Live data from Hacker News

NeverSSL

neverssl.com

181–190 of 212 posts

Re: NeverSSL

#181

Earlier quoted context omitted.

Android detects wifi with captive portals automatically and pops-up a notification that says "Wifi network requires sign-in". Clicking on that takes you to non-HTTPS page in a browser that is intended to be intercepted. There is no reason why Apple can't add captive portal detection at OS level like Android does.

As the OP said, that is already in iOS - it is just that more and more captive portals are whitelisting the domains it hits to check for a captive portal.

> captive portals are whitelisting the domains it hits to check for a captive portal.

Why?

Re: NeverSSL

#185
post #20

Earlier quoted context omitted.

> why there isn't a better solution... There is a better solution: No captive portals.

My real plan with NeverSSL.com is to use the access logs to publish an up-to-date database of broken networks and what the rough popularity of each broken network is. I'm hopeful that these kinds of public analytics could lead to solutions, or at least who to start talking to.

Keep in mind that you'll also get hits from users with devices that completely lack automatic captive portal detection.

Re: NeverSSL

#186

Earlier quoted context omitted.

Windows does the same thing, at least in 10. I get a notification that further action is required and clicking it opens a no-SSL Microsoft URL that Will redirect.

It's go.microsoft.com. I Think you can be pretty sure that will forever be without https as well since it is hardcoded into several Windows versions

I believe it's http://www.msftncsi.com/

Re: NeverSSL

#187
post #6

example.com works as well. it doesnt redirect to https://example.com

http://captive.apple.com/ also. That's what Apple devices use when trying to present the login for a captive network.

I think I saw my Android phone use http://gstatic.com/generate_204, though more recent phones might use something different.

Re: NeverSSL

#189
post #181

Earlier quoted context omitted.

As the OP said, that is already in iOS - it is just that more and more captive portals are whitelisting the domains it hits to check for a captive portal.

> captive portals are whitelisting the domains it hits to check for a captive portal. Why?

As the OP said,

> ...so iOS will think it is connected to a good network... The stated reason for this stupidity? The mini-browser that pops up doesn't work with their stupid captive portal login or payment page.

Post reply on HN