New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 903908 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

Hidden SSIDs

Project Member Reported by tna...@google.com, Nov 9

Issue description

Understand how hidden SSIDs work in Chrome OS. Are they broadcasted? If yes, we probably should change something, either stop broadcasting or at least show a scary warning to users.

Reference: https://apple.stackexchange.com/questions/244171/ios-10-warning-using-a-hidden-network-can-expose-personally-identifiable-inform
 
Owner: glevin@chromium.org
Status: Assigned (was: Untriaged)
Greg, this is a bit of an unusual review as it might require us to find a feature team to work on it. Do you know a 20%er who might be interested in working on it? Or is that task better suited for a 100%er?
Owner: ----
Status: Available (was: Assigned)
Cc: benchan@chromium.org
Components: OS>Systems>Network
I just tested this:
1. Create a hidden SSID
2. Connect Chromebook to hidden SSID
3. Disable and re-enable wifi on Chromebook
--> Chromebook auto-connects to hidden SSID

Afaiu this is only possibly by broadcasting the hidden SSID.

I can see the following options for moving forward:
a) disable auto-connecting to hidden SSIDs (with enterprise policy to add it back)
b) show a scary warning when auto-connecting to hidden SSIDs is enabled:
b1) allow users to choose whether they would like to auto-connect as part of the "Join other ..." flow and show a warning both in "Join other" and Settings when auto-connecting is enabled
b2) disable auto-connecting by default and allow users to opt into auto-connecting from Settings and show the the warning only there
Cc: steve...@chromium.org
Labels: Hotlist-Privacy-Followup
Steven, do you have thoughts about what would be the best UI here? I assume a) is infeasible because sometimes users just don't have control of the wifi setup and they need to work with what's available?
Cc: derat@chromium.org kirtika@chromium.org
This should probably have a better description.

+derat@ and kirtika@ who may have a better informed opinion here.

b1) seems reasonable to me. Requiring a separate step to enable auto connect seems pretty high friction, and forbidding it entirely for non enterprise users seems pretty extreme (and would likely impact a lot of users).

As noted, this will require UX input and a feature effort.



I don't know anything about this beyond what's written here (and in the linked documents), but b1) sounds reasonable to me too.
Labels: Enterprise-Triaged

Comment 9 by tnagel@chromium.org, Today (14 hours ago)

Cc: jessejames@chromium.org
Owner: mgalonsky@chromium.org
Status: Assigned (was: Available)
It seems that we have consensus on the changes [1] that we should make. Assigning to Melissa for the actual implementation.

[1] https://docs.google.com/document/d/1aDZHyDlaGPYZhVS7jO61TscTyC9n19_mF295fsrz4rY/edit

Sign in to add a comment