Live data from Hacker News

Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

arnaucode.com

11–20 of 56 posts

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#12
post #6

I guess all it takes is one request to a non-https site?

Well, one persistently active tab with a non-https site open.

I suppose you could configure the rogue AP to have one of those registration pages but the registration page tells them the WiFi will only work so long as they keep that tab open.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#13
post #7

Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.

Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?

If you control the AP, you should disallow client to client communication. Most AP's and routers allow this and it would mitigate this risk.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#14
post #7

Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.

Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?

I think we will get it everywhere soon.

And no, that's not a solution. Well at least not everywhere. If the clients aren't completely isolated I can for example poison your DNS and redirect example.com to my computer's web server.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#15
post #2

I've thought about adding something like this to my guest wifi to mine some cryptocurrency - but quickly dismissed it as most guests would need to use a charger soon(ish) and thus using my electricity :P

It's also a scummy thing to do and sets a terrible precedent. Do you want friendly customers on your WiFi or do you want angry customers who feel cheated when they learn the truth?

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#16
post #13
post #7

Earlier quoted context omitted.

Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?

If you control the AP, you should disallow client to client communication. Most AP's and routers allow this and it would mitigate this risk.

Is there any way to mitigate this without limiting abilities of people on the network? It kind of destroys the point of a LAN.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#17

Earlier quoted context omitted.

New users are green, iirc 50 or 100 karma points required to get normal grey

Feels like they are more superior than us based on his color.

That's probably a cultural thing. In some cultures, red is superior to green.

Really, it's not about them being better or worse than a user with more Karna. It's just a signal to everyone that this person might be advertising or AstroTurfing.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#18
post #7

Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.

Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?

>is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?

AFAIK that wouldn't help because at the very least you can MITM the handshake.

Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

#19
post #2

I've thought about adding something like this to my guest wifi to mine some cryptocurrency - but quickly dismissed it as most guests would need to use a charger soon(ish) and thus using my electricity :P

It's also a scummy thing to do and sets a terrible precedent. Do you want friendly customers on your WiFi or do you want angry customers who feel cheated when they learn the truth?

I think it was basically a joke, and I think his "guests" are friends, not customers, and would therefore be likely to appreciate the joke even if he actually did it.
Post reply on HN