Alexa, what is my wifi password?
dragon863.github.io
dragon863.github.io
I look forward to seeing what you do 10 years from now. Keep it up!
What is GNU.
Linux is a kernel.
People often refer to the whole system as Linux, but what they really mean is GNU/Linux.
GNU is a collection of free software.
GNU is the name of a project that is focused on software freedom.
Here is a statement from GNU on Android:
https://www.gnu.org/philosophy/android-and-users-freedom.htm...
An example of a backronym as a mnemonic is the Apgar score, used to assess the health of newborn babies. The rating system was devised by and named after Virginia Apgar. Ten years after the initial publication, the backronym APGAR was coined in the US as a mnemonic learning aid: Appearance, Pulse, Grimace, Activity, and Respiration.[6]
Many United States Congress bills have backronyms as their names; examples include the American CARES Act (Coronavirus Aid, Relief, and Economic Security Act) of 2020,[7][8] the USA PATRIOT Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act) of 2001, and the DREAM Act (Development, Relief, and Education for Alien Minors Act).[9] In the 113th Congress (2013) there were over 240 bills with such names.[10]
The Bing name was chosen through focus groups, and Microsoft decided that the name was memorable, short, and easy to spell, and that it would function well as a URL around the world. The word would remind people of the sound made during "the moment of discovery and decision making".[19] Microsoft was assisted by branding consultancy Interbrand in their search for the best name for the new search engine.[20] The name also has strong similarity to the word bingo, which is used to mean that something sought has been found or realized, as is interjected when winning the game Bingo. Microsoft advertising strategist David Webster originally proposed the name "Bang" for the same reasons the name Bing was ultimately chosen (easy to spell, one syllable, and easy to remember).
[FWIW, no mention of Bing as a backronym.]
For me it's mix of Linux kernel and a subset of common FOSS software[0] providing the boot and low-level operations, while the middleware is provided by AOSP with Dalvik/ART and the top, the whole user experience with GUI, apps and whatever. The middle and the top has absolutely nothing common with Linux.
To give you and idea - if you swap the engine in your Ford to Cummins, would you tell everyone what you are driving Cummins? No, you would tell what you are still driving Ford. The same applies to Android, if you swap the Linux kernel to something else, eg to OpenBSD kernel, would you tell what your smartphone is now running on OpenBSD? No, it's still Android, though with OpenBSD kernel.
[0] if you have Linux kernel then it doesn't makes sense to write tooling and userspace from scratch. Like you can, but.. why?
So, it IS a Linux distribution with other userspace that's not made by GNU. What some people call non-GNU/Linux. Distributions like Alpine for example would also be it.
>The same applies to Android, if you swap the Linux kernel to something else, eg to OpenBSD kernel, would you tell what your smartphone is now running on OpenBSD? No, it's still Android, though with OpenBSD kernel.
Nobody says that it wouldn't, and it also would be true for other Linux distributions. Remember Debian GNU/kFreeBSD?[0]
Now, you could argue that someone who's using the terminal in Debian GNU/kFreeBSD would notice that it's not in fact Linux, but that's a matter of expertise (not every Linux user relies on the terminal), and that's also true for Android.
So, it IS a Cummins distr^W car with other car parts that's not made by Cummins? Despite the big blue "Ford" everywhere on the car and in the documentation?
Another litmus test I often amused by is how when where is a report of a bazillion of Windows infections (especially those when a user should explicitly run the payload, not just a drive-by) then it's Windows problem, but when there is a report of bazillion of infected Android phones and tablets then of course it's not Linux and therefore it shouldn't be chalked up in any "Amount of infected computers per OS" graphs, lol.
> So, it IS a Linux distribution
Humans tends to omit unnecessary repetition and overall tends to shorten things when it's fits their current situation.
But that doesn't make "an operating system distribution based on Linux kernel with system instrumentation and userspace common to other popular operating systems based on Linux kernel" equal to "Linux distribution" or "Linux".
Normally, when it comes to CVEs you tend to see it targeted to the affected piece. E.g.: CVE-2022-38533 affecting GNU binutils and CVE-2023-25139 affecting sprintf() in glibc. Those two things are core parts of most Linux distributions, yet they are still their own distinct thing.
The fact that many times the accused piece of software is Android (like in CVE-2022-20472 or CVE-2023-21079) is just a testament of how big of a monolithic most of the Android userspace is, without ceasing to be a Linux disribution.
>But that doesn't make "an operating system distribution based on Linux kernel with system instrumentation and userspace common to other popular operating systems based on Linux kernel" equal to "Linux distribution" or "Linux".
Well, that's precisely one of the arguments[0] used in favor of naming some Linux distributions as GNU/Linux:
>Since a long name such as GNU/X11/Apache/Linux/TeX/Perl/Python/FreeCiv becomes absurd, at some point you will have to set a threshold and omit the names of the many other secondary contributions. There is no one obvious right place to set the threshold, so wherever you set it, we won't argue against it.
Counter question, is firmware on some cheap-ass $10 router is a Linux distribution? Is this cheap-ass $10 router IS Linux?
> Those two things are core parts of most Linux distributions, yet they are still their own distinct thing
Well, Explorer is the core part of the most of Windows SKUs, yet when the Explorer is at fault - it's Windows fault and goes in the stats, while millions of infected Android phones suddenly doesn't because it's not Linux, it's Android (emphasis mine). Kindergarten level of logic, yet used by grown-ass men.
Well, I think it is. Although they tend to refer to them as Linux-powered, which is still the same but with a hyphen
>Well, Explorer is the core part of the most of Windows SKUs, yet when the Explorer is at fault - it's Windows fault and goes in the stats, while millions of infected Android phones suddenly doesn't because it's not Linux, it's Android (emphasis mine). Kindergarten level of logic, yet used by grown-ass men.
Yeah, probably those things come mostly from how widely present are both Windows and Android on people's lives. It's a media preference since it wont't get you many clicks to say that there was an error on Explorer :P
Still, Android is a Linux distribution until they find a new kernel
Thankfully there are some programs now where kids like that can still thrive under a job+degree hybrid (and no I don't mean that one co-op semester). The work gives them real experience and a faster pace, the degree secures a stable foundation to provide that work context. So maybe when OP is of age the programs will be less limited and accept more students.
in our real world, most of the people making cutting edge breakthroughs in math and science were gifted kids who got a great education through graduate school.
Just depending on age you might refer to it as "a tool called wpa_supplicant to manage its wireless connections, which is not uncommon on older android versions" vs "wpa_supplicant, an old standby Linux wifi management program" or somesuch.
Not suggesting that the work is not impressive, but the kids of today grew up in the era of computers and the Internet, and a lot of problems that were hard for you and me are no longer hard today.
I spent my teenage years learning and understanding sendmail milters. I got to a point where I could write them from scratch. Guess how useful this knowledge is today...
But today, the useful bit is the process you learned to obtain that level of mastery.
All my work arounds and tricks are completely useless today. There is some broader knowledge and problem-solving I learned I’m sure, but ultimately a lot of the tools I learned over the past 15 years are completely useless now and those youngsters are now overcoming their own obstacles!
I was also into these things at that age, without guidance from my environment. It is great to rationalise everything, isn't it ?
This is not meant to doubt him or anything, but the legal stuff makes me wonder whether it was solely him who wrote it.
I wasn't particularly bright. I think we underestimate the capabilities of children.
I see no reason a 14 year old shouldn't be able to program and say, do multivariate calculus. If anything, they are more intellectually capable than someone going through the pains of late adolescence.
Crystallized intelligence at that age might be low, but fluid intelligence is at or near its peak.
I miss the clarity of mind I had when I was younger than that, perhaps 10 or 12.
Probably to a large degree because we lock them up in a room all day where they spend their time listening to information targeted at the bottom decile of the room.
However, I do think they should be encouraged and tutored to go REALLY deep into anything they might be interested in.
Maybe he really is a genius but I've become far more cynical in recent years, don't believe everything on the internet! By the way, I'm 12 years old.
Amazing level of cynicism for a 12 year old, I'm impressed.
Anyone can write with this level of skill now. Just have ChatGPT give you suggestions for improvements
Huh? Anyone who has that hash can still connect to your Wi-Fi network, which kind of defeats what is being claimed. At that point you can also bruteforce the plaintext password (offline, at your leisure), or worse...
They then up the goofyness in that it doesn't provide any mechanism in the UI to actually see the password, but you can screenshot the "share QR" code, read the QR in an app, and finally extract the password phrase that way (at least in all the Android versions I've tried). I have to do this dance regularly b/c scanning a QR code from a laptop is a pain
Loosing all my wifi passwords when I get a new phone always kinda sucks...
Well, it turns out getting the name of the current WiFi network is near impossible. There are four different ways for four different ranges of Android versions, the most recent of which plain doesn't work on my phone.
Somewhere down the line the greedy tracking on mobile apps has gotten so bad that even Google wants to make sure their users know they're being tracked. Without a permanent notification and a permission you can't grant in a popup, you're just not getting the WiFi name.
I completely understand why they changed the API and I'll even agree with the most recent incantation, but the state of mobile app development has become truly deplorabele because of tracking companies and everyone must now suffer the consequences.
https://micahflee.com/2013/07/use-android-youre-probably-giv...
The only way was turning on some enterprise mode most home routers don't have, I think because they didn't want to get sued for leaking company passwords.
Apple used to play that security-by-obscurity game too in their implementation of password sharing with nearby devices, and by not allowing users to view passwords in the Wi-Fi settings (even passwords they hand-entered themselves, as if they can't also make a copy of that in a much less secure place at that point). Fortunately, they've come around in the newer iOS versions.
But which Android feature are you referring to? On my Pixel, I can share the PSK as a QR code – not just the hash as far as I can tell.
The only thing you can't get from the hash (without reversing it) is the password itself, so if you use the same high-entropy one for a different SSID or non-WPA-PSK purpose (but why would you?), it helps a bit in that specific scenario.
Apple has annoyingly decided to share the password hash using the "share Wi-Fi password with nearby devices" at least in some versions, which makes it impossible to actually manually copy-paste over a password received in such a way. I consider that pretty poor security-by-obscurity as well.
If you need your network to be resilient against such attacks, you need WPA-EAP ("enterprise"). PSK was never designed for that threat model. That said, it's a shame WPA-EAP is as complicated to set up and poorly supported by most routers as it is.
Note that deriving keys in a passive fashion only works with WPA2. With WPA3 SAE you must do an active Man in the Middle attack, which means also that you need to possess the key at the time of the handshake. With WPA2 you can decrypt any historic traffic you have recorded.
You dislike this feature? It’s pretty amazing compared to explaining which letters are uppercase and what an ‘&’ is called.
On exception are those originally received via nearby sharing, potentially also those afterwards synced to other devices via Keychain, as the iPhone does not have the preimage to display.
Because, if a device has all of the information needed to connect to a network on it, then.. well, it has all of the information needed to connect to a network on it. Could be passwords, hashes, or whatever -- doesn't really matter.
https://unix.stackexchange.com/questions/40/use-wpa-supplica...
From the PMK, all other per-connection keys are then derived at association time, but everybody that captures that conversation can derive all further keys since that exchange uses only symmetric functions with all secret inputs derived from the PMK, not something like Diffie-Hellman.
It's unfortunately not easy to do anything more resistant against compromised clients without storage on the APs (or at least a stable encryption key available to all access points of an SSID), so WPA-PSK doesn't – for anything more robust than that, you need WPA-EAP. (Some networks support a per-station/MAC address PSK as a proprietary feature, but that's only possible because they do have some management plane that allows the APs to share the required state.)
Anyone with physical access to your Echo probably has a dozen other methods to get access to your password.
Now dumping this is still quite impressive for 14 year old. Kudos.
For example, walk two meters to the side over to where the router sits, flip it over and read the label where the PSK is printed on the router. :D
The only part I don't believe is the three Makefiles. Even grey beards struggle write correct Makefiles. If Daniel wrote those too then that’s the truly impressive feat.
My WiFi network is no different than a hotspot at a coffee shop, anything important lives in another VLAN and has tight access controls. Someone could get access to my network, and they’d have zero ability to do anything useful other than access the public Internet. This also protects against sketchy apps like TikTok and proprietary devices (like voice assistants).
Most people don't have the background to understand that attacks like this are possible. Hell, the other day I almost chucked a couple of old 11n era APs flashed with OpenWRT into the trash until I remembered that there's some incredibly sensitive data (SSID, key, logs, etc.) stored in a manner that likely wouldn't hold up to a physical attack.
I do have the understanding of attacks like this and in a moment of haste to decluter my home office I nearly opened myself up to an attack like the one described in this post.
I can imagine that being effective as part of a complex spear phishing attack against a celebrity or something. But if someone dumpster dives and ends up finding my wifi password, why should I care?
The better coarse of action for a wrongdoer would be to get everything off the router using a serial interface and leave no traces behind for an extended remote access.
The added benefit is that any possible attacker gets two additional data points for free: Where the corresponding SSID is most likely located, and that that household can afford to give away the hardware for free instead of reselling it or trading it in.
that that household can afford to give away the
hardware for free instead of reselling it or trading it in
The Echo Dot in the article retails for $40, cheap enough to be considered disposable by many/most.Would probably gain much more useful socioeconomic information simply by looking at the neighborhood in which said curb is located, right? :)
>Storing passwords in plain text is a major security risk in hotels or businesses using the devices on their internal or private wireless networks, giving any potential attackers access to any other equipment on this network or allowing them to create a rogue network and redirect traffic or conduct a MITM (man-in-the-middle) attack.
Nah, unless it's a truly awful network even for a prosumer let alone any organization. Even with IOT, ever more widespread PPSK support (which I'd consider a must have for anything greenfield at this point) makes segmenting devices onto their own tightly firewalled VLANs trivial. Normal user interactive devices (computers, smartphones, tablets etc) should all be using VPNs for internal access and just not trust the WiFi at all, or at the least again have their own VLANs. These devices should all support WPA-EAP as well so that's another option, and can just use certs and do away with passwords entirely. If IOT wasn't such crap that'd be an option there too but such is life.
It would be fair to say this is all still more complex then it should be, all the tech pieces are in place to make this vastly easier even for the non-technical, the UX is poor in a bunch of respects. And I'm sure there are plenty of small businesses who just run flat networks, maybe with a guest wifi. But that's an issue anyway, and I don't think someone physically stealing an Echo and dumping its eMMC to get at their WiFi password is floor level on their threat model. More like "the desk machine has a password of abc123 and is left unlocked while the elderly B&B lady goes and makes breakfast for guests" and frankly who is breaking in looking for that anyway? It's egg on Amazon's face for sure, absolutely embarrassing for a company of that size and product line that big, and that it's exposed in plaintext on the fs might chain a remote exploit in interesting ways, but not if physical access is required. And again, organizations actually facing threats really just shouldn't be trusting WiFi much anyway. It's not that secure even in theory and implementations are a mess and probably always will be.
I guess the one generalist suggestion I'd have for you just for security overall is to always try to consider the overall threat scenario and "economics" of given attacks when judging seriousness for clients. It's easy to theorycraft purely in terms of hardware or software and get lost in the weeds of attacks that don't actually make any sense. All "security" overall is about the economics between how much it costs to defend and attack and what the value gained/lost is. So things that scale very well, like pure software remote exploits, are huge risks since somebody can run attacks near or fully automatically dirt cheap/free at mass scale and do so in a way that can be hard to trace back. Thus even those with very few resources are at risk, if the attack is free to the attacker then anything at all is profit. In contrast an attack that requires in person access doesn't scale at all, it must be done each time by an actual human actually going out there. And that entails major physical risks as well. So while expensive to defend against, it's also expensive to execute and thus won't happen unless a lot of value is available, and naturally individuals/organizations in that position (lots of money or high value assets) tend to have the resources themselves to take action.
Anyway, "engineering is the art of the possible", getting the best bang for the buck matched to what clients or employers need sometimes is part of the real challenge. Good luck with everything!
Honestly, who has an Amazon Echo dot on a private network in a public place?
Yes, it is a valid attack vector but I would vote the likelyness and importance at very very low risk.
That said, in a corporate network, admins would hopefully put these in a pretty isolated subnet (by SSID+PSK, since they presumably don't support WPA-EAP where you could VLAN/subnet them based on their credentials).
I don't know if such a mechanism exists for networks and I guess it would also be trivial to just spoof a mac address. I guess it does for something like a captive portal.
Hostapd which manages the encryption of wifi access point in pretty much all wireless aps already supports it. You can supply a list of mac address to psk or obtain the psk from radius server. The mac address is provided as the username, all your need to do is return a different psk depending on the mac address. I have POC code lying around I should probably publish somewhere.
Like pointed in sibling comments, it is pretty trivial to clone a mac address so if you were to dump a "unique" psk, all you need is the mac address that goes with it.
What it does gain you though and that is a big plus in some situations, is the ability to revoke a single psk without having to reconfigure all your client devices. That is very useful.
The onboarding is a little bit wacky though. You need an easy way to get the client mac address, generate a unique psk for it, save that in your config, then attempt connection....
One way I would like to explore is have a "next available psk" easily available, for example in an app available to the network administrator. When hostapd asks for the psk associated with unknown/never seen before mac, return that default PSK and save it as associated with that mac on succesful connection, then regenerate a new default PSK for the next device.
This way, an admin can share the password or onboard new devices easily. You don't need to know the mac address of the client in advance.
If you need to revoke access for a device, just revoke the psk that was associated with it.
Another option comes to mind, thinking about it some more: The standard could be extended (or a proprietary extension added) to make the PMK something like Hash(PSK, SSID, client MAC), or Hash(Hash(PSK, SSID), client MAC) for a bit more backwards compatibility.
That wouldn't help against clients that just store the PSK (hash), of course, and clients would in fact need to do that to allow sharing the access, but it would offer some marginal security benefit (for other clients on the network) against attacks on clients that do implement it.
If you have a single AP and replace that for some reason, you'd also need to enter the PSK again on all clients.
WPA-PSK seems like a pretty bare-bones protocol, but if you consider the constraints it has to operate in, it's actually not that easy to come up with something better (other than the omission of ephemeral key exchanges through something like Diffie-Hellman, which was only added in WPA3, but would not help in this threat scenario in any case).
Mikrotik, you can associte PSK with mac address. it's not easy to setup but basically, PSK & mac address need to match in order to access the network. I think it also puts user in the configured vlan.
This is bullshit. The device ultimately needs the wifi passcode in plaintext. What this person is asking for is obfuscation and cryptography theater, not real security.
Of course if you root the device you can read the wifi passcode. This is not shocking.
Why is this the case? There are a number of cryptographic methods of varying complexity which allow a server to authenticate a client against a password without storing the password itself.
Whatever scheme it is, it's probably compromised by rooting the device storing secrets... To make a reference to the quote used by Raymond Chen, the security flaw "rather involved being on the other side of this airtight hatchway".
The security hole, if there is one, is compromising the storage.
Most devices of that era including many Android phones lacked any sort of secure enclave for tamper proof secret storage or encryption. I believe the early Echo stored the wifi password using a weak block cipher and a fixed key, like Kindles. Given the password needs to be eventually decrypted in software, any sort of encryption like this is effectively obfuscation. Physical access is far, far worse!
I think folks forget how much security innovation there has been, and become accessible to consumers, in the last decade. It wasn't too long ago that SSL was considered a luxury.
I suppose access to plaintext vs hashed password in this case saves the owner embarassment if they've used a secret, or if they've used the same password elsewhere, though that isn't a problem of device manufacturer.
If you look in your apple keychains, lastpass, browser saved passwords, all of those data are viewable in plaintext on your machine.
Maybe it could be argued the password shouldn't be stored in plaintext on the storage, so it would have to be decrypted during runtime to get the original plaintext password back again. This does add some security, but only takes someone dedicated enough to pull out the decryption source from the application to get around it.
I hope google chromecast don't show the password.
sniff traffic? you can’t MitM due to HTTPS
so… curious. what can be done?