Live data from Hacker News

NeverSSL

neverssl.com

81–90 of 212 posts

Re: NeverSSL

#81
post #66

Earlier quoted context omitted.

What would you suggest if someone wants payment for a water tab? Ever seen that? I think we should move towards considering Internet access as a general service that people make available for their guests/customers.

How do you see this scaling? Do you think hotels and restaurants can deliver reliable internet without charging for it? Is it reasonable to assume that companies that don't charge for wifi can afford the staff to make sure that users don't abuse it? I am considering your proposal & I don't see it working at all.

> Do you think hotels and restaurants can deliver reliable [[tap water]] without charging for it?

> Is it reasonable to assume that companies that don't charge for [[tap water]] can afford the staff to make sure that users don't abuse it?

Sorry to post the snarky response, but with internet access, as with all shared goods like access to water or noise in a semi-shared space such as a hotel, yes, I do expect they can handle it and not have it be a big deal.

Re: NeverSSL

#82
I've always just used asdf.com, but I suppose there's always the risk it might switch over to HTTPS; might switch to this instead.

Re: NeverSSL

#83
post #48

Earlier quoted context omitted.

What would you suggest for the case of someone wanting payment for the connection? Like it or not, a lot of places do that.

WPA/WPA2 Enterprise supports a multi user environment. You can require a unique login per user and thus associate payment with that. It also alleviates the problem with mac address whitelisting.

Then people either have to pay offline or you need to set up a different unencrypted network with a captive portal to facilitate payment.

Re: NeverSSL

#84
post #66

Earlier quoted context omitted.

What would you suggest if someone wants payment for a water tab? Ever seen that? I think we should move towards considering Internet access as a general service that people make available for their guests/customers.

How do you see this scaling? Do you think hotels and restaurants can deliver reliable internet without charging for it? Is it reasonable to assume that companies that don't charge for wifi can afford the staff to make sure that users don't abuse it? I am considering your proposal & I don't see it working at all.

> Do you think hotels and restaurants can deliver reliable internet without charging for it?

Yes. Because most already do.

Re: NeverSSL

#85
I might just be really stupid but I read the "what" and the "how" a couple of times and I still don't understand. I only inferred from the comments that this is to get through captive portals used in coffee shops by exploiting the fact that they have to to permit HTTP unauthenticated in order for the redirect to the login page to work.

But can someone walk me through how never SSL allows me to connect to FB once my browser loads their default page? I feel like I am missing something which is maybe obvious?

Re: NeverSSL

#86
post #20

Earlier quoted context omitted.

> why there isn't a better solution... There is a better solution: No captive portals.

What would you suggest for the case of someone wanting payment for the connection? Like it or not, a lot of places do that.

Honestly? It's 2017. Just throttle bandwidth and give your internet away for free.

There are some obvious cases in which this is unacceptable, but they are few and far between. The overwhelming majority of captive portals I see are just trying to get your contact info... so now you have two reasons why they should disappear.

Re: NeverSSL

#87
post #66

Earlier quoted context omitted.

What would you suggest if someone wants payment for a water tab? Ever seen that? I think we should move towards considering Internet access as a general service that people make available for their guests/customers.

How do you see this scaling? Do you think hotels and restaurants can deliver reliable internet without charging for it? Is it reasonable to assume that companies that don't charge for wifi can afford the staff to make sure that users don't abuse it? I am considering your proposal & I don't see it working at all.

I wonder why this seems so intractable in some countries. In others, such as Indonesia or Vietnam or Taiwan, WiFi really is free in most establishments and nobody seems to have a problem with customers abusing it. Even a $10 hotel has WiFi. Versus say London where a $300 hotel charges $25 for WiFi. In many places nobody would ever expect to pay one cent for WiFi in a place where they are already a paying customer unless it's an Internet cafe.

Re: NeverSSL

#88
post #20

Earlier quoted context omitted.

> why there isn't a better solution... There is a better solution: No captive portals.

What would you suggest for the case of someone wanting payment for the connection? Like it or not, a lot of places do that.

802.11 standard could come up with some kind of captive portal standard.

Re: NeverSSL

#89
post #79
post #68

Earlier quoted context omitted.

Do you travel? I often have problems and am running out of non-https sites to test against. Best I can figure is that they're whitelisting certain domains so the captive portal detection isn't triggered. I think this is so certain things like iMessage or email work (hence, whitelisting apple.com), but blocking out the rest of the web. I don't travel often (Christmas and maybe once or twice a year outside of that), bu…

Apple uses a large amount of domains to avoid this problem.

Really? My point was, I have no specific idea why, but I /constantly/ have problems. My solution is to go to a non-https website in Safari and use the clickthrough. It seems to be on certain networks (not just a % of the time on all networks).

The experience has gotten a lot better. I see Apple's pop up covering a lot more corner cases, but after years I see have problems almost every time I travel.

Re: NeverSSL

#90
post #69
post #6

Earlier quoted context omitted.

http://captive.apple.com/ also. That's what Apple devices use when trying to present the login for a captive network.

My iPhone constantly misses captive portals and I have to hunt for a non-ssl website. I can't say if it's 5% or 30% of networks, but enough to be frustrating. Does anyone know if it is common for apple.com to be whitelisted for iMessage or something?

The captive portal browser (pop-up on macOS, slide-over on iOS) doesn't support full JavaScript or cookies (or previously didn't, maybe that has changed), so some captive portals specifically allow the captive portal test domains through.

There's actually a huge list of domains that macOS/iOS try: http://stackoverflow.com/questions/18891706/ios7-and-captive...

Post reply on HN