{"id":2650,"date":"2015-08-03T22:35:56","date_gmt":"2015-08-04T03:35:56","guid":{"rendered":"https:\/\/justinparrtech.com\/JustinParr-Tech\/?p=2650"},"modified":"2015-08-04T15:56:00","modified_gmt":"2015-08-04T20:56:00","slug":"wifi-sense-has-microsoft-crossed-the-line","status":"publish","type":"post","link":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/","title":{"rendered":"WiFi Sense:  Has Microsoft Crossed the Line?"},"content":{"rendered":"<p>Windows 10 rolls out with a feature called &#8220;WiFi Sense&#8221;, the ability to cache WiFi passwords, and share them with your contacts.<\/p>\n<p>There are arguments in both directions, but I feel that Microsoft has crossed the line.\u00a0 Here is why&#8230;.<\/p>\n<p>&nbsp;<\/p>\n<p><!--more--><\/p>\n<p>&nbsp;<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_81 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\"><p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<\/div><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#recap-of-wifi-sense\" >Recap of WiFi Sense<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#arguments-for-and-against\" >Arguments For and Against<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-its-convenient\" >For:\u00a0 It&#8217;s convenient<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-sharing-with-your-outlook-contacts-is-no-different-than-telling-them-in-person\" >For:\u00a0 Sharing with your Outlook contacts is no different than telling them in person<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-this-has-been-available-since-windows-phone-8\" >For:\u00a0 This has been available since Windows Phone 8<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-if-you-object-you-can-always-opt-out\" >For:\u00a0 If you object, you can always opt-out!<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-its-cool\" >For:\u00a0 It&#8217;s Cool!<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#for-corporate-networks-are-excluded\" >For:\u00a0 Corporate Networks are Excluded<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#against-its-a-security-breach\" >Against:\u00a0 It&#8217;s a Security Breach<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#against-its-an-ethical-breach\" >Against:\u00a0 It&#8217;s an ethical breach<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#why-i-feel-that-microsoft-has-crossed-the-line\" >Why I Feel that Microsoft has Crossed the Line<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/justinparrtech.com\/JustinParr-Tech\/wifi-sense-has-microsoft-crossed-the-line\/#recommendations\" >Recommendations<\/a><\/li><\/ul><\/nav><\/div>\n\n<p>&nbsp;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"recap-of-wifi-sense\"><\/span>Recap of WiFi Sense<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Rolled out as part of Windows Phone 8, this &#8220;feature&#8221; allows you to save any WiFi password, and share it with any of your contacts on Outlook.com<\/p>\n<p>So, Alice connects to a WiFi network called &#8220;NETWORK1&#8221;.\u00a0 She gets the password, saves the connection, and chooses to share it using WiFi sense.<\/p>\n<p>Bob sees that Alice connected to &#8220;NETWORK1&#8221;, so he&#8217;s now able to connect to NETWORK1.\u00a0 Bob can&#8217;t SEE the password, nor can he share it with Fred&#8230; only ALICE can share it.<\/p>\n<p>Microsoft stores YOUR WiFi passwords on THEIR server, encrypted.<\/p>\n<p>There is a way to opt out.\u00a0 All you have to do is change your SSID from whatever to whatever_optout.\u00a0 In the example above, NETWORK1_optout.<\/p>\n<p>&#8220;Opting out&#8221; doesn&#8217;t actually &#8220;opt out&#8221;, it signals Microsoft&#8217;s servers to remove your information which &#8220;might take a couple of days&#8221;, according to ARS Technica.<\/p>\n<p>&nbsp;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"arguments-for-and-against\"><\/span>Arguments For and Against<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"for-its-convenient\"><\/span>For:\u00a0 It&#8217;s convenient<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 You&#8217;re able to share known WiFi networks with <em>yourself<\/em> across multiple devices.\u00a0 So, if you have a Windows 8 phone that has already been connected to NETWORK1, now, your laptop can automatically connect without having to obtain the WiFi password again.<\/p>\n<p><strong><span style=\"text-decoration: underline;\">Response:<\/span><\/strong>\u00a0 Every platform, including older versions of Windows, supports &#8220;cached&#8221; WiFi passwords that are stored securely:\u00a0 They can&#8217;t be reversed, and the operating system prompts if the password is required for some reason.\u00a0 Bypassing this control allows unreasonable use of the WiFi password.\u00a0 YES, you could write it down.\u00a0 If you did that, it&#8217;s still kind of unethical:\u00a0 Whoever gave you the password trusts you not to share it, nor use it liberally.\u00a0 For example, I would consider it rude, if I gave someone my WiFi password, and they immediately connected all 20 devices that they own.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Bottom Line:<\/strong><\/span>\u00a0 Using someone&#8217;s WiFi network to connect multiple devices is an abuse of trust, unless you explicitly discuss it with them.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"for-sharing-with-your-outlook-contacts-is-no-different-than-telling-them-in-person\"><\/span>For:\u00a0 Sharing with your Outlook contacts is no different than telling them in person<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 Bob shares Alice&#8217;s WiFi network password with Fred.\u00a0 That&#8217;s no different than what happens with WiFi Sense.<\/p>\n<p><strong><span style=\"text-decoration: underline;\">Response:<\/span><\/strong>\u00a0 It&#8217;s a breach of trust, unless Bob discusses it with Alice up front.\u00a0 Alice gave Bob her password, expecting Bob to use it.\u00a0 Maybe Alice doesn&#8217;t even KNOW Fred.\u00a0 Why should she NOT be able to control Fred&#8217;s access?<\/p>\n<p><strong><span style=\"text-decoration: underline;\">Bottom Line:<\/span><\/strong>\u00a0 It&#8217;s a breach of trust to share someone&#8217;s network password with someone else, without their knowledge and consent.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"for-this-has-been-available-since-windows-phone-8\"><\/span>For:\u00a0 This has been available since Windows Phone 8<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 This feature has existed since Windows Phone 8 was released.\u00a0 No one complained about it then!<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span>\u00a0 No one bought a Windows Phone 8, and frankly, if more people knew about this feature then, they would have objected to it.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Bottom Line:<\/strong><\/span>\u00a0 Windows Phone 8 is NOT a legitimate precedent.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"for-if-you-object-you-can-always-opt-out\"><\/span>For:\u00a0 If you object, you can always opt-out!<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 You can rename your SSID to SSID_optout, to remove your information from Microsoft&#8217;s servers.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\"><em><strong>Emotional:<\/strong><\/em>\u00a0 Why should *I* have to make changes to accommodate some Microsoft standard?\u00a0 It&#8217;s MY WIFI, IN MY OWN HOUSE.\u00a0 I&#8217;m not changing ANYTHING, and if Microsoft stores my WiFi password on their server, I&#8217;ll simply sue them.<\/span><\/p>\n<p><em><strong>Logical:<\/strong><\/em>\u00a0 What if IBM requires me to rename my SSID to _noIBM tomorrow?\u00a0 Now what?\u00a0 Do I rename it to _optout_noIBM or _noIBM_optout?\u00a0 Oh&#8230; right&#8230;. Microsoft is the only operating system in existence.\u00a0 Yes, my IBM example is pretty feeble, but the point is valid:\u00a0 You can&#8217;t just *require* me to change my infrastructure, and update 30+ devices just to avoid Microsoft&#8217;s feeble attempt to unilaterally own the internet.<\/p>\n<p><em><strong>Factual:<\/strong><\/em>\u00a0 Renaming my SSID to SSID_optout doesn&#8217;t &#8220;opt me out&#8221;, it simply flags Microsoft&#8217;s servers to delete my SSID.\u00a0 Meaning, for whatever period of time it exists on Microsoft&#8217;s servers, *my security* is basically a free-for-all.<\/p>\n<p><em><strong>Burden of Configuration:<\/strong><\/em>\u00a0 If I rename my OWN SSID, then I have to reconfigure 30+ devices, just to &#8220;avoid&#8221; Microsoft.\u00a0 This leaves me with the &#8220;burden&#8221; of configuration.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Bottom Line:<\/strong><\/span>\u00a0 If I want to &#8220;avoid&#8221; Microsoft&#8217;s WiFi sense, I need to rename my SSID.\u00a0 This means reconfiguring 30+ devices, and there is the risk that some other standard will ALSO require some naming standard that conflicts.\u00a0 On an emotional level, my WiFi exists in MY HOUSE.\u00a0 This feels like Microsoft coming in to MY HOUSE, dictating MY NETWORK to me.\u00a0 All of this is unacceptable.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"for-its-cool\"><\/span>For:\u00a0 It&#8217;s Cool!<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 What a COOL feature!!\u00a0 People who don&#8217;t like this are just stifling progress.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span>\u00a0 It&#8217;s an unethical breach of trust, no matter how you slice it.<\/p>\n<p>People called the Windows 8 anti-start-button &#8220;progress&#8221;, but it wasn&#8217;t what the market demanded:\u00a0 The market demanded a &#8220;start&#8221; button.\u00a0 I think people demand security.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Bottom Line:<\/strong><\/span>\u00a0 It&#8217;s an unethical breach of trust, no matter how you slice it.\u00a0 It&#8217;s not what the market wants.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"for-corporate-networks-are-excluded\"><\/span>For:\u00a0 Corporate Networks are Excluded<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Argument:<\/strong><\/span>\u00a0 Networks that use enterprise authentication, such as 802.1x, requiring a user \/ device to authenticate itself, are excluded automatically.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span>\u00a0 This is biased against small business owners and home users who don&#8217;t have ready access to enterprise authentication, don&#8217;t have Access Points that use it, and don&#8217;t have the technical knowledge to implement it.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Bottom Line:<\/strong><\/span>\u00a0 If you switch your network to use enterprise authentication, WiFi Sense will ignore it.\u00a0 However, this is difficult, and possibly expensive.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"against-its-a-security-breach\"><\/span>Against:\u00a0 It&#8217;s a Security Breach<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span>\u00a0 Correct!\u00a0 It&#8217;s also an ethical breach.\u00a0 Sharing passwords is the #1 DO NOT do, of computer security.\u00a0 Yet Microsoft, despite touted &#8220;beyond password&#8221; security enhancements, seems to be OK with sharing passwords!\u00a0 Biometrics is known to be weak, and has some pretty serious side effects &#8212; you could lose a limb, a finger, or an eye if someone thinks that your body is the key to your access.\u00a0 BUT IT&#8217;S OK to steal your WiFi password.<\/p>\n<p>&nbsp;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"against-its-an-ethical-breach\"><\/span>Against:\u00a0 It&#8217;s an ethical breach<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><span style=\"text-decoration: underline;\"><strong>Response:<\/strong><\/span>\u00a0 This is the main argument against WiFi Sense.\u00a0 Because someone shares something with you, does not entitle you to share that secret item with someone else.<\/p>\n<p>&nbsp;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"why-i-feel-that-microsoft-has-crossed-the-line\"><\/span>Why I Feel that Microsoft has Crossed the Line<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>With Internet Explorer 8, Microsoft declared that it had been supporting &#8220;loose standards&#8221;, introduced by convention, but that didn&#8217;t apply to the HTML standards.\u00a0 In IE8, Microsoft introduced &#8220;compatibility mode&#8221; to deal with websites that didn&#8217;t &#8220;conform to HTML standards&#8221;.<\/p>\n<p>I have news for Microsoft:\u00a0 &#8220;Convention&#8221;\u00a0 = Standard<\/p>\n<p>In one fell swoop, Microsoft declared that it owned the internet, and that the internet was wrong.<\/p>\n<p>Microsoft continued to make a series of bone-headed blunders based on FOISTING a decision on the user community:<\/p>\n<ul>\n<li>Windows 8 had no start menu.\u00a0 The prophets of technology called this &#8220;innovation&#8221;.\u00a0 The market called this &#8220;crap&#8221;.\u00a0 The market won.<\/li>\n<li>XBox One.\u00a0 Originally, XBox One was going to charge for EACH USER to play a game&#8230; even if you live in the same house.\u00a0 Borrowed games would require a registration fee, and every &#8220;XBone&#8221; console would be required to check in each day, via the internet.\u00a0 &#8220;You have no internet&#8221;, Marie Antoinette said, &#8220;Then you should eat cake!&#8221;<br \/>\nONLY the competition from Sony Playstation reversed these absurd, unilateral decisions prior to launch.<\/li>\n<li>WiFi Sense.\u00a0 Microsoft Owns your Wifi.\u00a0 Just ask them!\u00a0 In retrospect, this will prove to be a horrible decision, but Microsoft doesn&#8217;t listen to the market, and doesn&#8217;t care.\u00a0 They want to &#8220;innovate&#8221; to the point that we bleed for it.<\/li>\n<\/ul>\n<p><strong><span style=\"text-decoration: underline;\">Your WiFi sits in your home<\/span><\/strong><\/p>\n<p>It&#8217;s personal.\u00a0 Why would Microsoft consider sharing something personal and trusted with someone YOU, personally, don&#8217;t know?<\/p>\n<p>They don&#8217;t care!<\/p>\n<p>This is clearly an ethical breach of trust, but Microsoft has rationalized it away, just like all of their other bad decisions.<\/p>\n<p><span style=\"color: #ff0000;\">My answer is simple:\u00a0 I use MAC filtering.\u00a0 I have two guest Wifis, one of which is called &#8220;AT&amp;T Sucks&#8221;.<\/span><\/p>\n<p><span style=\"color: #ff0000;\"><span style=\"text-decoration: underline;\"><strong>I&#8217;m renaming it tonight, to <\/strong><\/span><strong>&#8220;Microsoft Sucks_optout&#8221;<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\">&lt;drops the mic&gt;<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span class=\"ez-toc-section\" id=\"recommendations\"><\/span>Recommendations<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You know what?\u00a0 SCREW Microsoft and their crap.<\/p>\n<p>Here is what you need to do:<\/p>\n<ol>\n<li>Configure your &#8220;secure&#8221; WiFi network with MAC filtering.\u00a0 Despite what people say, your MAC address is only broadcast in an encrypted state.\u00a0 MAC FILTERING IS SECURE.\u00a0 Set up MAC Filtering to allow ONLY trusted devices on your &#8220;inner&#8221; WiFi network.<\/li>\n<li>Devices such as Netgear and Linksys (Cisco) allow a &#8220;guest&#8221; cleartext network.\u00a0 This takes the form of a web page, where you sign in with the guest ID, but the traffic is not encrypted.\u00a0 This seems to be the best approach to defeating Microsoft.<\/li>\n<li>Change your guest WiFi password every week.\u00a0 If you have devices that depend on your guest network, spend the measly $20 for a cheap AP, and configure the new AP as your guest AP.\u00a0 CHANGE IT EVERY WEEK.\u00a0 This gives you a trusted network, semi-trusted, and &#8220;true guest&#8221;.<\/li>\n<li>Don&#8217;t buy Microsoft Products.\u00a0 Buy a Chromebook, or a Mintbook, or a Debian Linuxbook.\u00a0 Don&#8217;t support a company that trades your secrets, as well as your ethics, so that they can make a buck.\u00a0 As stated previously, any company that fails to listen to its constituents isn&#8217;t in the market to serve its constituents:\u00a0 it&#8217;s in the market for profit, only.<\/li>\n<\/ol>\n<p>Do I hate Microsoft?\u00a0 No, I pity them.\u00a0<span style=\"color: #ff0000;\"> An asshole with a typewriter could design a far superior operating system.\u00a0 Oh, wait, that&#8217;s how we ended up with Linux!<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows 10 rolls out with a feature called &#8220;WiFi Sense&#8221;, the ability to cache WiFi passwords, and share them with your contacts. There are arguments in both directions, but I feel that Microsoft has crossed the line.\u00a0 Here is why&#8230;. &nbsp;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,4],"tags":[],"class_list":["post-2650","post","type-post","status-publish","format-standard","hentry","category-analyses-and-responses","category-rants"],"_links":{"self":[{"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/posts\/2650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/comments?post=2650"}],"version-history":[{"count":10,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/posts\/2650\/revisions"}],"predecessor-version":[{"id":2666,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/posts\/2650\/revisions\/2666"}],"wp:attachment":[{"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/media?parent=2650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/categories?post=2650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justinparrtech.com\/JustinParr-Tech\/wp-json\/wp\/v2\/tags?post=2650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}