Live data from Hacker News

NeverSSL

neverssl.com

11–20 of 212 posts

Re: NeverSSL

#13
Not sure about Apple, but isn't this automatically handled by Android these days? Every time it connects to a network it pings http://google.com/generate_204 and if the response code isn't 204 then it should prompt you to open the browser to the redirected URL.

Re: NeverSSL

#15
It's sad, because these are the kinds of things that confuse the hell out of "common folk" and explaining requires explaining HTTPS, HSTS, how captive WiFi portals work, and then ultimately, why there isn't a better solution... which maybe doesn't have a great answer.

I feel like this "workaround" site is designed to draw attention to the problem at hand more than it is meant to be useful for the task at hand?

Re: NeverSSL

#16
post #6

Earlier quoted context omitted.

http://captive.apple.com/ also. That's what Apple devices use when trying to present the login for a captive network.

Is that better in any way than using example.com?

If I regularly used that as a known-good site that should be up with no SSL, I'd trust that an apple-maintained site (backed by akamai) would be up before "example.com".

I'm sure there are plenty of others, but someone might remember that URL over another so I thought it would be helpful.

Re: NeverSSL

#18
post #11

example.com works as well. it doesnt redirect to https://example.com

does it actually make an outbound connection or just a local page?

It makes an outbound connection. It's a real website, managed by the IANA (Internet Assigned Numbers Authority).

Re: NeverSSL

#19
post #15

It's sad, because these are the kinds of things that confuse the hell out of "common folk" and explaining requires explaining HTTPS, HSTS, how captive WiFi portals work, and then ultimately, why there isn't a better solution... which maybe doesn't have a great answer. I feel like this "workaround" site is designed to draw attention to the problem at hand more than it is meant to be useful for the task at hand?

I still think having people connect to something handed out by dhcp would be really great, that's what dhcp is for in the first place. If that's too complicated you could always try connecting to the gateway.

Re: NeverSSL

#20
post #15

It's sad, because these are the kinds of things that confuse the hell out of "common folk" and explaining requires explaining HTTPS, HSTS, how captive WiFi portals work, and then ultimately, why there isn't a better solution... which maybe doesn't have a great answer. I feel like this "workaround" site is designed to draw attention to the problem at hand more than it is meant to be useful for the task at hand?

> why there isn't a better solution...

There is a better solution: No captive portals.

Post reply on HN