ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Windows 10 Wi-Fi Sense is a bad idea

    IT Discussion
    microsoft windows 10 security
    6
    118
    31.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by JaredBusch

      Just had @TechnicalAngel send me this link.

      http://www.tomsguide.com/us/windows-10-wifi-sense,news-21409.html

      WTF.. Come on Microsoft how f'n stupid can you be..

      If you're taking up Microsoft on its offer of a free upgrade to Windows 10, you should know that the new operating system has a feature, called Wi-Fi Sense, that automatically shares your Wi-Fi passwords with others.

      When Wi-Fi Sense is enabled, anyone you have in your Skype, Outlook or Hotmail contacts lists — and any of your Facebook friends — can be granted access to your Wi-Fi network as long as they're within range. Microsoft added this feature to save users' time and hassle, but as independent security blogger Brian Krebs put it, some security experts see it as "a disaster waiting to happen."

      1 Reply Last reply Reply Quote 4
      • scottalanmillerS
        scottalanmiller
        last edited by

        That's a bit nutty. What a bad idea.

        1 Reply Last reply Reply Quote 0
        • Reid CooperR
          Reid Cooper
          last edited by

          This is terrible. Does this include business networks or Pro versions?

          1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch
            last edited by

            I never used WiFi on my Insider Preview VM so I have no idea. My daughter's laptop has not popped that up yet. It is Windows 10 Home and here is what settings are available.

            2015-07-30 21_34_49-Settings.png
            2015-07-30 21_35_08-Settings.png

            1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch
              last edited by

              Turning off the "Connect to netoworks shared by my contacts" setting seems to disable all sharing.

              2015-07-30 21_35_38-Settings.png

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Wow, even Facebook is on by default?

                JaredBuschJ 1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch @scottalanmiller
                  last edited by

                  @scottalanmiller said:

                  Wow, even Facebook is on by default?

                  You still have to grant it FB permission, but yeah.

                  1 Reply Last reply Reply Quote 1
                  • A
                    Alex Sage
                    last edited by

                    How come this is a bad idea? Personal I think it is awesome. Has been in Windows Phone for a while.

                    JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @Alex Sage
                      last edited by

                      @anonymous said:

                      How come this is a bad idea? Personal I think it is awesome. Has been in Windows Phone for a while.

                      Go read the linked article and come back to me on how this is a good idea..

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Alex Sage
                        last edited by

                        @anonymous said:

                        How come this is a bad idea? Personal I think it is awesome. Has been in Windows Phone for a while.

                        Surprise sharing of security information with social media contacts is data leakage. It would be a great way to social engineer someone or just confuse people about their security boundaries.

                        1 Reply Last reply Reply Quote 1
                        • A
                          Alex Sage
                          last edited by

                          They don't know what your password is.... They just auto connect when they are in range.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Alex Sage
                            last edited by

                            @anonymous said:

                            They don't know what your password is.... They just auto connect when they are in range.

                            Their machine knows what your password is. More or less the same thing. Are you saying that their machine can be trusted to keep secrets from its owners?

                            A 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              This is actually a great way to hack other people. You could set up a way to capture their data with a man in the middle attack and use this as a way to get them to connect to a wifi they were not aware that they were going to connect to. It's not safe for either party, really.

                              A 1 Reply Last reply Reply Quote 0
                              • A
                                Alex Sage @scottalanmiller
                                last edited by

                                @scottalanmiller said:

                                Their machine knows what your password is. More or less the same thing. Are you saying that their machine can be trusted to keep secrets from its owners?

                                It's encrypted.

                                scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 0
                                • A
                                  Alex Sage @scottalanmiller
                                  last edited by

                                  This post is deleted!
                                  1 Reply Last reply Reply Quote 0
                                  • JaredBuschJ
                                    JaredBusch
                                    last edited by

                                    Even simpler than that. It gives people access to my wireless network without my explicit permission.

                                    I have ZERO method to control this sharing other than renaming my entire wireless network with some stupid _optout on the SSID.

                                    A 1 Reply Last reply Reply Quote 1
                                    • A
                                      Alex Sage @JaredBusch
                                      last edited by

                                      @JaredBusch said:

                                      Even simpler than that. It gives people access to my wireless network without my explicit permission.

                                      I have ZERO method to control this sharing other than renaming my entire wireless network with some stupid _optout on the SSID.

                                      So you don't trust your friend? Or you don't trust yourself to keep up in your contact list?

                                      scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Alex Sage
                                        last edited by

                                        @anonymous said:

                                        It's encrypted.

                                        Maybe, but access is already granted. We'll have to see how this encryption holds up. Sharing data with someone means that your security has been compromised. When people talk about data center breaches, often it is encrypted data that they get. They just get unlimited time to crack it. Cracking data you own is generally pretty trivial. Not seconds or minutes, but very, very doable.

                                        But that's the lesser concern. That a human knows your password is only so big of a deal. What matters is that a human can leverage that password at will.

                                        1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch @Alex Sage
                                          last edited by

                                          @anonymous said:

                                          It's encrypted.

                                          Doesn't matter.

                                          You are my FB firned and gain access to my network.

                                          Your FB friend that lives across town drives by my house and pulls the password from you while at a stoplight.

                                          His FB friend is my neighbor (that I don't know except to see in passing sometimes int he parking lot) and now has unlimited access to my private wifi network.

                                          A DashrenderD 2 Replies Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @Alex Sage
                                            last edited by

                                            @anonymous said:

                                            So you don't trust your friend? Or you don't trust yourself to keep up in your contact list?

                                            You have a very different definition of friend than I do. "Person with access to an account that is a 'friend' with mine on a communications system" is not what I call a friend. My contact list includes business associates, people who want to chat with me, etc. The security of my Facebook or Skype list, all of which is just public info, is now a weak link in the security of any wifi to which I have access, not necessarily my own.

                                            This has nothing to do with friends, this has to do with an arbitrary usage of one data set for a purpose for which it is not and never was intended. It's a massive security vulnerability, it's that simple. Even the idea that the association via FB or Skype somehow means friends is a fundamental flaw - the connection on Skype in no way suggests that I know that person, like that person or am friends with them.

                                            The leap between "random list A" and "people you want to grant access to your network" is huge.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 1 / 6
                                            • First post
                                              Last post