privacy > Backup my data, backup application data, Wi-fi passwords, and other settings to Google servers. Every few months someone rediscovers that Google also syncs Wifi credentials between devices (perhaps when logging into a new device and finding it tethers itself nicely to the network on its own). It's a matter of convenience, Wifi passwords are only applicable at a ce…

> like hardware address whitelisting I wouldn't recommend that in any circumstance, it's completely false security really. MAC filtering is incredibly easy to bypass, all Malory has to do is wait for another device to connect and clone their hardware's address.

It's also a diagnosis nightmare. The ISPs in my country used to use WEP with MAC filtering with their wifi-routers. The password was mildly complex (16 characters) and on a label on the box. Most users never changed the password. So Joe Blow connects his laptop using the password on the sticker, and it doesn't work. Imagine the same problem for a few million users.

It's false security because (especially for wifi) MAC filtering is like a verbal password that's been written down on a billboard. Everyone can read it so its not a secret.

Re: Android saves wifi passwords in plaintext to the cloud

#53
post #45

Earlier quoted context omitted.

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

an act which can be in no way cast as user convenience. It's very convenient to me. I have both an Android phone and tablet. I've also switched Android phones multiple times- it's been quite gratifying to return to a city I visited three years ago and have it automatically connect to the WiFi hotspots I used back then.

Yes. I just upgraded from one Android phone to another. Was resigned to the tedious nightmare of setting up multiple WiFi connections again. This feature is fantastic. Not that that negates privacy issues but it is a massive user convenience.

Re: Android saves wifi passwords in plaintext to the cloud

#54

Earlier quoted context omitted.

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

I'd imagine people getting new phones is the common use case.

If I buy a new Android phone, odds are it is not one which makes me a Google customer - i.e. Google gets none of the proceeds should I purchase a Samsung Galaxy.

The only means by which Google profits is by monetizing data leaking from my device. And my WiFi password is something potentially monetizable. When choosing between ignorance and malice as motivations, it is perhaps proper to choose ignorance even with Google. When choosing between my privacy interests and Google's monetary interests, it seems naive to place my privacy interests above those of Google's actual customers.

An American corporation is determined to be part of the military-industrial complex; film at 11.

Re: Android saves wifi passwords in plaintext to the cloud

#55
post #41

Earlier quoted context omitted.

I seem to recall that not backing up anything is the default. Am I wrong?

I believe cyanogenmod has backup turned off. But I had used previous (earlier version) of Android and it was turned on.

I only use the Android that comes with my phone and I recall having to check the box myself on my T-Mobile Galaxy S3.

Re: Android saves wifi passwords in plaintext to the cloud

#56
post #51

Earlier quoted context omitted.

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

If you're going to dismiss an argument as "horseshit", you should perhaps offer a compelling alternative. Because your idea of what is going on is frankly ridiculous. It's easy to see the user-experience story for this. Upgrade your phone, buy a tablet, etc, and as by magic all 10 wifi networks you use work without any configuration. No need to type that 32-character nuisance of a WPA2 password again, etc. How lovely…

[deleted]

Re: Android saves wifi passwords in plaintext to the cloud

#57
post #49

Earlier quoted context omitted.

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

> Google's scheme allows them to harvest the passwords to a vast number of wireless networks. I wasn't too worried until I read this from you.

Yep, we all know google needs extra bandwidth and/or has the capability or need to illegally snoop on your over the air http traffic at enormous legal risk.

Re: Android saves wifi passwords in plaintext to the cloud

#59
Google could use this to bootstrap a FON like worldwide network. Have an additional option in the settings for "Make this network part of Google Free Wifi" and then any android phone anywhere can connect seamlessly to the network. If you change the security settings they are immediately updated because you also update them on your own phone.

At least for networks that are already designed to be public (e.g., coffeeshop wifi) this would be awesome. For my home network I'd have to first setup a second SSID myself that I firewall from the rest so that I don't expose all my wifi devices to any passer by. That bit isn't very user friendly.

Re: Android saves wifi passwords in plaintext to the cloud

#60
post #49

Earlier quoted context omitted.

Horseshit. Setting up a password for an Android device only needs to be done once for each device->network pairing. The reuse of Wifi passwords across devices is an edge case given the predominate ownership pattern of Android devices - i.e. most people have a phone that runs Android and no other Android device. Google's scheme allows them to harvest the passwords to a vast number of wireless networks. Google has harv…

> Google's scheme allows them to harvest the passwords to a vast number of wireless networks. I wasn't too worried until I read this from you.

I wouldn't worry.

It's not as if the government could compel our friends at goooogle to give up said passwords.

Besides, you don't have anything to hide. Do you?

Post reply on HN