Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

21–30 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#22
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I'm less concerned with the security issues - WiFi you don't control should always be treated as possibly being compromised. What is a problem is that the networks are password protected and not meant for use by the general public. Airline lounges are providing WiFi for customers who have paid for access (either through the type of ticket or by spending enough to have status to access the lounges). Depending on the l…

> What is a problem is that the networks are password protected and not meant for use by the general public.

I agree but wanted to point out that what you are saying is exactly what parent commenter is saying too.

Re: A Map of Wireless Passwords from Airports and Lounges

#23
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I'm less concerned with the security issues - WiFi you don't control should always be treated as possibly being compromised. What is a problem is that the networks are password protected and not meant for use by the general public. Airline lounges are providing WiFi for customers who have paid for access (either through the type of ticket or by spending enough to have status to access the lounges). Depending on the l…

It is controversial but there is something in publicly posting already compromised long-living static credentials.

I do not approve nor disapprove of this. It could be unethical, could be even illegal but still - it also may force to not rely on this security-through-obscurity approach and maybe actually start doing things right. Sadly, many people don't learn from theoretical implications - they just ignore those and don't implement any security. They only start reacting when their passwords are posted in the open.

E.g. if you want only paying customers to access your WiFi, generate unique passwords and print them on their receipts (or tickets or whatever) to look up.

Re: A Map of Wireless Passwords from Airports and Lounges

#24
post #14

Any wifi other than yours, or your company's is huge security risk. I would not trust a second for a service like this.

Would you care to elaborate what those risks are? The internet is rather bigger than the WiFi network you connect to.

Do I need to explain risks using foreign local networks in HN ? I see it quite unfair to get a downvote for this.

Re: A Map of Wireless Passwords from Airports and Lounges

#25
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I'm less concerned with the security issues - WiFi you don't control should always be treated as possibly being compromised. What is a problem is that the networks are password protected and not meant for use by the general public. Airline lounges are providing WiFi for customers who have paid for access (either through the type of ticket or by spending enough to have status to access the lounges). Depending on the l…

There's been an irritating trend of malware authors and other digital miscreants self-identifying as 'security researchers' lately.

If they just want to hack other people's shit, they should own up to the antipathy that comes with that. Instead they act like extorting companies over undisclosed vulnerabilities, emptying *coin exchange accounts, posting credential dumps on the internet or exfiltrating gigabytes of data are somehow noble or academic endeavors.

Re: A Map of Wireless Passwords from Airports and Lounges

#26
post #24

Earlier quoted context omitted.

Would you care to elaborate what those risks are? The internet is rather bigger than the WiFi network you connect to.

Do I need to explain risks using foreign local networks in HN ? I see it quite unfair to get a downvote for this.

Yes. Having a properly secured laptop on public wifi is no different than having a server on the public internet. It's not difficult to reason about the threat model here, and operating systems are fully capable of rejecting potentially harmful traffic.

Re: A Map of Wireless Passwords from Airports and Lounges

#27
post #17

Almost every item I see on here is using private WiFi connections intended for paying or premium customers, and precisely zero ones that are intended to be free. This would seem to constitute "piggybacking", which is of questionable legality in many places: https://en.wikipedia.org/wiki/Legality_of_piggybacking Given the dubious legality, seems odd to see this on HN.

No you got it wrong, WiFi is controlled by greedy monopolies and he’s just being disruptive ;)

This answer, with the due edits, would describe Uber and AirBnB pretty well, too. ;)

Re: A Map of Wireless Passwords from Airports and Lounges

#28
post #24

Earlier quoted context omitted.

Would you care to elaborate what those risks are? The internet is rather bigger than the WiFi network you connect to.

Do I need to explain risks using foreign local networks in HN ? I see it quite unfair to get a downvote for this.

[deleted]

Re: A Map of Wireless Passwords from Airports and Lounges

#29
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

If you don't want your semi-public (ie payed for) WPA2 key to be compromised, use 802.1x. Then you can use whatever you want for authentication, including time based tokens.

Re: A Map of Wireless Passwords from Airports and Lounges

#30
post #21

Is it possible to set up a trap where someone who inputs a leaked password will be automatically blocked or put on a naughty list? If you owned a coffeeshop, you would want your Wi-Fi users to be for customers only.

Wlan is usually not that strong to be reachable outside said coffeeshop. If you live near enough, you'll know the key anyway. (for the chance it does)
Post reply on HN