Google knows nearly every Wi-Fi password in the world
blogs.computerworld.com
blogs.computerworld.com
Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publish videos saying that no-one can ever walk out of a Google data centre with a hard drive.
I continue to use the services I use because I find the benefit I gain from them, more useful than the potential risk of exposure.
Should these secrets be encrypted? If they were, it would be possible for Google to steal your key if they wanted to. This is the same kind of perception problem that led to the Chrome team being hauled over the coals in public for not encrypting saved passwords. They have to be available to be useful, but people would rather perceive they weren't available.
if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data?
edit: to be clear, I use Google services all the time & store a lot of confidential data w/ them. but there need to be institutional (whether at Google or outside it) safeguards that go beyond trusting a company as a whole to always behave in a way compatible w/ its own rational self-interest.
To me, that level of naivety with respect to operational security is just baffling. All it takes is one unscrupulous person in the right place at Google and those convenient, "free" services could end up costing millions. It isn't like the people in the finance industry have a reputation for being upstandingly moral either.
Google Ventures, no matter how spectacularly they might do as VCs, will always be several orders of magnitude less important to Google than Gmail. Google Ventures invests $300 million per year. Say they are always, every year, one of the top VCs so they--every year--deliver 3x on the money invested a few years before. They are still delivering less than $1 billion, less than 2% of Google's revenue.
In reality, it will probably be more like 1%, plus or minus 4%. And also, in reality, it won't be considered revenue, it will be Extraordinary Gains from Non-operational Events, or some such accounting gibberish, and nobody on Wall Street will give them any credit for it.
That's ridiculous. The risk isn't institutionalized abuse, the threat is an unscrupulous guy in the Ventures group who has a buddy who works in the gmail (or other) groups. Calls him up one night and says, "Can you do me a big favor? Check out so-and-so and see what he's working on."
It isn't about Google's bottom line on wall street, it is about an individual abusing access to further his own career.
If there were an unscrupulous person in the gmail group, he would be more likely to break company policy (and, I think, the law) with someone who does not work for Google than with someone who does, unless it were motivated by someone up the chain at Google itself.
Saying that someone at Gmail is sharing your secrets may be a worry. That they would share them with Google Ventures is far less likely than that they would share them with someone else entirely. And frankly, if someone were to try to profit from stolen information, they'd be looking at hedge fund manager emails and investment banker emails. The very slight edge you might get from seeing some VC's email is worth less than a cup of coffee at Starbucks, if you risk-adjust it and discount it back to the present.
I'm assuming that people within a company are more likely to know each other and know what areas they work on versus simply "working at google." They have all kinds of opportunities to rub shoulders - previous projects they've worked on together, company social events, even just riding the google bus to work each day.
While outsiders are also a risk, working for the same company substantially increases the opportunities.
That's virtually all profit, not revenue, and WSt would be thrilled. And all you would need a crooked employee to do that. Maybe a GV partner could approach a SRE...ala http://www.sec.gov/news/press/2011/2011-53.htm
Goldman Sachs and PG board member has been corrupted that way, imagine a lowly engineer that could triple his salary in a heartbeat.
Every single aspect of business and government is susceptible to NSA snooping. Had I access and the lack of scruples, I'd much rather read selections from Goldman Sachs' gmail than any VC's; similarly I'd much rather listen to Obama's telephone calls than Paul Graham's. I'd much rather make my investments in the futures market based on e-mails from high-ranking officials in the DOD than on those from any social networking VC. I could make more money (or have more influence, etc.) that way.
As you say, it takes only "one unscrupulous person". So how common is unscrupulous behavior among highly-trained and highly-screened sysadmins? My bet, no less than 5 in every 100 would be unscrupulous, at least 1 in 100 would be absolute psychopaths, and possibly 1 in 200 would be unscrupulous enough and have sufficient social/business skills to take it to the bank in a big way (I'm talking serious crime/spying/nation-selling).
There may be "Snowdens" out there that we don't know about - persons who are now selling us (corporations, person, and nations) down the river for a few million dollars.
The NSA has put the nation in a very precarious situation.
> if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data?
Already happened: http://gawker.com/5638874/david-barksdale-wasnt-googles-firs...
I am not a fan of Google, but I feel that in Larry Page's era few things are sacred when it comes to making money. Maybe a Googler decides to read some Goldman Sachs' trader emails, or Google in general can sell trend data. Who knows?
They have (IMO) ruined search and destroying any trust in its fairness, yet they are a monopoly, have a lot of goodwill and nothing is happening. So far.
I used to think this but now I'm not so sure. With the way services like FB and others slowly change settings, Sony gets hacked and other data breaches, news about govt spying etc, I wonder whether the mass public is suffering from Learned Helplessness [1]. After all, what alternatives do most people really have?
I guess there are similar incidents happening at almost all cloud providers, but even if detected by the company, we don't hear about them because they're really bad PR. All they come up with is, "trust us, things are secured". And no one cares anyway because Gmail, Docs and Outlook.com are slick and convenient.
This happens in major, respected newspapers. It happens in an extremely disciplined and well-trained superpower's military. Small town telephone operators were sometimes known to spy on the communications of people they knew, and post office workers would sometimes gossip about postal metadata. Organizations can still have integrity (ok, well, maybe not telecoms) when there are a handful of swiftly punished incidents. I'd be concerned if there was a culture of disregard for privacy or a lack of internal controls, unrestricted access for everyone (Barksdale was a Site Reliability Engineer with a legitimate need to access production data, I believe), or no punishment, but this case doesn't invalidate Google's products.
Just out of curiosity, how would we know even if a secret was let out to, say, the NSA or US Govt? Because (a) Google isn't allowed to legally acknowledge it and (b) US LEOs will use "parallel construction" to obscure the fact that they obtained such secret information.
Moreover, if you're not a US citizen, even lesser chances of ever coming to know what information is being handed over/intercepted by the US Govt. If Presidents of countries can be targeted for surveillance, no reason a common person cannot.
Please note, I am not saying Google was specifically guilty of passing on info to the NSA in these cases, but just that, even if they were forced to, there's no way the affected users would come to know.
Link: http://worldnews.nbcnews.com/_news/2013/09/02/20291489-snowd...
And the smartest thing to do, whether you are the NSA or some other foreign government or any entity that holds that information, is to keep quiet about it. The less others know that you know something, the more power you have.
For that reason, it is unlikely that we will see these powers used by the NSA, or other government. It is in their best interest to hold on to that data as secretly as possible and as restrictively as possible, to avoid the chance of others getting a hold of the data. Snowden if anything has only given the NSA and all others who hold the information that we do not know about reason to be careful open even mentioning that they have the data, to anyone.
The "parallel construction" mentioned above is how they do use these powers while obscuring the use of these secrets.
You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices.
Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic options for any of the mayor tech players right now, when they face a data request from the US goverment other than fighting it in the courts? (which they do)
Moving all Google employees to Iceland or some asian country and closing all offices in the US/Western Europe? Closing down any service that collects private data?
Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did.
To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power.
Snowden is a significant outlier... hiring policies are intended to prevent the hire of the kind of person who would do what he did. The scary thing is that Google's hiring practices achieve the same thing.
We do not know this and it would be questionable if the risk associated with such an act would be worth it considering that Google can actually use its resources to move things in a legal way. (via courts, lobbying in Washington etc.)
"To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power."
I remember Google protesting (SOPA) and actively pursuing privacy initiatives multiple times in the last years and even pull out of the Chinese market.
They release detailled copyright removal reports: http://www.google.com/transparencyreport/removals/copyright/
They let you take all your data out of all Google products: http://www.dataliberation.org/takeout-products
They fight governments data requests in courts (sometimes successfully) and release strongly worded statements when they are allowed to.
Suggesting that we ended up with an abusive goverment because Google slavishly followed orders seems unrealistic to me.
"Snowden is a significant outlier... hiring policies are intended to prevent the hire of the kind of person who would do what he did. The scary thing is that Google's hiring practices achieve the same thing."
Google as a company would arguably not exist anymore, if its developers/admins constantly leaked data.
The survival of the NSA does not depend on public trust and a positive public image - Google does.
Google's legal initiatives are largely just naked lobbying for its own corporate interest. SOPA in particular. Nothing wrong with this but it's a lot different than using its legal team to fight government abuses. Google is reasonably scared and chastened by Microsoft's massive antitrust battle, and Eric Schmidt pragmatically ramped up lobbying and philanthropy when he took the helm.
They let you take all your data out of all Google products: http://www.dataliberation.org/takeout-products
Do you think this removes it from the system that the NSA has access to?
They fight governments data requests in courts (sometimes successfully) and release strongly worded statements when they are allowed to.
Strongly worded PR statements while being 100% cooperative. My guess is that the statements are run by the NSA for approval before they are published.
Suggesting that we ended up with an abusive goverment because Google slavishly followed orders seems unrealistic to me.
I did not argue this. But it's a very slow and gradual slide into tyranny, and Google has done nothing to prevent the obvious abuses. I again point to the Government's treatment of Microsoft as a significant driver of Google's supplication.
The survival of the NSA does not depend on public trust and a positive public image - Google does.
Only when the information is kept secret does the NSA's survival not depend on public trust. I'd argue that the NSA depends more on public trust than Google, since Google's motives are very clear, at least insofar as the shareholders are concerned. The NSA is there to protect US interests which generally are not documented and are subject to the whims of both high level and low level officials.
This is where I stopped reading.
I personally know all of the people at Google involved in doing SOPA, and you have literally no idea what you are talking about.
You are talking about a group of people mostly from places like EFF, Creative Commons, and other wonderful orgs. They do it because they want to make the world better, don't want to see the internet censored, and because it's the right thing to do. Maybe you are too cynical and jaded to do something like that, but they aren't. Your opinions have zero basis in fact.
(I read the rest, and it's equally as uninformed. You no nothing of what google has tried to do, done, or anything of the sort, be it related to the NSA or anything else. If Google puts out press releases, you call them self-interested, if they do it quietly, you never notice and think they are 100% cooperative. They are fucked either way).
There is a difference between the people Google has employed to do the work and the corporate strategy behind the work. I have no doubt that the people you describe are truly passionate and dedicated.
But you don't see Google funding advocacy groups for initiatives that don't have a corresponding corporate benefit. Google's evolving stance on net neutrality is a case in point. An analogy would be a housing development firm supporting advocacy of home loans for the poor.
http://searchenginewatch.com/article/2190617/Googles-Legaliz...
Of course there is difference, but you haven't explained what evidence you have that this it the corporate strategy. I actually know the corporate strategy, and i'm stating for a fact it's not as self-interested as you think. You don't have to believe me of course, and I'm not crazy enough to claim google doesn't have interests, but you present it as a very cynical 100% self-interested thing and it's simply not.
"But you don't see Google funding advocacy groups for initiatives that don't have a corresponding corporate benefit."
???? I think you are confused about what google funds.
What is your source of info? Press releases? Have you considered that maybe they don't let press releases happen because they just want the org to succeed, rather than being cynical and self-interested and trying to get credit, and that's why you don't know about it?
I personally helped fund opening of of polling location data (IE getting states to let us tell us where people vote so we could help people find their polling places). https://votinginfoproject.org/ There are now other partners, but Google created it, and funded it, as a separate org.
This was done for no other reason that I felt this was data that should be open, and it was completely ridiculous that you needed to pay various providers (many many figures) in order to get data on telling people where to vote.
This project was entirely altruistic - people were often confused by the info they had, or forgot, or something else. I wanted to solve this problem. There was no money, ads, or anything involved.
My group also funds the software freedom law center, software freedom conservancy, osu labs, etc. Not just open source either.
We fund many millions of dollars to organizations because it's the right thing to do and the orgs are fighting for the right things. Policy does the same. Of course, they do some advocacy and lobbying. But not all or even most of it has any direct corporate benefit.
In DC alone, Google funds a lot of dc related homeless and other advocacy organizations. Do you think Google has designs on ads for homeless people?
So when you say "But you don't see Google funding advocacy groups for initiatives that don't have a corresponding corporate benefit.", it would be more correct to say You don't see. And by "You don't see", that's often because Google doesn't put out press about it, because that's not the point. That would be self interested on Google's part. The point is to help the org.
Thanks for your work and I hope you don't take my remarks as any kind of criticism of the work you do.
Put more cautiously, I think indirect corporate benefit is the main impetus for Google's philanthropy and lobbying programs. There is not necessarily a specific business outcome associated with the philanthropy... it's more like "branding" and "brand awareness" campaigns. The payoff is far into the future and is extremely hard to measure.
How is it possible to feel comfortable with Google's answers when you consider that companies are forbidden from disclosing some information? I'm equally skeptical of the truthfulness of both Google's and the NSA's responses to the revelations.
I'm not able to accept the whole "trust us, everything was circuitously legal so there's nothing to worry about" excuse.
Because you are implicitly claiming that not a single VP, SVP, well known person, etc, would be ethical enough to quit over this if Google had done it wrong. Given who those people are, it seems far fetched.
Further, the recent revelations that the NSA deploys agents as employees of various tech companies (like Google) indicates that Google's internal security processes have been breached and the careful (and likely reasonable) way that cooperation with law enforcement has been crafted may be largely irrelevant.
The above may be wild speculation, and I hope it's incorrect. But considering the Snowden revelations I don't think Google has done enough to make a person or firm that explicitly didn't want the NSA to have access to data its feel comfortable using Google's network and services to store/transmit it.
And, since Google's core business is ads, Google has designed its own systems so that data from any Google service (analytics, dns, gmail, doubleclick) can be used for targeting and behavioral profiling. The scope of it is really quite impressive. Thus I think it's sobering to think about all the data being readily available to the NSA, as Snowden suggests it is.
You could encrypt the data locally before sending it to the server. You might also question whether this model of computing is in fact sensible. There are at least partial alternatives, for instance holding all data locally on a smartphone, and then plugging that in to use as a desktop, tablet etc. We should be asking whether the advantages of the Google model outweigh its (significant) disadvantages.
In fact it would probably be a good idea for Google to proactively report/describe some of the technical tradeoffs they have made when it is related to privacy.
Because what most people do is judge based on incomplete information - and Google has more and more problems with its public perception.
Regarding the idea of encrypting all data (I believe you mean that not even Google should be able to decrypt it) before sending it to the servers I see some issues, but my views on cryptography are probably pretty naive.
1) There are laws that force them to hand over data to governments when courts order it - I do not know if they would get away with only turning over encrypted data.
2) They also have business goals - like increasing ad revenue by matching ads to the personal preferences of its users.
3) They have social interactions in most of their products - I don't know how this could work with total encryption.
4) There are certainly some usability tradeoffs to make - like how many times does a user have to enter a password to access his data.
There are belated efforts by google to encrypt the traffic between its data centres, but its basically too late.
It has also been considered to be pretty secure against eavesdropping due to multiplexing and just the sheer amount of data that can be shoved down a single long-haul fiber these days (5+ Tb/sec). Unfortunately, that's no longer necessarily true when you're up against an adversary with nation-state resources.
Really? Because from what I've seen, the general public (including companies) would just continue using it without caring.
CyanogenMod is on my list.
EDIT: Oh, and "backing up" my contacts without asking me. That made me livid, that's the height of arrogance. And yet I still use Android.
The only thing WiFi passwords are good for is to prevent your neighbors from using your network and using up all of your bandwidth (which would slow down your network access) and preventing drive-by spammers/hackers from doing things which you might then get blamed for.
Most of the problem is that passwords are either easy for computers to crack or hard for humans to remember. The middle ground has disappeared as computational power has increased.
Obligatory xkcd comic: https://xkcd.com/936/
Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination.
Crackers will simply start using wordlist rules to generate large lists of meshed together dictionary words and use them if they have good reason to believe you're using this pattern (pretty sure it's simple with tools like Crunch). Whether they'll guess the proper order is unknown, but as with any other case people will use certain permutations and combinations more than others.
$ wc -l /usr/share/dict/words
119095
$ python -c 'print(119095 ** 4)'
201175048646341950625
$ python -c 'print(85 ** 10)'
19687440434072265625
So, even if your target is known to be using this scheme in pure form, this has more entropy than a completely random 10-digit password (assuming ~85 characters) -- and who would actually be using such a thing, except someone using a password management program - who could just as easily be using a 20-character random password?So even if it becomes known, it's an improvement on what users are doing now.
$ perl -E 'open(my $fh, "<", "/usr/share/dict/words"); my @words = map {chomp; $_} <$fh>; close $fh; say join " ", map {$words[int rand @words]} 1..4'
menu chemists administrative seeps
Might have to run it a couple of times before you get something that you can memorize. shuf -n 4 /usr/share/dict/words | tr -dc 'A-Za-z0-9'Obviously a random 64 character string would beat either of them, but if you're expecting a human to memorize a password, correct horse battery staple is clearly preferable.
There are more possible permutations of four words than permutations of 10 upper/lowercase letters, digits, and common symbols. The four random word approach is harder to crack.
is a really good password that people can remember easily.
Create a near-random 63 char password, put it in a text file on a USB key and possibly print it out as a QR code and you’ll never have to worry about either entering it by hand or it getting cracked by that strange kid across the street.
(You can copy and paste it, though.)
There are a few problems with all PSK schemes that make internal attacks problematic. Anyone who sniffs your initial handshake and knows the master PSK can read your traffic. There's a lack of mutual authentication. Having a scheme where each device registers its own password with the AP would probably be better.
Other than that, it's generally a good solution, why do you feel it needs replacing?
Search for it there is a list of routers that are better than others. With WPA+WPS we are mostly back to WEP days where any kid with a laptop and some googling skills can get access to many wireless networks.
The problem is with the PSK variety, mainly that it's susceptible to offline dictionary attack: about 5% of actual WPA2-PSKs can be easily guessed [1].
There is stuff in the works to fix this though. My favorite is EAP-PWD [2]. It's resistant to offline dictionary attacks, it has perfect forward secrecy and it's already supported by Android. Basically, it's what WPA2-PSK should have been.
In the mean time, if you're security conscious just set a long random PSK or configure e.g. EAP-TLS. Both will give you strong security against pretty much any attacker.
http://en.wikipedia.org/wiki/Extensible_Authentication_Proto...
EDIT: Sorry for having repeated some of the stuff bjornsing already said. Should read through more carefully before rushing to comment, I guess.
The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.
- Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level.
- Until they argue that your technical background means that you should have known better that WEP is crackable.
Following your reasoning, my background means that I should know that I shouldn't have a wireless network at all. There are vulnerabilities for just about any method I would use to secure a wireless network.
My important stuff is firewalled within the network. I use WEP because it's the easiest way to give network access to folks I've authorized to use my network while still letting unauthorized users know they're not welcome.
It would be argued that you should have taken 'reasonable' measures to prevent unauthorized access. It could then be argued that using WEP is not reasonable, especially it you know it is easily crackable.
We should use the default standard method of locking our doors. And our Wi-Fi access points.
A better door analogy is replacing the deadbolt with a slightly crappier one that unlocks whenever you're in bluetooth range (for "convenience"). Just because the system is "easily broken into" doesn't mean that you're not "breaking and entering" when you break the security and enter the house.
However, I try to treat even my home WIFI as if it were a coffee shop. The password is there to keep leechers out, but I still vpn into a more secure location for some tasks, use SSL when connecting to sensitive services, and keep my ports locked down.
WPA2 is in fact quite secure if you're careful about your passkey and who you give it to.
While it certainly could be the crowd I hang out with (not all of which are techies, mind you), but I've never met anyone who uses WPS.
- http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup#Security
Mind you, I think with open source firmware like TomatoUSB and good password you should be good.
Heck, in many countries, wifi routers actually use WPA2 with a pregenerated shared key, which is a good 24 chars long and fully random. Incredibly easy to guess or crack! (its very, very hard to crack.)
As do actors other than Federal agents.
Actually, this is what amuses me in the whole privacy affair. So a bunch of companies were using and abusing your data to target ads at you and shape your news stream so that it's more addictive, and people were cheering. A government (still mostly democratic, though not from my non-US perspective) is revealed to snoop on people illegally and people rage. I don't actually question the rage – but I see the complacent acceptance of the private companies using the same data as amusing.
A large part (not whole, though) of what NSA does is taking your stuff from the place it already shouldn't have been. We're complaining about a fireplace in a burning forest.
I don't mind getting targeted ads, I prefer them to spam ads.
And the reason that it's much scarier if private companies abuse privacy than if the government does it, is that you yourself decide who the government is. You don't get that right wrt a private company.
"Gubment" is pretty silly, though.
http://books.google.com/ngrams/graph?content=SPELT%2BSpelt%2...
from the people that authorizes budget, to the contractors in hawaii reading your info, to the agents in CIA/FBI building evidence against you, to the cops arresting you...
not a single one is your representative. Your only representatives are all in the same dark as you are.
As a practical matter, you have a lot more to fear from corporations misusing your private data to deny you jobs, mess up your credit, etc, than you do from government misusing your private data to shut down your anarchist political movement.
Large business, owned by very rich people. Without campaign contribution limitations and regulation, the voice of people is drowned out by the flow of money. We're about the least regulated in that respect in about a century.
It is hopeless to expect the gov't to not do whatever corporations commonly get away with.
Once the corporations do it, the information in question becomes private property. Now all the gov't has to do is persuade the corporation to hand over or "sell" some little nuggets of their private property. As it is private property that is not yours, it is none of your business in the eyes of the law whether these nuggets of private property are dizzyingly complete records about you.
Then the NSA/GCHQ/BND scandal hit and (at least as far as I can tell) now completely overshadows that former concern.
That said, I read the article more as 'yet another reason this whole compelling third parties is an issue' sorts of reasoning as opposed to this is some new threat that we didn't know about. The author points out it has been covered in lots of places. The argument is that more for the folks who aren't thinking they are affected by this because they aren't dissidents or people of interest (yet).
Quote: "The typical gain for this kind of antenna in the 2.4 GHz Wi-Fi band is about 10 dB."
The gain over a baseline quarter-wave ground-plane antenna obviously comes from the device's directionality.
So define "good design". If you mean an optimal design at any cost, of course not. If you mean clever use of readily available materials, it's a great design.
For my specific setup, it's something of a moot point. With my home office and router at the front of the house, a distance enough to include the back yard will also include a fair chuck of the street. It may be close enough that I'd notice the suspicious vehicle, though.
The idea that the parent poster was trying to point out is that at the point the feds are within 100 ft of your house in a truck or 1000 yards but targeting your house with an antenna, they'll find a way. How secure your Wifi password is irrelevant. At that point they've probably tapped your phones.
Your curt response oversimplifies the situation to the point where an uninformed reader could mistakenly believe the situation has no impact. Your comment should be read in the light of an engineer not only completely missing the point, but an example of the danger of this type of engineering analysis.
Minor technical decisions that "make sense" sometimes have severe technical repercussions.
On (http://hashcat.net/oclhashcat-plus/) you can find some values on how slow it is. The same computer can crack 7 billion md5 hash per seconds, but it can barely do 181 thousand WPA2 password per second.
At this speed you would need more than 200 days just to crack a 7 letter password only using a-zA-Z0-9. And more than 38 years to crack an 8 letter password. If your password is a word or derivation of a word, you can obviously get it much faster with a dictionary attack.
(Quick search, seems a good explanation, if anyone else is curious.)
Source: If you log in to https://play.google.com from a desktop computer, you can install apps on your phone. You get the permissions dialog on the website (on your desktop computer), not on your phone.
How they install them?
I was once visiting my friends house in the English midlands. I had been there once before, but this time I had to find the way there myself.
I managed to get the entire way to his street, but then I realized that I had forgotten his house number. He didn't pick up his phone, and I didn't want to knock on every door on the road. I was lost.
Then I realized that the previous time I had visited, I had logged on his wifi. It was from a different phone, but with Google's sync all my old wifi passwords had been synced. I didn't remember the name he had given it, but I could walk along the road until I suddenly connected.
Saved the night.
I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust.
The reason people don't seem to be ganging up on Facebook, Apple, etc. in a similar way is because they never really earned that faith. Take Facebook: from the very start their founder was known to consider their users "dumb fucks" for entrusting him with their privacy.
In my opinion, the fact that Google went out of their to, and generally succeeded at earning that trust is a good sign. It shows they take the matter seriously.
All American companies operate under the same rules. If you've taken the position that all American companies are not to be trusted, fine. But if you haven't, wouldn't Google's history make them one of the more trustworthy ones?
See a couple of months ago (the context is iMessages but the level of implicit trust is the same): https://news.ycombinator.com/item?id=5943778
I hate to say it because I abhor the word, but this reeks of fanboyism.
Not really. We only learned of FB's attitude to privacy when they started changing defaults and were being sued by the Winklevoss bros. Otherwise, we may never have known what he thought of his early users.
Apple never claimed "Don't be evil" as a motto and they do appear to care more about security. There is encryption in some of their products (even though they can likely still gain access - a point that is made in the article). Arguably, they've done more than Google to demonstrate that they care about my data.
Apple encrypt WiFi passwords and never store them in plain text – not on their servers and not on the device. The encryption requires your login password to decrypt which Apple also don't store in plain text on their servers (although it is accessible on the device if you don't use a PIN or password, it is not backed up to iCloud).
The reason why this allegation is levelled against Google: they don't encrypt backups and they don't encrypt WiFi passwords on the device.
A little more specifically about iOS WiFi passwords: the Keychain (which is where WiFi passwords are backed up on iOS and the Mac) is AES encrypted and requires your login password (or your Apple ID password) to decrypt. Unless Apple is also stealing plain text versions of your login passwords (there's no indication that they are) then it is not possible for Apple to read your WiFi password. Yes, theoretically, they could steal your Apple ID password too but there's no indication that they do (and they've talked about the exact security on Apple IDs following the developer.apple.com breach recently).
In a word, it isn't. The new password is no more nor less safe than the old one. Or are you asking about the data, not the password? Pretty much the same answer.
If Apple resets your Apple ID password and you restart your device (remember: the Apple ID is kept decrypted in RAM while the device is running), you lose the entire keychain and must re-enter all passwords.
Apple makes its money from selling you new hardware every year or two - they need to make you lust after slick, shiny things every keynote.
Google makes its money from knowing about you, mining that data and converting that into advertising clicks - they need to collect as much information about you as possible.
Which means that the same pieces of data have different value to the two companies.
(Of course, Facebook follows a similar model to Google)
(Disclaimer: I work for Google, but if I had an iPhone I'd want the same functionality.)
Since Google has misused access to WIFI hotspots to slurp data it's a little bit more worrying.
Since it's probably personal information it's also probably covered by data protection laws in some countries.
As long as I expect them not to overload my wifi too much, I'm perfectly happy with google or FBI or KGB or friends or random strangers to use have that wifi password.
If wifi routers were good at traffic shaping / quality of service tech, I'd put no passwords at all on wifi devices - if a neighbour wants to browse some web, then it's a good deed to make it easier.
I.e. someone who knows your password could drive by your home, listen to the air and see what you're doing online.
If I use https/ssh, then my traffic is safe even if wifi is open; if I don't, then my traffic is unsafe even if WPA2 is used.
What I had in mind was the following case: if you disrupt someone's connectivity (jam the channel for some time) and force them to reconnect, having listened to nonces and knowing pre-shared secret, you can calculate PMK (and GTK), or I'm wrong?
(I haven't re-checked the specs, but believe 802.11 headers are unencrypted - only payload is - so MACs are not secret.)
I don't think it is a bad thing. It's about as bad as them having "All the IP addresses" - (http://blort.org/~kgasso/images/how-to-catch-script-kiddies....) (http://imgur.com/04sMAxd)
Security is always a trade-off.
Google also knows your Google account password. If you can decrypt the data using any deterministic function of your Google password, then so can Google, so there's no additional security gained. They probably already store your wifi password encrypted -- it's just when the device asks for it, Google decrypts it and sends it back to you. So in all likelihood, they're already doing what you want.
They could have done it by asking the user to provide a new unique password that would have to be entered on each new device. That would provide additional security as only the device could decrypt the password. However, (a) because such a password would only be used once or twice a year at most, no one would remember it and the whole feature would be useless, and (b) you still have to trust Google to not send the password after the device decrypts it, and if you trust the OS vendor to not backdoor the OS, you might as well trust them to not backdoor their own servers to access the same data.
Probably, but not necessarily. All they need to know is the hash of your password. When you set up a new device, it can call out to Google to authenticate without sending a cleartext password (similar to HTTP's Digest auth). Once you've authenticated and retrieved your encrypted settings, the password can be used locally to decrypt the settings. The password never has to leave the device.
If they haven't done it this way (and unless the article's author knows something, I don't think you can tell if they're doing it this way or not from observed behavior) they're either (a) lazy or (b) nefarious. I'm guessing lazy, since that's the reason for most developers who implement poor security... they just don't spend enough time thinking about security of the features they're working on.
Evil Google, disguising the 'Can we steal your password button'
I didn't use last pass until recently when keeping a difficult password on every site became a major pain given that countless numbers of password enforcing rules are there on the web some requiring at least one caps, some enforcing using at least one symbol but not using a ~ or a # yeda yeda. I gave up on it. Every damn time I had to reset password on services I use less frequently. But now I don't. Although LastPass claims that they keep the passwords encrypted and they themselves can not read them. But I don't believe them. Login to lastpass.com. Click your vault on top right corner. Click the pencil against any site in the list. Click the 'show' link in front of password field. And your password is staring at you in plain text. And it has been accessed at lastpass.com. Once they start storing master passwords, or once someone cracks their hash you are done with. But there is no simple and easy alternative. To get the job done we need to make these sacrifices.
This is a simple version of how it works, your master password isn't sent to lastpass, just an encryption key which is created with your email address and master password. On the website this is done client side with javascript. When you click on the pencil icon, you are reading the decrypted file, which you have decrypted on your own computer, with javascript.
The operative question is: when someone signs into a Google account on an Android device, and without any notification whatsoever the device sends his passwords to Google - which is what happens - has there been a meeting of the minds? Are both parties in agreement about what the deal is here?
Data backup is opt in and there is a pretty screen in the setup to enable it if you want
Frustrating then that it's so hard for users to reveal the password being used by their phone to connect to a WIFI hotspot.
Are you saying Google's using this for gain, or for any reason? Is there any evidence whatsoever to suggest that this data has ever been accessed by a Google employee ever, for any purpose whatsoever?
Slight tangent, but the difference between "can" and "does" is a vast one I don't think people are getting, with all these privacy issues coming about these days. Here's a scary thought: any person who owns a gun/car/knife/taser/baseball bat can kill someone else with it. They could do it.
Unless it "does" happen, and there's evidence that it happened, they don't get in trouble.
What Google can do is almost endless. What it does do is what matters.
But I do agree that it's a form of UI-fail that there is no legitimate way for a user to recover his own passwords.
That's not obvious. It's possible, common, and dare I say a "best practice" to store stuff like this encrypted. To be decrypted only on the device.
Also, wifi passwords, Oh my!!! Security wise you should treat your wifi network as open whether it is or not. I.e. isolate it, firewall it, do not trust it.
MSCHAP is not good enough anymore either.
Marry the Geo-location, SSID, phone owner and passwords and you've got real information for the authorities. On Everyone.
If you use a VPS, you can (will) be owned by your VPS provider and any Internet provider your traffic goes through.
If you use colocation or self host, you will have to live without or self host/mantain/develop many alternatives for usual tools AND you can (will) be owned by all the internet providers your traffic goes through.
Not a very nice scenario.
Why not? I see 'back up my settings' and I assume it means everything. For a computer security reporter to clutch his pearls and say 'I certainly did not' makes me wonder why he think he's qualified to write a column on this subject. Strictly outrage bait.
Just having a reliable set of millions of real world passwords is invaluable - they'd be useful for brute-forcing other hashed password files.
This is not necessarily true - they could encrypt this data so that it requires a user password to read, and transmit these settings for client-side decryption. They probably don't though, and in all likeliness can read your WiFi password.
Not sure why the author assumes most Android users would enable this feature... unless he didn't realize it was an option on the initial setup.
For home use - who cares? It would be a sizable mission to make use of the password...and that would get them what? A couple of lolcats and my skyrim saved games? Nice.
OK, when NSA goes physically near my home, they can connect to my WiFi and secretly use my internet connection.
That's not really what I am concerned about.
Devices in an internal network maybe protected, but they are never as protected as they are from requests coming from the internet.
google must work with the NSA and must give them access to everything, but all is secret because FISA Laws.
Which i am sure they are willing to share if just pushed a little.
I'd like to see routers using the passphrase to generate a long lived authentication token. "Good netizens", as the phrase goes, could ensure their routers / client devices didn't store passphrases without inconveniencing the end user.
Then people go crazy about the NSA having the same access.. you guys don't make the link or ... ?
I don't see how trusted networking can be possible in stallmanic world.
SSL should be assumed as broken for defence against government surveillance but it still keeps the most common attackers out.