TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google knows nearly every Wi-Fi password in the world

503 pointsby brennannovakover 11 years ago

51 comments

crbover 11 years ago
Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you&#x27;ve (secretly) searched for.<p>Google&#x27;s business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it&#x27;s game over, and no-one will ever trust a secret to Google again. This is why they publish videos saying that no-one can ever walk out of a Google data centre with a hard drive.<p>I continue to use the services I use because I find the benefit I gain from them, more useful than the potential risk of exposure.<p>Should these secrets be encrypted? If they were, it would be possible for Google to steal your key if they wanted to. This is the same kind of perception problem that led to the Chrome team being hauled over the coals in public for not encrypting saved passwords. They have to be available to be useful, but people would rather perceive they weren&#x27;t available.
评论 #6379623 未加载
评论 #6379582 未加载
评论 #6379554 未加载
评论 #6379647 未加载
评论 #6379787 未加载
评论 #6381394 未加载
评论 #6380125 未加载
评论 #6379940 未加载
tytsoover 11 years ago
The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you&#x27;re in trouble. WPS is horribly insecure, for example, and that&#x27;s what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt everything, or use network protocols which encrypt everything.<p>The only thing WiFi passwords are good for is to prevent your neighbors from using your network and using up all of your bandwidth (which would slow down your network access) and preventing drive-by spammers&#x2F;hackers from doing things which you might then get blamed for.
评论 #6380629 未加载
评论 #6380641 未加载
评论 #6382099 未加载
评论 #6380536 未加载
评论 #6381233 未加载
评论 #6380091 未加载
gueloover 11 years ago
Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.
评论 #6381254 未加载
评论 #6380908 未加载
评论 #6381480 未加载
评论 #6381352 未加载
评论 #6382461 未加载
评论 #6381391 未加载
评论 #6381380 未加载
评论 #6380890 未加载
评论 #6381648 未加载
评论 #6381609 未加载
评论 #6381148 未加载
thomasahleover 11 years ago
Funny story:<p>I was once visiting my friends house in the English midlands. I had been there once before, but this time I had to find the way there myself.<p>I managed to get the entire way to his street, but then I realized that I had forgotten his house number. He didn&#x27;t pick up his phone, and I didn&#x27;t want to knock on every door on the road. I was lost.<p>Then I realized that the previous time I had visited, I had logged on his wifi. It was from a different phone, but with Google&#x27;s sync all my old wifi passwords had been synced. I didn&#x27;t remember the name he had given it, but I could walk along the road until I suddenly connected.<p>Saved the night.
jfasiover 11 years ago
This very same point could be made against Apple, for instance, but there hasn&#x27;t been a single comment to that effect in any discussion of this article.<p>I wonder if all of this recent Google-bashing is really just a symptom of something larger. People are suddenly waking up to the obvious-in-hindsight realization that simply giving their data to a third party involves a certain amount of trust.<p>The reason people don&#x27;t seem to be ganging up on Facebook, Apple, etc. in a similar way is because they never really earned that faith. Take Facebook: from the very start their founder was known to consider their users &quot;dumb fucks&quot; for entrusting him with their privacy.<p>In my opinion, the fact that Google went out of their to, and generally succeeded at earning that trust is a good sign. It shows they take the matter seriously.<p>All American companies operate under the same rules. If you&#x27;ve taken the position that all American companies are not to be trusted, fine. But if you haven&#x27;t, wouldn&#x27;t Google&#x27;s history make them one of the more trustworthy ones?
评论 #6379945 未加载
评论 #6380408 未加载
评论 #6379942 未加载
评论 #6379754 未加载
cbrover 11 years ago
Security is about tradeoffs. How bad would it be if someone else got this information? How helpful is it to me to give it to this third party? Wireless passwords are a huge pain: visit someone&#x27;s house, ask them for their password, and then feel guilty while they look through various papers to find a long string of hex digits which are so annoying to enter on the phone. This pain makes the tradeoff well worth if for me (and I suspect for nearly everyone) when balanced against the low risk of Google doing something nasty with the saved passwords.<p>(Disclaimer: I work for Google, but if I had an iPhone I&#x27;d want the same functionality.)
评论 #6380337 未加载
PeterisPover 11 years ago
Are wifi passwords considered a security issue? I treat it the same way as a flimsy lock on a garden shed - I&#x27;d prefer both the shed and wifi to be open, but there&#x27;s a formal &quot;lock&quot; to keep out teenage pranksters and drunks.
评论 #6379803 未加载
tiernanoover 11 years ago
when i read the title, i though &quot;really?! how?&quot; then i read the article and realized any time i have restored my android phone, then entered my Google account, it automagically connects to all access points i usually use (home, work, other office, etc)...
评论 #6379501 未加载
cowlsover 11 years ago
&quot;On an HTC device, the option that gives Google your Wi-Fi password is &quot;Back up my settings&quot;<p>Evil Google, disguising the &#x27;Can we steal your password button&#x27;
prab97over 11 years ago
For convenience, most people won&#x27;t opt out of it. Most people won&#x27;t bother at all. Google employees(or even NSA if you don&#x27;t do anything illegal) coming to your home&#x2F;office to use your WiFi is a joke! Only the paranoid ones are perturbed by these kinds of revelations, and they are ready to face the inconvenience caused.<p>I didn&#x27;t use last pass until recently when keeping a difficult password on every site became a major pain given that countless numbers of password enforcing rules are there on the web some requiring at least one caps, some enforcing using at least one symbol but not using a ~ or a # yeda yeda. I gave up on it. Every damn time I had to reset password on services I use less frequently. But now I don&#x27;t. Although LastPass claims that they keep the passwords encrypted and they themselves can not read them. But I don&#x27;t believe them. Login to lastpass.com. Click your vault on top right corner. Click the pencil against any site in the list. Click the &#x27;show&#x27; link in front of password field. And your password is staring at you in plain text. And it has been accessed at lastpass.com. Once they start storing master passwords, or once someone cracks their hash you are done with. But there is no simple and easy alternative. To get the job done we need to make these sacrifices.
评论 #6379628 未加载
评论 #6379797 未加载
评论 #6379630 未加载
wglbover 11 years ago
Or, in other words, Google remembers the things that we agree to have it remember.
评论 #6380579 未加载
DanBCover 11 years ago
&gt; And, although they have never said so directly, it is obvious that Google can read the passwords.<p>Frustrating then that it&#x27;s so hard for users to reveal the password being used by their phone to connect to a WIFI hotspot.
diminotenover 11 years ago
What does that mean? &quot;Google knows&quot;? That data exists in a database owned by Google, or that Google actively farms that data and makes use of it?<p>Are you saying Google&#x27;s using this for gain, or for <i>any</i> reason? Is there any evidence whatsoever to suggest that this data has <i>ever</i> been accessed by a Google employee ever, for any purpose whatsoever?<p>Slight tangent, but the difference between &quot;can&quot; and &quot;does&quot; is a <i>vast</i> one I don&#x27;t think people are getting, with all these privacy issues coming about these days. Here&#x27;s a scary thought: any person who owns a gun&#x2F;car&#x2F;knife&#x2F;taser&#x2F;baseball bat <i>can</i> kill someone else with it. They <i>could</i> do it.<p>Unless it &quot;does&quot; happen, and there&#x27;s evidence that it happened, they don&#x27;t get in trouble.<p>What Google can do is almost endless. What it does do is what matters.
0x006Aover 11 years ago
And in addition to that they have the audacity to not make them accessible to the user! No way to look up your own wireless password in your phone, i.e. to tell a guest, thats just ridiculous.
评论 #6380002 未加载
评论 #6379570 未加载
njharmanover 11 years ago
&gt; backing up Wi-Fi passwords along with other assorted settings. And, although they have never said so directly, it is obvious that Google can read the passwords.<p>That&#x27;s not obvious. It&#x27;s possible, common, and dare I say a &quot;best practice&quot; to store stuff like this encrypted. To be decrypted only on the device.<p>Also, wifi passwords, Oh my!!! Security wise you should treat your wifi network as open whether it is or not. I.e. isolate it, firewall it, do not trust it.
nlyover 11 years ago
Google can also install anything on my phone remotely.
donniezazenover 11 years ago
I do not agree with the statement that users aren&#x27;t aware of if their settings are being backed up. It is one of the options that users get when setting up Google account on any Android phone.
shmerlover 11 years ago
It&#x27;s completely ridiculous that Google &quot;backs up&quot; passwords in clear text without encrypting them. Mozilla does that properly in their Sync service. So why can&#x27;t Google do that?
评论 #6384349 未加载
chinpokomonover 11 years ago
Does MAC filtering at the router level help at all? If the backup option is turned on, does Google also save your MAC addresses? If not, that seems like a good start to prevent someone from connecting to your network, even if they know the password. Obviously this won&#x27;t help for public hot spots, but I always assume that public hot spots are already open to anyone. What if you are connecting to a Wi-Fi network using MSCHAP or MSCHAPv2? Does Google now know my domain login and password? That seems like a huge gaff.
评论 #6381877 未加载
bobzibubover 11 years ago
IM(Paranoid)O, it puts the &quot;inadvertent&quot; collection of SSIDs while driving down every street taking pictures for Google View into a new context. They gave a simply implausible explanation that this data was recorded &quot;inadvertently&quot;. (No, fitting all those vehicles with the equipment and software would cost serious money!)<p>Marry the Geo-location, SSID, phone owner and passwords and you&#x27;ve got real information for the authorities. On Everyone.
frank_boydover 11 years ago
Another reason to (really) go open-source&#x2F;independent.
评论 #6380005 未加载
anigbrowlover 11 years ago
<i>And, anyone who does run across the setting can not hope to understand the privacy implication. I certainly did not.</i><p>Why not? I see &#x27;back up my settings&#x27; and I assume it means everything. For a computer security reporter to clutch his pearls and say &#x27;I certainly did not&#x27; makes me wonder why he think he&#x27;s qualified to write a column on this subject. Strictly outrage bait.
joostersover 11 years ago
Why all the NSA crap in this thread? You don&#x27;t need to add in a government agency to make this treasure trove of passwords valuable or dangerous. One day, this data will leak out, and then there will be trouble.<p>Just having a reliable set of millions of real world passwords is invaluable - they&#x27;d be useful for brute-forcing other hashed password files.
sspiffover 11 years ago
&gt; And, although they have never said so directly, it is obvious that Google can read the passwords.<p>This is not necessarily true - they could encrypt this data so that it requires a user password to read, and transmit these settings for client-side decryption. They probably don&#x27;t though, and in all likeliness can read your WiFi password.
评论 #6379931 未加载
Zoomlaover 11 years ago
Google don&#x27;t need your Wi-Fi passwords, they have admin rights to a computer inside your network (your phone).
ChrisAntakiover 11 years ago
When you buy a new Android phone, during the first setup it asks you if you&#x27;d like to enable this feature. I&#x27;ve always click &quot;no&quot;.<p>Not sure why the author assumes most Android users would enable this feature... unless he didn&#x27;t realize it was an option on the initial setup.
Havocover 11 years ago
If you&#x27;re running an actual corporate network then a wifi password had better not be the sum total of the protection.<p>For home use - who cares? It would be a sizable mission to make use of the password...and that would get them what? A couple of lolcats and my skyrim saved games? Nice.
aestraover 11 years ago
Google is going to have thousands of different passwords mapped to the SSID &quot;linksys.&quot;
评论 #6379715 未加载
评论 #6379692 未加载
评论 #6381002 未加载
dinkumthinkumover 11 years ago
The author must not realize that Google&#x27;s &quot;customers&quot; are advertisers, not Web searchers or Android users. Why is the government having the data more scary than just Google having it, if we&#x27;re going to be upset about it ...
Fandoover 11 years ago
Just forget about any internet privacy altogether. A new era has arrived.
ovoxoover 11 years ago
While the idea of Google knowing every wi-fi password is bad, they already know everything you search for and they also have a very good idea about all the websites you visit. So ...
darkrover 11 years ago
802.11x&#x2F;EAP-TLS have been around for ages and are well supported on most hardware... As long as Google aren&#x27;t collecting private keys _and_ usernames&#x2F;passwords.
runn1ngover 11 years ago
I am not sure why is this such a problem.<p>OK, when NSA goes physically near my home, they can connect to my WiFi and secretly use my internet connection.<p>That&#x27;s not really what I am concerned about.
评论 #6379614 未加载
评论 #6379631 未加载
d0mover 11 years ago
That&#x27;s how they can give internet for free, now I get it.
thrillgoreover 11 years ago
It&#x27;s troubling to see this, but I&#x27;ve always used MAC Filtering on my home network on top of WPA2 to limit what devices can connect to my network.
评论 #6380422 未加载
评论 #6380459 未加载
gdamjan1over 11 years ago
I hope the owncloud android app will one day have &#x27;backup service&#x27; support, so that I can backup my android to a service I own&#x2F;manage.
NanoWarover 11 years ago
Ehem, and later this year Apple gets your finger print!
评论 #6381521 未加载
progxover 11 years ago
That mean, that the NSA know all passwords too?<p>google must work with the NSA and must give them access to everything, but all is secret because FISA Laws.
ffrryuuover 11 years ago
So does the NSA, and not just your Wi-Fi passwords either. With the new iPhone, soon your fingerprint and movement data too.
jherikoover 11 years ago
when did settings and data become vague terms precisely? sure people might not make the connection that their wifi password is both a setting and some data... do we really need to be alerted to this? although maybe a little info box or something with details of exactly what is sent might be appreciated by the power user...
creatrixcordisover 11 years ago
Great! Now the NSA knows every Wi-Fi password in the world!<p>Which i am sure they are willing to share if just pushed a little.
gjbondgaurav322over 11 years ago
Absolutely, man Chrome is the best browser in the world and through that he can know everybody password...
holriover 11 years ago
This means that I will never allow a phone with a proprietary system into my WIFI.
评论 #6380335 未加载
nodataover 11 years ago
Oh god not this again.
16sover 11 years ago
It&#x27;s only been in the last few years that home wifi routers came with passwords by default. Before that, they defaulted to open access with no password.
ddalexover 11 years ago
Don&#x27;t worry, Google already knows EVERYTHING.
anxiousestover 11 years ago
Not sure what the author is after here. I mean he&#x27;s not breaking any news, he admits as much, he also links to some of the articles that were published weeks ago that do a better job of discussing the security&#x2F;convenience trade offs. Seems like he missed the furore at the the time and decided to compensate with a woefully inaccurate and baiting headline.
评论 #6379524 未加载
niixover 11 years ago
So
Kiroover 11 years ago
I don&#x27;t mind.
Qantouriscover 11 years ago
Scarry
kedar5over 11 years ago
What&#x27;s wrong in it.It&#x27;s not a bank account rite.
评论 #6379798 未加载