How do I hide my router's password? Windows 7 'Starter'__

Anonymous
2010-01-01T23:23:29+00:00

Hi,

We just got a Lenovo S10 Netbook with Win 7 'Starter' version for my daughter and I have a question about configuring the Wifi access.  This is my first exposure to Win 7, so I'll describe things as best I can.

I clicked on the "Internet Access" icon in the tray and up came the list of Wireless Network Connections.  I selected the one for our WPA-PSK encrypted router and cut and pasted my ~30 character 'Network Security Key' (passphrase/password) and, bingo, I was connected to the internet and websurfing just fine.

Here is my question.  How to I permenently hide my router's 'Network Security Key'? 

When I go back to the Wireless Network Connections and right click my router and select 'Properties" and go to the "Security" tab, there is a small check box labelled "Show Characters" that will toggle back and forth between a string of dots and the 'plain text' 'Network Security Key' for anyone to read.  I'm not willing to keep her set up to use our network if anyone with access to her Netbook can look up my router's WPA password. 

I have quite a few devices connected wirelessly to our network, but this is the only one where I can see the password in plain text.  The others only show a string of stars or dots to 'encrypt' the display of the password.

I will appreciate any help and so will the daughter that hopes to keep accessing the internet.

many thanks,  BDT

Windows for home | Previous Windows versions | Internet and connectivity

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2010-01-02T11:36:17+00:00

AFAIK you can't override that, although I could be wrong about that.

As far as others getting your wireless key from her netbook make sure your daughters account is astandard user account and that she does not have administrator permissions. That way if she tried to see the wireless security properties for your wireless network she can't unless she enters the administrator password. In the example screen shot if I am logged in as a standard user and try to check the Show characters checkbox UAC pops up and requests my administrative user password.

http://cid-25ab668da65c8fbe.skydrive.live.com/self.aspx/Windows%20images/Showcharacters.png

In all cases make sure the administrative user accounts are password protected with a strong password and access to those is severely restricted.

http://windows.microsoft.com/en-us/windows7/Why-use-a-standard-user-account-instead-of-an-administrator-account

FWIW I run as a standard user 99% of the time on my Windows 7 laptop. My wife runs as a standard user 100% of the time on her XP Pro desktop. When I setup my PCs I create an administrative user, ie. Root in my case, and the required number of standard users for each machine. All are password protected. Root is only used to install programs, change system stuff, security settings, etc...etc...etc...


MS-MVP Windows Desktop Experience, "When all else fails, read the instructions"

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

62 additional answers

Sort by: Newest
  1. Anonymous
    2010-01-04T16:41:18+00:00

    How?  Do you care other people connect directly to your internal network?  Knowing your WPA password is an invitation to your internal network --- and remotely! 

    Rubbish! Sorry, you are SO PARANOID it's unbeleivable. If all your Users are Standard users with strong passwords then the possibility of casual incursion is almost NIL!

    I'm not going to bother to argue with you any more. Goodbye and I hope you have a large stock of tinfoil hats.


    If you find my response helpful, please click on the "Vote as Helpful" button!Thank you! My Blog

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2010-01-04T16:29:37+00:00

    Yes, many routers show the WPA password and I can accept that because the router provides network connectivity to all devices (switch/PC) connecting to it (security boundary is all the subnets of the router).  If an user who has access to the router admin console or physical access to it.  You assume the same user is given full control over the particular portion of the network.  This is not the same for one particular PC.

    Al Jarvi,

    I agree with you that users need to take appropriate safe guards depending on their individual risk thresholds.  But what's the points to reveal the WPA password on a PC after it is saved?  If there is, why bother to masked it at the time of password entry?   If an user forget the WPA password, he/she should go to the router or ask the Network administrator.  This sounds like an OOPS in UI design to me.  If I am wrong, I welcome Microsoft or other Security and UI experts to step in to educate me.   To me, reveal the WPA password after it is saved is same as giving local administrator the power to see your Online Banking password on IE - a breach of security boundary.   I know local admin can install keyboard logger to steal the online banking password but that's another type of security issue.  

    Patch please... Microsoft.  We love Win7.

    As I noted earlier standard users can NOT see the encryption key after it has been configured on a particular PC. Users with administrator permissions can see the encryption key. That is the way it works on my Windows 7 Home Premium laptop. Is your PC or laptop different? This, at least to me, seems no different than some routers being able to display the encryption key in plain text after you login as the administrator.

    Now the problem seems to be that many folks are still running Windows 7 (or Vista and XP for that matter) using the old Windows Me/98/95/WFWG model of every user being able to do all things on a PC. The correct model is to make the majority of a machines users standard users, ie. your kids for example, and only certain individuals, ie. parents for example, administrators.

    That is all I have to say on the subject...

    Case closed...


    MS-MVP Windows Desktop Experience, "When all else fails, read the instructions"

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2010-01-04T16:02:41+00:00

    The security boundary of WPA password affects the entire network. 

    How?


    If you find my response helpful, please click on the "Vote as Helpful" button!Thank you! My Blog

    How?  Do you care other people connect directly to your internal network?  Knowing your WPA password is an invitation to your internal network --- and remotely! 

    Yes, many routers show the WPA password and I can accept that because the router provides network connectivity to all devices (switch/PC) connecting to it (security boundary is all the subnets of the router).  If an user who has access to the router admin console or physical access to it.  You assume the same user is given full control over the particular portion of the network.  This is not the same for one particular PC.

    Al Jarvi,

    I agree with you that users need to take appropriate safe guards depending on their individual risk thresholds.  But what's the points to reveal the WPA password on a PC after it is saved?  If there is, why bother to masked it at the time of password entry?   If an user forget the WPA password, he/she should go to the router or ask the Network administrator.  This sounds like an OOPS in UI design to me.  If I am wrong, I welcome Microsoft or other Security and UI experts to step in to educate me.   To me, reveal the WPA password after it is saved is same as giving local administrator the power to see your Online Banking password on IE - a breach of security boundary.   I know local admin can install keyboard logger to steal the online banking password but that's another type of security issue.  

    Patch please... Microsoft.  We love Win7.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2010-01-04T11:36:58+00:00

    BDT, I have the same issue.  Wish Microsoft will fixed this issue with a patch.  What's the purpose to reveal a password after it is saved?  There is a reason why character is masked into "*" in any password prompt.  It is a good idea to give user the ability to "unmask" because some WPA password is tedious to enter, but this option should only available during initial password setup.  This goes against the intention of password field in most GUI design. 

    The security boundary of WPA password affects the entire network.  The security boundary of local admin password affects only one PC.  The fact that there are 3rd party tool to reveal the WPA password in XP show another security issue in XP WZC and/or WPA design.  Fortunately most business networks use WPA-Enterprise instead of PSK.

    Keep in mind that some consumer grade wireless access point/router devices also display the wireless encryption key in plain text or have an option to do so. Also as I noted earlier if you use WCN, and I do, the encryption key is also stored in plain text in the \Smrtntky\Wsetting.txt file on the flash drive. This is a convenience for users that have wireless clients that can not use WCN automatically, ie. a Linux client for example.

    As with any security scheme users simply need to take appropriate safe guards dependent on their individual risk thresholds. Security best practices and common sense should be the watch words...


    MS-MVP Windows Desktop Experience, "When all else fails, read the instructions"

    Was this answer helpful?

    0 comments No comments