Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

81–90 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#81
post #27

Earlier quoted context omitted.

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

> Just out of curiosity, how would we know even if a secret was let out to, say, the NSA And the smartest thing to do, whether you are the NSA or some other foreign government or any entity that holds that information, is to keep quiet about it. The less others know that you know something, the more power you have. For that reason, it is unlikely that we will see these powers used by the NSA, or other government. It…

> For that reason, it is unlikely that we will see these powers used by the NSA, or other government.

The "parallel construction" mentioned above is how they do use these powers while obscuring the use of these secrets.

Re: Google knows nearly every Wi-Fi password in the world

#82
post #16

And in addition to that they have the audacity to not make them accessible to the user! No way to look up your own wireless password in your phone, i.e. to tell a guest, thats just ridiculous.

I you root your Android phone, there are apps to do that for you.

But I do agree that it's a form of UI-fail that there is no legitimate way for a user to recover his own passwords.

Re: Google knows nearly every Wi-Fi password in the world

#83

Another reason to (really) go open-source/independent.

How independent you'd have to be to be secure? Quite a whole lot.

If you use a VPS, you can (will) be owned by your VPS provider and any Internet provider your traffic goes through.

If you use colocation or self host, you will have to live without or self host/mantain/develop many alternatives for usual tools AND you can (will) be owned by all the internet providers your traffic goes through.

Not a very nice scenario.

Re: Google knows nearly every Wi-Fi password in the world

#84
post #34

Earlier quoted context omitted.

I agree that it's unlikely Google as a whole would decide to read/use confidential data. on the other hand, the idea that someone w/in Google might abuse their position is completely plausible. if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data? edit: to be clear, I use Google servic…

Given that Google has a VC arm, I am stunned every time I run into a VC who uses gmail and other google-hosted services as part of their business. They are handing their competition an enormous chunk of their business proprietary information and trusting them not to peek at it without even a contract. To me, that level of naivety with respect to operational security is just baffling. All it takes is one unscrupulous…

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it.

Google Ventures, no matter how spectacularly they might do as VCs, will always be several orders of magnitude less important to Google than Gmail. Google Ventures invests $300 million per year. Say they are always, every year, one of the top VCs so they--every year--deliver 3x on the money invested a few years before. They are still delivering less than $1 billion, less than 2% of Google's revenue.

In reality, it will probably be more like 1%, plus or minus 4%. And also, in reality, it won't be considered revenue, it will be Extraordinary Gains from Non-operational Events, or some such accounting gibberish, and nobody on Wall Street will give them any credit for it.

Re: Google knows nearly every Wi-Fi password in the world

#85
post #47
post #38

Google is going to have thousands of different passwords mapped to the SSID "linksys."

I think the MAC Address of the router is known too, so there's no duplicates.

That's why there was federal malware that captured MAC addresses on tormail when it was shut down. Easy for them to get Google to match it up to an identity

Re: Google knows nearly every Wi-Fi password in the world

#86
post #35

What's wrong in it.It's not a bank account rite.

It could be like leaving your bank account password in the open. Your bank account password could be sniffed probably very easily by someone who is connected to your network. Now imagine somebody exposes some way to get the password of your home network from the google servers.

If a random attacker in your local network can do that easily you should talk to your bank about SSL or change to one that actually knows basic internet technology.

SSL should be assumed as broken for defence against government surveillance but it still keeps the most common attackers out.

Re: Google knows nearly every Wi-Fi password in the world

#87
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Isn't it about time we get new security standards for Wi-Fi? Is there anything in the works right now to replace WPA2?

Re: Google knows nearly every Wi-Fi password in the world

#88
post #34

Earlier quoted context omitted.

Given that Google has a VC arm, I am stunned every time I run into a VC who uses gmail and other google-hosted services as part of their business. They are handing their competition an enormous chunk of their business proprietary information and trusting them not to peek at it without even a contract. To me, that level of naivety with respect to operational security is just baffling. All it takes is one unscrupulous…

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it. Google Ventures, no matter how spectacularly they might do as VCs, will always be several orders of magnitude less important to Google than Gmail. Google Ventures invests $300 million pe…

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it.

That's ridiculous. The risk isn't institutionalized abuse, the threat is an unscrupulous guy in the Ventures group who has a buddy who works in the gmail (or other) groups. Calls him up one night and says, "Can you do me a big favor? Check out so-and-so and see what he's working on."

It isn't about Google's bottom line on wall street, it is about an individual abusing access to further his own career.

Re: Google knows nearly every Wi-Fi password in the world

#89
post #27
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

> As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information. Moreover, if you're not…

I can't remember where I read it, but google does notify you. They can't say the NSA was in your account – they're under a gag order – but they do put a notice on your account so you're aware. I'll try to find a linl.
Post reply on HN