Google Ordered To Teach America How To Put Passwords On Wi-Fi Networks
forbes.com
forbes.com
The ISM band exists within strict FCC control. There is no "don't sniff" provision and if there was, it would make promiscuous mode or applications like inssider illegal.
I dare say that every day you are protected by the state from those who would take advantage of your ignorance in many, many aspects of the world. The system works well enough that you don't even notice what you're ignorant of!
Edit: so I suppose the distinction's that that the first implies self-contradiction, and the other doesn't. Or perhaps the line is drawn when policy like that interferes with official judgment. Who knows.
The exact role of the state in protecting it's citizens requires nuanced debate. Saying "it's not the state's job" doesn't cut it.
Perhaps you're upset by the language? "Paternalist", to my eye, is a descriptive term that closely matches the circumstances under discussion. If you find that adjective has unfortunate connotations, by all means suggest another that has approximately the same definition.
If someone enters your house without your permission and refuses to leave you may call the police. If there are any immediate threats to person or property the police response will usually be swift (though, of course, this depends on your local P.D.).
I'll stipulate that this isn't what we were taught in junior high civics, but it is the experience of many communities in the USA that security problems are best handled without the intervention of police.
Just because a paternalistic state is usually bad doesn't mean that government shouldn't intervene in anything.
How does an unsecured Wi-Fi network, emanating signal out into the street, deserve some sort of "expectation of privacy"? You deserve no expectation of privacy if your blinds are pulled-up and your windows are open. Why should Wi-Fi be any different, just because users can't be bothered to learn to protect their assets?
How many people do you know who, say, do their own water softener maintenance? Is that plumbing illiteracy/laziness, or is it a sign that people are willing to pay for service that frees their time and attention for more productive things?
If these politicians and prosecutors cared one bit about helping people, they'd regulate the aftermarket wireless router industry to have passwords by default. Or have the FCC change the rules on usage of the ISM band. Instead, they're just posturing for career advancement and media attention.
While I think it's sleazy to spy on people's open WiFi, I don't think it should be illegal.
Making it illegal is a complete waste of resources because it doesn't solve the problem. Google is a giant company and they only got found out more or less by accident. In every other case it's almost trivial to spy on unencrypted WiFi without anybody knowing, which means it would be nearly impossible to enforce a law against it.
This is such a weirdly negative framing. What's wrong with sharing? I've always left my wifi routers open and unsecured so my neighbors can use the bandwidth if they want.
A few things. Some of these things can be mitigated, but I think then we've moved beyond simple sharing.
1. Your neighbor could use too much bandwidth, thereby impacting your usage negatively.
2. Your neighbor could do naughty things on your Internet connection, and you'll be held liable. Practically, this might mean getting a bunch of DMCA notices. For some ISPs, this has a real impact on your account.
3. Many applications by default share their data with whoever is on your network. Maybe this is OK, but maybe it has stuff that you'd rather your neighbors did not see.
To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
2. Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place? And why shouldn't all the network hops in-between be responsible as well???
3.Yes, it is OK
"Link sharing" is OK regardless of your decision whether to share or not. Don't blame the technology man.
> To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
...
> This is not necessarily wrong. Maybe I set it up so he can use all the bandwidth that he can get
Maybe you did. So?
> Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place. And why shouldn't all the network hops in-between be responsible as well???
Red herring. We're not talking about the appropriate legal perspective of network responsibility, but rather, what is the legal perspective of network responsibility.
> Yes, it is OK
For you? Great! Not for everyone. Which was my point.
And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
This has two interpretations. Either you're claiming that:
1) Just because person A doesn't want to share their data doesn't mean that it's bad for person B to share their data.
or
2) Person A doesn't want to share their data, but person A having their data shared unwittingly isn't bad.
I agree with (1). I don't see how (2) can be true. If I don't want my data shared, then having it shared is bad.
Moreover, this isn't even just about sharing data. It's also about sharing bandwidth and legal/ISP ramifications.
> And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
I don't equate it with anything. My initial post was very clear about potential ramifications. Perhaps you should re-read it.
> If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
You're still very clearly missing the point. I don't care who the "true" owner is. I don't care about the workings of the network. In this instance, I care about what my ISP will do to me and what the government will do to me. I was very clear about this in my initial post.
Please revisit the context of this discussion. The top post in this thread asked, "What is wrong with sharing?" I answered with what I could see as the potential pitfalls of sharing. What argument are you trying to make exactly? That sharing has no pitfalls?
To me the issue isn't people sharing their network, it is having the ability to trace an action back to a group of people who have access to a specific network.
I am all for a free and open web and actually have had several arguments with people why I think that access to the internet is starting to become a human right and should be socialized. But there needs to be accountability for your actions online, and for there to be accountability you need to be able to map an action made over a network to the person or people who did it.
This opens the door to all sorts of abuse.
And while we're at it, we should put FBI warning messages on all legally purchased DVDs, because, yes, they do a lot to catch the bad guys who rip them off.
I'm not suggesting that we have a system where someone can look up what anyone is doing on the Internet at any point in time. I'm simply saying that if there is no way to connect an action made online to the real world such that it cannot be used as evidence against someone then anything a person does on the internet has no possible repercussions. Which I think would have some horrific consequences. Yes there is room for some abuse, and an actual implementation of any system would have to work out how to minimize this abuse, but at a certain point you need to trust your government. They have the ability to do a lot worse to a person then find out what they are browsing online.
Trust is something that is earned.
I am a firm believer in this as well. My post way probably a little too aggressive on the side of overwatch, but I tend to go a little to extremes in these kinds of conversations to push the discussion. You're obviously correct, my point was just that there needs to be some kind of accountability for someones action online. Total anonymity and lack of accountability can be just as dangerous in my opinion. Obviously any real life implementation like this would need to find a balance between perserving the rights of the individual and aiding in identifying and prosecuting criminals.
I'm curious as to why you believe it would hinder the legal user experience? I feel like having some sort of accountability to actions made online in the case of illegal activity would have little to no effect on the legal users. Also I think saying that it would do nothing to stop the bad guys is blatantly false. Yes any computer system is able to be compromised by people of high skill but making it require high skill to get around would weed out a lot of people.
Even though people move around with their phones and laptops all the time, network protocols still want to trust the LAN. Things like rogue DHCP servers, unencrypted HTTP traffic and unsecured devices (like printers) are real problems.
Bandwith caps and accountability are also of concern.
Does IP adress = the person who pays the ISP bill?
I suppose legislation could help to clarify things in that regard but that has little to do with understanding the technology.
What I'm saying though, is that (like marssaxman) I'd like more people to share their connection but I understand why many don't given the technical issues, bandwidth bill, and legal uncertainties.
No - because "absence of bug reports does not mean there are no bugs"
Feel free to replace "bug" with "security breach"
Or, are you going to turn off the public WiFi and pretend there was a breach should you get into trouble?
The whole thing is "it's your network you go to jail". That's all they got. And it is not correct, because they can't prove that it was me or someone else, the same way I can't. But if the argument is only on network ownership, then I loose because now the burden of proof is on me and I can't prove anything.
In other words, you're the one with the problem. It is open by design, and there isn't a problem with the design.
All that may be true (though I would argue that, since you use your home connection a lot more than any other, your risk exposure is much greater and therefore it makes sense to have a layered defense there), but it completely misses the point that you are responsible to your ISP for how your internet connection gets used. Starbuck's may be able to say "look, we're a public place, we can't possibly control everything that everybody does on our wifi", and get away with just making people check an "I agree to your terms of use" box when they connect to their wifi. You, as a home user, are not likely to get away with that.
Schneier also says this: "if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence." This seems backwards to me: if you have enabled wireless security, you know exactly who you have authorized access to--it's whoever you gave your passphrase to. So it's easy to distinguish authorized from unauthorized use. If you leave your wifi open and someone uses it for something nefarious, how can you defend yourself? You're still liable for the use of your internet connection, and you can't say the use was unauthorized because, well, you left your wifi open for anyone to use.
His point is that you _should_ be able to get away with that. Precisely because there is no difference between an open network and a cracked one!!!
Yes, there is. An open network means whoever is providing the wifi disclaims all responsibility for how the network is used. Starbuck's may be able to get away with that, as I said, but I don't think the average home user can, unless they have a really unusual ISP. Have you read the fine print in your ISP's terms and conditions?
If the point is that home users should not have to tolerate those kinds of terms and conditions, I don't disagree; but I don't expect it to happen any time soon. :-)
If your wifi is secured and there are open networks nearby, the hacker isn't going to bother trying to hack yours (I assume you're using WPA, not WEP, the latter is so easy to hack now that it doesn't really make a difference). He's going to use one of the open ones. To have a serious chance of having your WPA hacked you would need to have attracted the notice of someone much more determined than your neighborhood porn junkie, someone like the NSA. So I would say the former scenario is much more likely than the latter.
You mean the burden of proof is on you that you secured your network? How can you prove this, because, you know, you can't!
You say you run an open wifi network, so anybody could have downloaded that porn using your wifi? You're a high profile figure and you expect us to believe that? Yeah, right.
We can spin scenarios all day. At the end of the day, I still think that an ordinary person with an ordinary ISP is better off securing their wifi; the likelihood of WPA security being broken is much smaller than the likelihood of someone using your open wifi to do something that your ISP won't like (or worse). Even a high profile figure is, IMO, better off securing their wifi than running an open network for every nutjob who has a fixation on them to use.
For someone in this situation, it's very unfortunate that Google doesn't have this info anymore!
Although historical records would be more dispositive, it isn't difficult to verify that someone is running open wifi now.
Good luck with that. Setting up passwords varies between different routers. So what may work in their ad may not work for grandpa down the road. Telling manufacturers to set a wifi password by default would probably do more to secure people.
http://portforward.com/ exists to help people set up port forwarding, so it is possible to do something similar for passwords.
[1]: http://code.google.com/p/reaver-wps/ [2]: https://community.rapid7.com/servlet/JiveServlet/download/21...
Encryption has true security benefits, primarily the prevention of HTTP session hijacks via tools like Firesheep.
You can still share your network by simply putting the password in the SSID. Name your network "Password is 12345" or something. Encryption protects against Firesheep even if everyone knows the password.
WiFi is designed to trust everyone on the LAN/subnet. But LANs are not secure. People roam between networks all the time. I have around 20 WiFi networks saved on my smartphone right now.
Sadly, people are trained to password protect their WiFi these days. Other than security issues, bandwidth caps and the risk of being held accountable for your internet connections are of concern to a lot of people.