Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Catherina

(35,568 posts)
Wed Jul 17, 2013, 01:43 PM Jul 2013

Does NSA know your Wi-Fi password? Android backups may give it to them

Does NSA know your Wi-Fi password? Android backups may give it to them
EFF technologist says "back up my data" exposes users' data to government spies.

by Sean Gallagher - July 17 2013, 10:55am CAST


On by default on most newer Android devices, Google's Android backup stores your personal details in plaintext.

Risk Assessment / Security & Hacktivism
Does NSA know your Wi-Fi password? Android backups may give it to them
EFF technologist says "back up my data" exposes users' data to government spies.

by Sean Gallagher - July 17 2013, 10:55am CAST

If you’re using Google’s “back up my data” feature for Android, the passwords to the Wi-Fi networks you access from your smartphone or tablet are available in plaintext to anyone with access to the data. And as a bug report submitted by an employee of the Electronic Frontier Foundation (EFF) on July 12 suggests, that leaves them wide open to harvesting by agencies like the NSA or the FBI.

“The ‘Back up my data’ option in Android is very convenient,” wrote Micah Lee, staff technologist at the EFF. “However, it means sending a lot of private information, including passwords, in plaintext to Google. This information is vulnerable to government requests for data.”

The Backup Manager app stores Android device settings in Google’s cloud, associated with the user account paired with the device; the Backup Manager interface is part of the core Android application API as well, so it can be used by other Android apps. Backup is turned on by default for Nexus devices and can push data such as MMS and SMS messages, browser bookmarks, call logs, and system settings—including Wi-Fi passwords—to Google’s cloud for retrieval in the event that a device is broken, lost, or stolen.

...

Most of those Wi-Fi networks have been mapped by Google as well. So it would be relatively trivial for an organization with access to backup data to match Wi-Fi network names and passwords with geolocation data. The result would be a partial map of where the targeted user has been as well as access to the networks his or her device has connected to in its travels.

...

http://arstechnica.com/security/2013/07/does-nsa-know-your-wifi-password-android-backups-may-give-it-to-them/

Latest Discussions»General Discussion»Does NSA know your Wi-Fi ...