Google Ordered To Teach America How To Put Passwords On Wi-Fi Networks(forbes.com)
forbes.com
Google Ordered To Teach America How To Put Passwords On Wi-Fi Networks
http://www.forbes.com/sites/kashmirhill/2013/03/13/google-ordered-to-teach-america-how-to-put-passwords-on-wi-fi-networks
70 comments
What a bullshit case, judgement, and punishment. Unencrypted wifi should be collectable. Don't broadcast in the plain on a public channel if you want some special level of privacy. This is an incredible case and probably not politically worth the fight for google. All of our rights have been limited by this judgement.
But most unencrypted wifi exists because of tech illiteracy/laziness on the part of users. Its not a conscious choice they made. Commercial collection is exploiting this. Finally your last sentence is unnecessarily hyperbolic.
Generally, it isnt the job of the state to protect the ignorant and the lazy. Sorry, but this kind of precedent is going to lead to even more draconian judgements over "computer trespassing" and "hacking." Computer crime laws aren't reasonable as-is and now with this new case law, they're arguably worse.
The ISM band exists within strict FCC control. There is no "don't sniff" provision and if there was, it would make promiscuous mode or applications like inssider illegal.
The ISM band exists within strict FCC control. There is no "don't sniff" provision and if there was, it would make promiscuous mode or applications like inssider illegal.
It is exactly the job of the state, because the ignorant do not know how to protect themselves, or even that they are ignorant.
I dare say that every day you are protected by the state from those who would take advantage of your ignorance in many, many aspects of the world. The system works well enough that you don't even notice what you're ignorant of!
I dare say that every day you are protected by the state from those who would take advantage of your ignorance in many, many aspects of the world. The system works well enough that you don't even notice what you're ignorant of!
By this logic, ignorance should then be accepted as a defense to illegal activity, especially in today's world where, increasingly, everyday activity is a crime.
To be fair, he's never said anything about abstract defense or justification - rather, he's talking about government dealing with the consequences.
Edit: so I suppose the distinction's that that the first implies self-contradiction, and the other doesn't. Or perhaps the line is drawn when policy like that interferes with official judgment. Who knows.
Edit: so I suppose the distinction's that that the first implies self-contradiction, and the other doesn't. Or perhaps the line is drawn when policy like that interferes with official judgment. Who knows.
This is also a disturbingly paternalist view of the role of the state, to me.
That's hardly an argument -- it's barely rising above just calling the state names.
The exact role of the state in protecting it's citizens requires nuanced debate. Saying "it's not the state's job" doesn't cut it.
The exact role of the state in protecting it's citizens requires nuanced debate. Saying "it's not the state's job" doesn't cut it.
Let's be fair. the_watcher posts a comment of fifteen words. It's too much to expect "nuanced debate" in a single sentence. I take it you were unconvinced by that sentence; do you believe your three sentences are much more persuasive? Can you imagine a viewpoint that approves most state-provided security services, yet still rejects the actions of the Attorneys General in this case?
Perhaps you're upset by the language? "Paternalist", to my eye, is a descriptive term that closely matches the circumstances under discussion. If you find that adjective has unfortunate connotations, by all means suggest another that has approximately the same definition.
Perhaps you're upset by the language? "Paternalist", to my eye, is a descriptive term that closely matches the circumstances under discussion. If you find that adjective has unfortunate connotations, by all means suggest another that has approximately the same definition.
[deleted]
This is how we end up with bans on soft drinks larger than 16 ounces.
Sorry, but I think Bloomberg is on the correct side of that issue, even if he won't win in court. It's becoming increasingly clear that large quantities of sugar are a long-term poison. Since there's no practical use for soft drinks other than "They taste good" (which is a personal-happiness argument, but a particularly juvenile and narrow-minded one), large softdrinks should be banned. If arsenic salts tasted really good, and they were not already banned, would you oppose efforts to get restaurants to stop serving that?
Just because a paternalistic state is usually bad doesn't mean that government shouldn't intervene in anything.
Just because a paternalistic state is usually bad doesn't mean that government shouldn't intervene in anything.
Mandated warning labels would be a better idea. Banning things is rarely necessary to achieve policy goals.
Ethanol is poison as well.
and on incandescent lamps...
So, by that logic, the "state" is obligated to provide security to homeowners who can not be bothered to lock their homes?
The state is generally obligated to provide security to homeowners who can not be bothered to lock their homes.
If someone enters your house without your permission and refuses to leave you may call the police. If there are any immediate threats to person or property the police response will usually be swift (though, of course, this depends on your local P.D.).
If someone enters your house without your permission and refuses to leave you may call the police. If there are any immediate threats to person or property the police response will usually be swift (though, of course, this depends on your local P.D.).
You have a security problem. You call the police. Now you have two security problems.
I'll stipulate that this isn't what we were taught in junior high civics, but it is the experience of many communities in the USA that security problems are best handled without the intervention of police.
I'll stipulate that this isn't what we were taught in junior high civics, but it is the experience of many communities in the USA that security problems are best handled without the intervention of police.
Remaining tech illiterate is a choice people make.
While I think it's sleazy to spy on people's open WiFi, I don't think it should be illegal.
Making it illegal is a complete waste of resources because it doesn't solve the problem. Google is a giant company and they only got found out more or less by accident. In every other case it's almost trivial to spy on unencrypted WiFi without anybody knowing, which means it would be nearly impossible to enforce a law against it.
While I think it's sleazy to spy on people's open WiFi, I don't think it should be illegal.
Making it illegal is a complete waste of resources because it doesn't solve the problem. Google is a giant company and they only got found out more or less by accident. In every other case it's almost trivial to spy on unencrypted WiFi without anybody knowing, which means it would be nearly impossible to enforce a law against it.
How is this any different than "exploiting" data from Facebook, or mailing lists of people who did not check the box next to the words "I don't want my information to be shared with third-parties"?
How does an unsecured Wi-Fi network, emanating signal out into the street, deserve some sort of "expectation of privacy"? You deserve no expectation of privacy if your blinds are pulled-up and your windows are open. Why should Wi-Fi be any different, just because users can't be bothered to learn to protect their assets?
How does an unsecured Wi-Fi network, emanating signal out into the street, deserve some sort of "expectation of privacy"? You deserve no expectation of privacy if your blinds are pulled-up and your windows are open. Why should Wi-Fi be any different, just because users can't be bothered to learn to protect their assets?
I wouldn't call it laziness. Network setup is something most people just pay their ISP to take care of. It's a commodity service. They don't care how the bits get from here to there, they just want to check their email and go on Facebook.
How many people do you know who, say, do their own water softener maintenance? Is that plumbing illiteracy/laziness, or is it a sign that people are willing to pay for service that frees their time and attention for more productive things?
How many people do you know who, say, do their own water softener maintenance? Is that plumbing illiteracy/laziness, or is it a sign that people are willing to pay for service that frees their time and attention for more productive things?
Except these are self-installs. If it was something their ISP took care of, it would more than likely have a password. So yeah, if I did my own plumbing in a half-assed fashion, I should pay the consequences.
If these politicians and prosecutors cared one bit about helping people, they'd regulate the aftermarket wireless router industry to have passwords by default. Or have the FCC change the rules on usage of the ISM band. Instead, they're just posturing for career advancement and media attention.
If these politicians and prosecutors cared one bit about helping people, they'd regulate the aftermarket wireless router industry to have passwords by default. Or have the FCC change the rules on usage of the ISM band. Instead, they're just posturing for career advancement and media attention.
> to instruct Americans not to let neighbors free-ride on their Wi-Fi networks
This is such a weirdly negative framing. What's wrong with sharing? I've always left my wifi routers open and unsecured so my neighbors can use the bandwidth if they want.
This is such a weirdly negative framing. What's wrong with sharing? I've always left my wifi routers open and unsecured so my neighbors can use the bandwidth if they want.
> What's wrong with sharing?
A few things. Some of these things can be mitigated, but I think then we've moved beyond simple sharing.
1. Your neighbor could use too much bandwidth, thereby impacting your usage negatively.
2. Your neighbor could do naughty things on your Internet connection, and you'll be held liable. Practically, this might mean getting a bunch of DMCA notices. For some ISPs, this has a real impact on your account.
3. Many applications by default share their data with whoever is on your network. Maybe this is OK, but maybe it has stuff that you'd rather your neighbors did not see.
To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
A few things. Some of these things can be mitigated, but I think then we've moved beyond simple sharing.
1. Your neighbor could use too much bandwidth, thereby impacting your usage negatively.
2. Your neighbor could do naughty things on your Internet connection, and you'll be held liable. Practically, this might mean getting a bunch of DMCA notices. For some ISPs, this has a real impact on your account.
3. Many applications by default share their data with whoever is on your network. Maybe this is OK, but maybe it has stuff that you'd rather your neighbors did not see.
To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
1. This is not necessarily wrong. Maybe I set it up so he can use all the bandwidth that he can get
2. Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place? And why shouldn't all the network hops in-between be responsible as well???
3.Yes, it is OK
"Link sharing" is OK regardless of your decision whether to share or not. Don't blame the technology man.
2. Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place? And why shouldn't all the network hops in-between be responsible as well???
3.Yes, it is OK
"Link sharing" is OK regardless of your decision whether to share or not. Don't blame the technology man.
I think you've blithely missed the point. I will quote my concluding remark for further emphasis:
> To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
...
> This is not necessarily wrong. Maybe I set it up so he can use all the bandwidth that he can get
Maybe you did. So?
> Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place. And why shouldn't all the network hops in-between be responsible as well???
Red herring. We're not talking about the appropriate legal perspective of network responsibility, but rather, what is the legal perspective of network responsibility.
> Yes, it is OK
For you? Great! Not for everyone. Which was my point.
> To clarify, I think sharing is great if you decide to do it. But I also think that the uninformed should be advised to not share by default because of the issues I mentioned above.
...
> This is not necessarily wrong. Maybe I set it up so he can use all the bandwidth that he can get
Maybe you did. So?
> Why is only the penultimate hop responsible for the last hop? Why should he be responsible in the first place. And why shouldn't all the network hops in-between be responsible as well???
Red herring. We're not talking about the appropriate legal perspective of network responsibility, but rather, what is the legal perspective of network responsibility.
> Yes, it is OK
For you? Great! Not for everyone. Which was my point.
I get your point. I just don't agree with it. If you don't want to share your data that doesn't make sharing bad. Which is _my_ point.
And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
> If you don't want to share your data that doesn't make sharing bad.
This has two interpretations. Either you're claiming that:
1) Just because person A doesn't want to share their data doesn't mean that it's bad for person B to share their data.
or
2) Person A doesn't want to share their data, but person A having their data shared unwittingly isn't bad.
I agree with (1). I don't see how (2) can be true. If I don't want my data shared, then having it shared is bad.
Moreover, this isn't even just about sharing data. It's also about sharing bandwidth and legal/ISP ramifications.
> And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
I don't equate it with anything. My initial post was very clear about potential ramifications. Perhaps you should re-read it.
> If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
You're still very clearly missing the point. I don't care who the "true" owner is. I don't care about the workings of the network. In this instance, I care about what my ISP will do to me and what the government will do to me. I was very clear about this in my initial post.
Please revisit the context of this discussion. The top post in this thread asked, "What is wrong with sharing?" I answered with what I could see as the potential pitfalls of sharing. What argument are you trying to make exactly? That sharing has no pitfalls?
This has two interpretations. Either you're claiming that:
1) Just because person A doesn't want to share their data doesn't mean that it's bad for person B to share their data.
or
2) Person A doesn't want to share their data, but person A having their data shared unwittingly isn't bad.
I agree with (1). I don't see how (2) can be true. If I don't want my data shared, then having it shared is bad.
Moreover, this isn't even just about sharing data. It's also about sharing bandwidth and legal/ISP ramifications.
> And what _is_ the legal perspective for this issue, anyway? Do you equate it with illegal activities in a house? So the owner is responsible for what's going on there? It's not the same thing.
I don't equate it with anything. My initial post was very clear about potential ramifications. Perhaps you should re-read it.
> If you could be 100% sure that the originator is the true owner maybe you could have a stand in your argument. But you can't be 100% sure that the network is uncrackable.
You're still very clearly missing the point. I don't care who the "true" owner is. I don't care about the workings of the network. In this instance, I care about what my ISP will do to me and what the government will do to me. I was very clear about this in my initial post.
Please revisit the context of this discussion. The top post in this thread asked, "What is wrong with sharing?" I answered with what I could see as the potential pitfalls of sharing. What argument are you trying to make exactly? That sharing has no pitfalls?
Of course those things are possible in theory, but I've been doing this for 14 years and nothing bad has ever happened. I don't believe that it's as big a deal as people make it out to be.
The question is whether you trust your neighbors enough. If you live near a post-secondary institution, say, you might not be willing to leave your network that open.
The real danger with leaving you router unsecured is people piggybacking on the connection to perform illegal actions online. I don't have any stats on how prevalent this actually is but being investigated for something like downloading/distributing child pornography because someone in a van was driving around and stumbled upon your unprotected network would not be a fun experience, and if the fact they used your network makes it more difficult to track the person who did perform these action then that is bad for everyone.
To me the issue isn't people sharing their network, it is having the ability to trace an action back to a group of people who have access to a specific network.
To me the issue isn't people sharing their network, it is having the ability to trace an action back to a group of people who have access to a specific network.
Child porn - the ultimate illegal activity. The only reason people would go on the Internet.
My example was obviously extreme. But I think my point still stands. Being able to trace an action back to a person or a group of people is important if we want to be able to police and prosecute people based on their actions online. Just because the majority of people will have little to no harmful illegal activity doesn't mean we shouldn't put measures in place to be able to identify people who do.
I am all for a free and open web and actually have had several arguments with people why I think that access to the internet is starting to become a human right and should be socialized. But there needs to be accountability for your actions online, and for there to be accountability you need to be able to map an action made over a network to the person or people who did it.
I am all for a free and open web and actually have had several arguments with people why I think that access to the internet is starting to become a human right and should be socialized. But there needs to be accountability for your actions online, and for there to be accountability you need to be able to map an action made over a network to the person or people who did it.
See my other comments. You don't want to prosecute someone on the premise of being the originator. And the reason is that you can't tell the difference between a cracked network and an open one. From outside they look exactly the same.
This opens the door to all sorts of abuse.
And while we're at it, we should put FBI warning messages on all legally purchased DVDs, because, yes, they do a lot to catch the bad guys who rip them off.
This opens the door to all sorts of abuse.
And while we're at it, we should put FBI warning messages on all legally purchased DVDs, because, yes, they do a lot to catch the bad guys who rip them off.
I totally agree that we should not prosecute based on being the originator. But I'm saying it is a reasonable place to start an investigation. Being able to pick a starting point for an investigation even if it just narrows the search to a neighborhood or city or even country(even if it may not totally be correct in cases of people of high technical skill) is at least a better starting point then searching for John Doe who is somewhere, presumably on the planet earth.
I'm not suggesting that we have a system where someone can look up what anyone is doing on the Internet at any point in time. I'm simply saying that if there is no way to connect an action made online to the real world such that it cannot be used as evidence against someone then anything a person does on the internet has no possible repercussions. Which I think would have some horrific consequences. Yes there is room for some abuse, and an actual implementation of any system would have to work out how to minimize this abuse, but at a certain point you need to trust your government. They have the ability to do a lot worse to a person then find out what they are browsing online.
I'm not suggesting that we have a system where someone can look up what anyone is doing on the Internet at any point in time. I'm simply saying that if there is no way to connect an action made online to the real world such that it cannot be used as evidence against someone then anything a person does on the internet has no possible repercussions. Which I think would have some horrific consequences. Yes there is room for some abuse, and an actual implementation of any system would have to work out how to minimize this abuse, but at a certain point you need to trust your government. They have the ability to do a lot worse to a person then find out what they are browsing online.
Why should I ever trust the government? Especially since they have capabilities to do anything they like.
Trust is something that is earned.
Trust is something that is earned.
I'm not saying blindly trust the government on everything. Questioning your government is very important. But there is a baseline level of trust that must exist, you trust them to protect you in times of war, that the money you have will be honoured and so on. It's part of being a citizen of a country and people couldn't function within the country if everyone didn't trust the government on these things.
Freedom to voice politically unpopular beliefs is far more important than making law enforcement easy, and so I believe we must ensure that it is always possible to circumvent the kind of tracing measures you describe.
Freedom to voice politically unpopular beliefs is far more important than making law enforcement easy
I am a firm believer in this as well. My post way probably a little too aggressive on the side of overwatch, but I tend to go a little to extremes in these kinds of conversations to push the discussion. You're obviously correct, my point was just that there needs to be some kind of accountability for someones action online. Total anonymity and lack of accountability can be just as dangerous in my opinion. Obviously any real life implementation like this would need to find a balance between perserving the rights of the individual and aiding in identifying and prosecuting criminals.
I am a firm believer in this as well. My post way probably a little too aggressive on the side of overwatch, but I tend to go a little to extremes in these kinds of conversations to push the discussion. You're obviously correct, my point was just that there needs to be some kind of accountability for someones action online. Total anonymity and lack of accountability can be just as dangerous in my opinion. Obviously any real life implementation like this would need to find a balance between perserving the rights of the individual and aiding in identifying and prosecuting criminals.
The reason you get into argunents is because your point of view is flawed. It would be far to easy to hide yourself or fake your id. Implementing anything like this would simply hinder the legal user experience and do nothing to stop the bad guys.
I understand that hiding or faking an id is a concern for highly technical people but I would hope that it would not be easy to the point where someone of medium to low technical skill could do it.
I'm curious as to why you believe it would hinder the legal user experience? I feel like having some sort of accountability to actions made online in the case of illegal activity would have little to no effect on the legal users. Also I think saying that it would do nothing to stop the bad guys is blatantly false. Yes any computer system is able to be compromised by people of high skill but making it require high skill to get around would weed out a lot of people.
I'm curious as to why you believe it would hinder the legal user experience? I feel like having some sort of accountability to actions made online in the case of illegal activity would have little to no effect on the legal users. Also I think saying that it would do nothing to stop the bad guys is blatantly false. Yes any computer system is able to be compromised by people of high skill but making it require high skill to get around would weed out a lot of people.
I can't agree more. But there are real concerns with sharing.
Even though people move around with their phones and laptops all the time, network protocols still want to trust the LAN. Things like rogue DHCP servers, unencrypted HTTP traffic and unsecured devices (like printers) are real problems.
Bandwith caps and accountability are also of concern.
Even though people move around with their phones and laptops all the time, network protocols still want to trust the LAN. Things like rogue DHCP servers, unencrypted HTTP traffic and unsecured devices (like printers) are real problems.
Bandwith caps and accountability are also of concern.
These things were built into the network with good reasons. As were the ways to secure yourself. Just because it is insecure by design doesnt mean laws should be in place to protect those who show no desire to understand or use technology in the way it was designed. Should cars speed be limited based on the speed limit just because a few speed? That is what you are talking about
When did I say a things about laws? By accountability, I mean:
Does IP adress = the person who pays the ISP bill?
I suppose legislation could help to clarify things in that regard but that has little to do with understanding the technology.
What I'm saying though, is that (like marssaxman) I'd like more people to share their connection but I understand why many don't given the technical issues, bandwidth bill, and legal uncertainties.
Does IP adress = the person who pays the ISP bill?
I suppose legislation could help to clarify things in that regard but that has little to do with understanding the technology.
What I'm saying though, is that (like marssaxman) I'd like more people to share their connection but I understand why many don't given the technical issues, bandwidth bill, and legal uncertainties.
"Does IP adress = the person who pays the ISP bill"
No - because "absence of bug reports does not mean there are no bugs"
Feel free to replace "bug" with "security breach"
No - because "absence of bug reports does not mean there are no bugs"
Feel free to replace "bug" with "security breach"
I agree. But if I'm sharing my WiFi connection, a "security breach" can't be defined as "someone using my IP address" as I'm also sharing that willingly through my NAT router.
Or, are you going to turn off the public WiFi and pretend there was a breach should you get into trouble?
Or, are you going to turn off the public WiFi and pretend there was a breach should you get into trouble?
I mean, if I have to prove that there was a breach, I couldn't.
The whole thing is "it's your network you go to jail". That's all they got. And it is not correct, because they can't prove that it was me or someone else, the same way I can't. But if the argument is only on network ownership, then I loose because now the burden of proof is on me and I can't prove anything.
The whole thing is "it's your network you go to jail". That's all they got. And it is not correct, because they can't prove that it was me or someone else, the same way I can't. But if the argument is only on network ownership, then I loose because now the burden of proof is on me and I can't prove anything.
[deleted]
The problem is that if you don't encrypt your over-the-air signal anyone can monitor your traffic.
I don't have a drinking problem, you have a problem with my drinking, and that is not my problem.
In other words, you're the one with the problem. It is open by design, and there isn't a problem with the design.
In other words, you're the one with the problem. It is open by design, and there isn't a problem with the design.
Aren't two issues being conflated here? (1) Securing access to your wi-fi with a password so that your neighbor can't free-ride on your ISP and (2) Encrypting your wi-fi traffic so that your neighbor (or Google) can't spy on you.
Conceptually, yes, these are two different issues. But since wifi security pretty much requires encryption of the traffic (otherwise anyone could just sniff your credentials during the access negotiation), and encryption requires some sort of access control anyway, they always go together in practice.
schneier on open wifi networks (he's for them): http://www.schneier.com/blog/archives/2011/04/security_risks...
I normally agree with Schneier, but I think he's wrong on this one. Basically his argument is that, rather than try to secure your wifi, you should just leave it open and make sure your personal computers are secure enough to be used on an open network. He points out that, if you use your laptop on public networks, you have to secure it anyway, so there's no additional risk to having your home wifi basically be a public network.
All that may be true (though I would argue that, since you use your home connection a lot more than any other, your risk exposure is much greater and therefore it makes sense to have a layered defense there), but it completely misses the point that you are responsible to your ISP for how your internet connection gets used. Starbuck's may be able to say "look, we're a public place, we can't possibly control everything that everybody does on our wifi", and get away with just making people check an "I agree to your terms of use" box when they connect to their wifi. You, as a home user, are not likely to get away with that.
Schneier also says this: "if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence." This seems backwards to me: if you have enabled wireless security, you know exactly who you have authorized access to--it's whoever you gave your passphrase to. So it's easy to distinguish authorized from unauthorized use. If you leave your wifi open and someone uses it for something nefarious, how can you defend yourself? You're still liable for the use of your internet connection, and you can't say the use was unauthorized because, well, you left your wifi open for anyone to use.
All that may be true (though I would argue that, since you use your home connection a lot more than any other, your risk exposure is much greater and therefore it makes sense to have a layered defense there), but it completely misses the point that you are responsible to your ISP for how your internet connection gets used. Starbuck's may be able to say "look, we're a public place, we can't possibly control everything that everybody does on our wifi", and get away with just making people check an "I agree to your terms of use" box when they connect to their wifi. You, as a home user, are not likely to get away with that.
Schneier also says this: "if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network? If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence." This seems backwards to me: if you have enabled wireless security, you know exactly who you have authorized access to--it's whoever you gave your passphrase to. So it's easy to distinguish authorized from unauthorized use. If you leave your wifi open and someone uses it for something nefarious, how can you defend yourself? You're still liable for the use of your internet connection, and you can't say the use was unauthorized because, well, you left your wifi open for anyone to use.
"You, as a home user, are not likely to get away with that."
His point is that you _should_ be able to get away with that. Precisely because there is no difference between an open network and a cracked one!!!
His point is that you _should_ be able to get away with that. Precisely because there is no difference between an open network and a cracked one!!!
there is no difference between an open network and a cracked one!!!
Yes, there is. An open network means whoever is providing the wifi disclaims all responsibility for how the network is used. Starbuck's may be able to get away with that, as I said, but I don't think the average home user can, unless they have a really unusual ISP. Have you read the fine print in your ISP's terms and conditions?
If the point is that home users should not have to tolerate those kinds of terms and conditions, I don't disagree; but I don't expect it to happen any time soon. :-)
Yes, there is. An open network means whoever is providing the wifi disclaims all responsibility for how the network is used. Starbuck's may be able to get away with that, as I said, but I don't think the average home user can, unless they have a really unusual ISP. Have you read the fine print in your ISP's terms and conditions?
If the point is that home users should not have to tolerate those kinds of terms and conditions, I don't disagree; but I don't expect it to happen any time soon. :-)
As Schneier describes it, there is a trade-off. Would you rather be kicked by your ISP for T&C violations, or imprisoned and branded a sex offender for your neighborhood wireless hacker's kiddie porn habits? If the chances of each scenario were roughly equal, I'd certainly agree with Schneier to prefer the former scenario. Since the former scenario seems much more likely than the latter I'm not so sure.
your neighborhood wireless hacker's kiddie porn habits
If your wifi is secured and there are open networks nearby, the hacker isn't going to bother trying to hack yours (I assume you're using WPA, not WEP, the latter is so easy to hack now that it doesn't really make a difference). He's going to use one of the open ones. To have a serious chance of having your WPA hacked you would need to have attracted the notice of someone much more determined than your neighborhood porn junkie, someone like the NSA. So I would say the former scenario is much more likely than the latter.
If your wifi is secured and there are open networks nearby, the hacker isn't going to bother trying to hack yours (I assume you're using WPA, not WEP, the latter is so easy to hack now that it doesn't really make a difference). He's going to use one of the open ones. To have a serious chance of having your WPA hacked you would need to have attracted the notice of someone much more determined than your neighborhood porn junkie, someone like the NSA. So I would say the former scenario is much more likely than the latter.
Let's see: You are a high profile figure who happened to step on someone's tail. What should we do to make you behave?
I know, we'll show the whole world how you download child porn. Did I say "child porn"?
You mean the burden of proof is on you that you secured your network? How can you prove this, because, you know, you can't!
You mean the burden of proof is on you that you secured your network? How can you prove this, because, you know, you can't!
So you're saying that if you are a high profile figure who happened to step on someone's tail, you should run an open wifi network to make it exponentially easier for your enemies to convince the world that you download child porn?
You say you run an open wifi network, so anybody could have downloaded that porn using your wifi? You're a high profile figure and you expect us to believe that? Yeah, right.
We can spin scenarios all day. At the end of the day, I still think that an ordinary person with an ordinary ISP is better off securing their wifi; the likelihood of WPA security being broken is much smaller than the likelihood of someone using your open wifi to do something that your ISP won't like (or worse). Even a high profile figure is, IMO, better off securing their wifi than running an open network for every nutjob who has a fixation on them to use.
You say you run an open wifi network, so anybody could have downloaded that porn using your wifi? You're a high profile figure and you expect us to believe that? Yeah, right.
We can spin scenarios all day. At the end of the day, I still think that an ordinary person with an ordinary ISP is better off securing their wifi; the likelihood of WPA security being broken is much smaller than the likelihood of someone using your open wifi to do something that your ISP won't like (or worse). Even a high profile figure is, IMO, better off securing their wifi than running an open network for every nutjob who has a fixation on them to use.
You're a high profile figure and you expect us to believe that?
For someone in this situation, it's very unfortunate that Google doesn't have this info anymore!
Although historical records would be more dispositive, it isn't difficult to verify that someone is running open wifi now.
For someone in this situation, it's very unfortunate that Google doesn't have this info anymore!
Although historical records would be more dispositive, it isn't difficult to verify that someone is running open wifi now.
> Google is going to teach naive people how to put passwords on their Wi-Fi networks.
Good luck with that. Setting up passwords varies between different routers. So what may work in their ad may not work for grandpa down the road. Telling manufacturers to set a wifi password by default would probably do more to secure people.
Good luck with that. Setting up passwords varies between different routers. So what may work in their ad may not work for grandpa down the road. Telling manufacturers to set a wifi password by default would probably do more to secure people.
Many newer routers come with a "first setup" page that forces you to pick a wifi password.
http://portforward.com/ exists to help people set up port forwarding, so it is possible to do something similar for passwords.
http://portforward.com/ exists to help people set up port forwarding, so it is possible to do something similar for passwords.
Setting wifi passwords would be a good start, but then you'd still have to address the security flaws in wps[1] and upnp[2][pdf].
[1]: http://code.google.com/p/reaver-wps/ [2]: https://community.rapid7.com/servlet/JiveServlet/download/21...
[1]: http://code.google.com/p/reaver-wps/ [2]: https://community.rapid7.com/servlet/JiveServlet/download/21...
Well, it doesn't need to be secure _per se_, just secure enough that it mitigates Google's liability. Like the password/PIN rules at the bank.
They are probably hoping Google create a router.
I would like to propose that we, as technologically literate people, start to separate the concepts of encrypting your WiFi signal, and sharing your WiFi signal.
Encryption has true security benefits, primarily the prevention of HTTP session hijacks via tools like Firesheep.
You can still share your network by simply putting the password in the SSID. Name your network "Password is 12345" or something. Encryption protects against Firesheep even if everyone knows the password.
Encryption has true security benefits, primarily the prevention of HTTP session hijacks via tools like Firesheep.
You can still share your network by simply putting the password in the SSID. Name your network "Password is 12345" or something. Encryption protects against Firesheep even if everyone knows the password.
Are you sure about that? How does that possibly work? If the shared secret is known, how can you possibly prevent people from hijacking the connection?
Both the AP and the client station produce nonces, which together with the passphrase and other values are used to calculate "pairwise" keys and eventually session keys. This makes hijacking more difficult. As you intuit, however, it can certainly be done by one who knows the passphrase and is able to sniff the nonces.
Unfortunately, there's no widely supported way of encrypting the traffic of individual users on a publicly accessible network.
WiFi is designed to trust everyone on the LAN/subnet. But LANs are not secure. People roam between networks all the time. I have around 20 WiFi networks saved on my smartphone right now.
Sadly, people are trained to password protect their WiFi these days. Other than security issues, bandwidth caps and the risk of being held accountable for your internet connections are of concern to a lot of people.
WiFi is designed to trust everyone on the LAN/subnet. But LANs are not secure. People roam between networks all the time. I have around 20 WiFi networks saved on my smartphone right now.
Sadly, people are trained to password protect their WiFi these days. Other than security issues, bandwidth caps and the risk of being held accountable for your internet connections are of concern to a lot of people.