How do I hide my router's password? Windows 7 'Starter'__

Anonymous
2010-01-01T23:23:29+00:00

Hi,

We just got a Lenovo S10 Netbook with Win 7 'Starter' version for my daughter and I have a question about configuring the Wifi access.  This is my first exposure to Win 7, so I'll describe things as best I can.

I clicked on the "Internet Access" icon in the tray and up came the list of Wireless Network Connections.  I selected the one for our WPA-PSK encrypted router and cut and pasted my ~30 character 'Network Security Key' (passphrase/password) and, bingo, I was connected to the internet and websurfing just fine.

Here is my question.  How to I permenently hide my router's 'Network Security Key'? 

When I go back to the Wireless Network Connections and right click my router and select 'Properties" and go to the "Security" tab, there is a small check box labelled "Show Characters" that will toggle back and forth between a string of dots and the 'plain text' 'Network Security Key' for anyone to read.  I'm not willing to keep her set up to use our network if anyone with access to her Netbook can look up my router's WPA password. 

I have quite a few devices connected wirelessly to our network, but this is the only one where I can see the password in plain text.  The others only show a string of stars or dots to 'encrypt' the display of the password.

I will appreciate any help and so will the daughter that hopes to keep accessing the internet.

many thanks,  BDT

Windows for home | Previous Windows versions | Internet and connectivity

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2010-01-02T11:36:17+00:00

AFAIK you can't override that, although I could be wrong about that.

As far as others getting your wireless key from her netbook make sure your daughters account is astandard user account and that she does not have administrator permissions. That way if she tried to see the wireless security properties for your wireless network she can't unless she enters the administrator password. In the example screen shot if I am logged in as a standard user and try to check the Show characters checkbox UAC pops up and requests my administrative user password.

http://cid-25ab668da65c8fbe.skydrive.live.com/self.aspx/Windows%20images/Showcharacters.png

In all cases make sure the administrative user accounts are password protected with a strong password and access to those is severely restricted.

http://windows.microsoft.com/en-us/windows7/Why-use-a-standard-user-account-instead-of-an-administrator-account

FWIW I run as a standard user 99% of the time on my Windows 7 laptop. My wife runs as a standard user 100% of the time on her XP Pro desktop. When I setup my PCs I create an administrative user, ie. Root in my case, and the required number of standard users for each machine. All are password protected. Root is only used to install programs, change system stuff, security settings, etc...etc...etc...


MS-MVP Windows Desktop Experience, "When all else fails, read the instructions"

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

62 additional answers

Sort by: Most helpful
  1. Anonymous
    2010-01-09T23:46:34+00:00

    I appreciate everybody's comments and it looks like the answer is that Windows 7 can't/won't do what I want it to do. 

    Checking with a utility called wirelesskeyview, I found that Windows XP does store the wifi password in hex format (which is 64 characters or 32 pairs), but it does not store the passphrasein clear text (at least not in the registery).  Since the passphrase is entered as the wifi password to connect, having the hex password doesn't grant easy/immediate access to the wifi network.  While XP isn't perfect, it offers some additional security compared to Win 7.

    Hopefully, one day soon, Microsoft will plug this security weakness.  Paranoid or not, any OS should give the user as much security as he/she chooses to apply and Win 7 is a step backwards regarding this issue.

    thanks again,  BDT

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2010-01-04T23:59:40+00:00

    Al Jarvi, as a MVP, I thought you would have better understanding.  I already stated that the problem is "local admin". 

    While I appreciated Microsoft finally learn that not everyone need to run as administrator since Vista [although the UAC design and security model was pretty bad and broke a lot of applications, it is better with Win7 but still have lots of room to improve.], I do have other consultants, guests need to connect to my network in an adhoc basis, and many of them are running local admin.  It seems no body bother to answer directly to my question.  What's the points to give local admin the ability to unmask WPA password?  If there is a good reason, why it was masked at the beginning?   Because of Win7, I have to purchase a router with multiple SSID and VLAN, but it will be a lot nicer if the "new feature" can be fixed with a patch.  Or at least give us an option as Shawn suggested. 

    Even for my kids, I am tired to install every single application they like to try (or type in the admin credential).  Restricted user can't even install Adobe Flash for Youtube!!!  They can run as restricted users but they still need an admin password or I will have to babysit them all the time.

    Gordon, it's unbelievable.  Why don't you put your PC on DMZ?  I bet you have a lot less firewall issue to deal with, although you may have zero day vulnerability issue. 

    I do care other people connect directly to my internal network.  I will be shocked Al Jarvi agree with you about this.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2010-01-04T16:41:18+00:00

    How?  Do you care other people connect directly to your internal network?  Knowing your WPA password is an invitation to your internal network --- and remotely! 

    Rubbish! Sorry, you are SO PARANOID it's unbeleivable. If all your Users are Standard users with strong passwords then the possibility of casual incursion is almost NIL!

    I'm not going to bother to argue with you any more. Goodbye and I hope you have a large stock of tinfoil hats.


    If you find my response helpful, please click on the "Vote as Helpful" button!Thank you! My Blog

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2010-01-04T16:29:37+00:00

    Yes, many routers show the WPA password and I can accept that because the router provides network connectivity to all devices (switch/PC) connecting to it (security boundary is all the subnets of the router).  If an user who has access to the router admin console or physical access to it.  You assume the same user is given full control over the particular portion of the network.  This is not the same for one particular PC.

    Al Jarvi,

    I agree with you that users need to take appropriate safe guards depending on their individual risk thresholds.  But what's the points to reveal the WPA password on a PC after it is saved?  If there is, why bother to masked it at the time of password entry?   If an user forget the WPA password, he/she should go to the router or ask the Network administrator.  This sounds like an OOPS in UI design to me.  If I am wrong, I welcome Microsoft or other Security and UI experts to step in to educate me.   To me, reveal the WPA password after it is saved is same as giving local administrator the power to see your Online Banking password on IE - a breach of security boundary.   I know local admin can install keyboard logger to steal the online banking password but that's another type of security issue.  

    Patch please... Microsoft.  We love Win7.

    As I noted earlier standard users can NOT see the encryption key after it has been configured on a particular PC. Users with administrator permissions can see the encryption key. That is the way it works on my Windows 7 Home Premium laptop. Is your PC or laptop different? This, at least to me, seems no different than some routers being able to display the encryption key in plain text after you login as the administrator.

    Now the problem seems to be that many folks are still running Windows 7 (or Vista and XP for that matter) using the old Windows Me/98/95/WFWG model of every user being able to do all things on a PC. The correct model is to make the majority of a machines users standard users, ie. your kids for example, and only certain individuals, ie. parents for example, administrators.

    That is all I have to say on the subject...

    Case closed...


    MS-MVP Windows Desktop Experience, "When all else fails, read the instructions"

    Was this answer helpful?

    0 comments No comments