Live data from Hacker News

Ask HN: Dangers of Unsecured WiFi?

news.ycombinator.com

31–40 of 42 posts

Re: Ask HN: Dangers of Unsecured WiFi?

#31
post #29

Earlier quoted context omitted.

Haha thats terrifying! I was just trying to point out that assuming that apps do this correctly is a bad idea; but my experience echoes yours, its a common mistake - even just browsing stack overflow people give some pretty gnarly advice. Unless I’ve looked at the app myself i wouldnt touch public wifi - even then there are other risks to consider

Would you do it with a VPN? (I would, just checking)

A vpn (that you trust) would certainly help a little, but in the above case the connection can still be mitmed from the vpn server to the application backend

Edit: I would for my personal devices, unless I knew the app did something horrendous in advance- but I guess the core problem is you really have no way of knowing unless you check the app yourself or there is a known and reported vulnerability.

Re: Ask HN: Dangers of Unsecured WiFi?

#32
post #29

Earlier quoted context omitted.

Haha thats terrifying! I was just trying to point out that assuming that apps do this correctly is a bad idea; but my experience echoes yours, its a common mistake - even just browsing stack overflow people give some pretty gnarly advice. Unless I’ve looked at the app myself i wouldnt touch public wifi - even then there are other risks to consider

Would you do it with a VPN? (I would, just checking)

I wouldn't, especially not having looked at the VPN at first. It might expose you to even more attackers than could fit in your Starbucks

Re: Ask HN: Dangers of Unsecured WiFi?

#33

Your question is meaningless and context-free. The only difference with "unsecured WiFi" is its lack of key and encryption. You've said nothing about who provided that WiFi service, where it was, or anything. Plenty of reputable and well-managed WiFi networks are unsecured these days. Even my ISP runs them; they're perfectly safe. I don't use a VPN. We're not your tech support department, and it's impossible for us t…

"You're wrong, but I don't feel like teaching. Just feeling smug about my supposed superiority."

I have negative feelings towards this sort of long winded holier than thou garbage.

And it's a documented self inflicted "why does nobody want to contribute to $project?" By burned out devs.

Re: Ask HN: Dangers of Unsecured WiFi?

#34
post #29

Earlier quoted context omitted.

Would you do it with a VPN? (I would, just checking)

I wouldn't, especially not having looked at the VPN at first. It might expose you to even more attackers than could fit in your Starbucks

VPNs have a bad reputation, but I trust Mullvad (have used and paid them often), and Proton (currently paying them).

Re: Ask HN: Dangers of Unsecured WiFi?

#35
post #27

BTW always wondered... often docs show that a wifi with a password uses encryption, and wifi without password are not encrypted, I'm wondering why that is? Is it for backward compatibility with old devices? Why isn't the standard that when connecting to a wifi without password, everything would be just like if there was a (fake) "public password" like the string "password", so that traffic is still encrypted?

WPA3 offers secure-open and unique+forward key secrecy. WPA2 is twenty years old.

Re: Ask HN: Dangers of Unsecured WiFi?

#36
post #34

Earlier quoted context omitted.

I wouldn't, especially not having looked at the VPN at first. It might expose you to even more attackers than could fit in your Starbucks

VPNs have a bad reputation, but I trust Mullvad (have used and paid them often), and Proton (currently paying them).

I trust Mullvad more than others, because IIRC they were one of the few that actually had RAM only infrastructure when they were audited

Re: Ask HN: Dangers of Unsecured WiFi?

#37

Your question is meaningless and context-free. The only difference with "unsecured WiFi" is its lack of key and encryption. You've said nothing about who provided that WiFi service, where it was, or anything. Plenty of reputable and well-managed WiFi networks are unsecured these days. Even my ISP runs them; they're perfectly safe. I don't use a VPN. We're not your tech support department, and it's impossible for us t…

"You're wrong, but I don't feel like teaching. Just feeling smug about my supposed superiority." I have negative feelings towards this sort of long winded holier than thou garbage. And it's a documented self inflicted "why does nobody want to contribute to $project?" By burned out devs.

Perhaps I could be less condescending, but is it not teaching, and constructive feedback, to warn this poster that it's impossible to diagnose without much more context, rather than engaging in wild speculation like other commenters? It would seem that they're the harmful ones. And I did suggest several avenues for superior support, rather than trying to tackle it all alone.

Re: Ask HN: Dangers of Unsecured WiFi?

#38
post #27

BTW always wondered... often docs show that a wifi with a password uses encryption, and wifi without password are not encrypted, I'm wondering why that is? Is it for backward compatibility with old devices? Why isn't the standard that when connecting to a wifi without password, everything would be just like if there was a (fake) "public password" like the string "password", so that traffic is still encrypted?

WPA3 offers secure-open and unique+forward key secrecy. WPA2 is twenty years old.

Not sure how this addresses my question? Or is the issue with "not encrypted when there is no password" only a WPA2 issue?

Re: Ask HN: Dangers of Unsecured WiFi?

#39
post #27

BTW always wondered... often docs show that a wifi with a password uses encryption, and wifi without password are not encrypted, I'm wondering why that is? Is it for backward compatibility with old devices? Why isn't the standard that when connecting to a wifi without password, everything would be just like if there was a (fake) "public password" like the string "password", so that traffic is still encrypted?

When you connect to a WiFi network, the goal is to be part of the network. Which means that all the devices on the network can reach each other.

If you have a password, it means that you select who can be part of that network (and hence who can reach your computer). If you don't have a password (e.g. a guest network somewhere), then there is no selection at all.

Now, if you let anyone connect and have a "fake" password, you still don't have any filter and should know that you are on a "public" network (i.e. you should not blindly trust other devices). So it's actually better to be able to see that you are on a "public" network (versus a "trusted" network like your home LAN).

Or did I misunderstand your question?

Re: Ask HN: Dangers of Unsecured WiFi?

#40

Your question is meaningless and context-free. The only difference with "unsecured WiFi" is its lack of key and encryption. You've said nothing about who provided that WiFi service, where it was, or anything. Plenty of reputable and well-managed WiFi networks are unsecured these days. Even my ISP runs them; they're perfectly safe. I don't use a VPN. We're not your tech support department, and it's impossible for us t…

What a weird reply to a call for advice. 'your machine got messed up somehow'. They now that, provide some recovery tips instead of downplaying.
Post reply on HN