Google Storing WLAN Passwords In the Clear
First time accepted submitter husemann writes "Micah Lee from the EFF filed a bug report about Google storing all your WLAN passwords on their application settings backup service without allowing you to encrypt them. So far it's not known whether the passwords are stored encrypted at rest, but just the fact that Google can read them (and disclose them if forced by 'law') is a bit surprising, too put it nicely. Already one German university is concerned enough about this 'feature' that they issued a warning to their users."
I think this is perfect example again that we put too much trust on Google. They have repeatly broken that trust and yet some people continue to trust them. This data also goes directly to NSA and FBI. I think both FCC and European Commission should hit them hard, upto jailing the top executives.
I turned off Backup on Android after discovering this. They're going to have to store them in the clear (or I guess reversible), so that the "backup" is reversible - i.e. you recover your backup or add a new phone to your account and it "just works" with your wifi.
However, there's no in-between. I can't choose to backup certain things but exclude very sensitive things, like my wifi password and other credentials. Given what we know about government snooping and the constant notices of breached databases these days, I just don't want to use the backup feature at all, and anyone who does is taking a bit of a gamble IMO.
Can't we have a sub-option to "also include credentials", at the very least?
This kind of shit is exactly why, as soon as I got an Android smartphone, I also installed a second wireless router, with its own encryption password, outside my firewall. Anybody who wasn't already assuming that smartphones and tablets are anything other than hostile network actors is an idiot.
Here's the thing. Even if you encrypt the data before giving it to them, and dont keep the key (which is much harder to do than to say) so what? Do you really think any encryption algorithm you are going to use today will stand up to the tools available to script-kiddies in 5 or 10 years? You do understand that once you put something 'in the cloud' it's probably never going away, right?
=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Friends don't let friends enable ecmascript.