Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

41–50 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#41
post #35
post #32

Earlier quoted context omitted.

If you wanted your Wi-Fi to be for customers only then you'd use WPA2 Enterprise with unique per-user passwords, or at least change the static password every day.

You might want your WiFi to be for customers only, but not have any idea how or enough money to enforce it.

I might want a million dollars but have no idea how to earn it nor enough power to force everyone to give me their money.

Now give me my million dollars!

Let’s be real. You can’t have your cake and eat it too.

Re: A Map of Wireless Passwords from Airports and Lounges

#42
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

Re: A Map of Wireless Passwords from Airports and Lounges

#43
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I think this is a red herring. Not using encryption is unacceptable. Sharing public information is not unethical.

Re: A Map of Wireless Passwords from Airports and Lounges

#44
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

At that point it is public information, and sharing it more widely is just journalism or publishing.

Re: A Map of Wireless Passwords from Airports and Lounges

#45
post #2

Sites and tools like this simply encourage lounge operators, vendors and airports to add captive portals or SMS verification and make getting access to wifi harder.

I don’t think these sorts of lists are in widespread enough use to affect the AP operators one bit. This is just handwringing.

Re: A Map of Wireless Passwords from Airports and Lounges

#46
post #44

Earlier quoted context omitted.

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

At that point it is public information, and sharing it more widely is just journalism or publishing.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries.

As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs around the airport you won’t figure it out. Some handy guide that has URL, ID of the WiFi and password is super helpful in situations like this.

Re: A Map of Wireless Passwords from Airports and Lounges

#47
post #44

Earlier quoted context omitted.

At that point it is public information, and sharing it more widely is just journalism or publishing.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries. As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs aro…

Typing 1.1.1.1 or any other IP address usually helps, it automatically redirects to the main login page. If you type a name, your DNS query fails.

Re: A Map of Wireless Passwords from Airports and Lounges

#48

Earlier quoted context omitted.

I might want a pet unicorn too, then what? Changing the password everyday is an acceptable compromise.

The password was changing everyday where I worked, with the daily password available on an intranet page, but then a few months ago a bunch of higher-ups were present in the office for a few days and wanted Wi-Fi access without having to type a new password each day, so the password rotation has been deactivated since

Well they chose convenience over security, which in this case is fair enough (it's public Wi-Fi to being with).

Another solution would've been to implement WPA2 Enterprise, where employees could have their own, permanent credentials while visitors get temporary ones.

Re: A Map of Wireless Passwords from Airports and Lounges

#49

Is there an android solution to automate registering and accepting T&Cs for free wifi? The log in process and unreliable connection make them barely worth using.

Try neverssl.com

That's just a static HTTP site, built in the hope that it will get redirected to a captive portal. It doesn't help with the captive portal authentication in any way.

Re: A Map of Wireless Passwords from Airports and Lounges

#50

Earlier quoted context omitted.

I'm less concerned with the security issues - WiFi you don't control should always be treated as possibly being compromised. What is a problem is that the networks are password protected and not meant for use by the general public. Airline lounges are providing WiFi for customers who have paid for access (either through the type of ticket or by spending enough to have status to access the lounges). Depending on the l…

It is controversial but there is something in publicly posting already compromised long-living static credentials. I do not approve nor disapprove of this. It could be unethical, could be even illegal but still - it also may force to not rely on this security-through-obscurity approach and maybe actually start doing things right. Sadly, many people don't learn from theoretical implications - they just ignore those an…

[deleted]
Post reply on HN