Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

51–60 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#51
post #34

Sharing a wi-fi password with the world is a bit like sharing a party invitation with the world. To use this you have to stand outside a restaurant / lounge and hope to acquire the weak signal (and hope the password hasn't changed). Why not just buy a coffee and you get to sit down and a have better signal.

Pretty much a case of "this is why we can't have nice things."

Everything becomes a bit more inconvenient for everyone if every establishment has to protect against this kind of thing.

Re: A Map of Wireless Passwords from Airports and Lounges

#52
post #32
post #21

Is it possible to set up a trap where someone who inputs a leaked password will be automatically blocked or put on a naughty list? If you owned a coffeeshop, you would want your Wi-Fi users to be for customers only.

If you wanted your Wi-Fi to be for customers only then you'd use WPA2 Enterprise with unique per-user passwords, or at least change the static password every day.

Well, if I was a cafe owner worried about non-customers going nefarious things I would not be happy until IBM deploy a decentralised blockchain solution that anyone with a HTC phone hardware wallet can seamlessly sign in to with the task only taking thirty minutes or so.

Or maybe make it as easy as possible, never changing the password and thereby getting repeat trade. I am sure a firewall can be opted into with the ISP to make sure nobody is downloading ISIS kiddie porn, Trump tweets etc.

Re: A Map of Wireless Passwords from Airports and Lounges

#53
post #45
post #2

Sites and tools like this simply encourage lounge operators, vendors and airports to add captive portals or SMS verification and make getting access to wifi harder.

I don’t think these sorts of lists are in widespread enough use to affect the AP operators one bit. This is just handwringing.

That you can abuse something only because other people don't is pretty weak justification.

Re: A Map of Wireless Passwords from Airports and Lounges

#54
post #44

Earlier quoted context omitted.

At that point it is public information, and sharing it more widely is just journalism or publishing.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries. As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs aro…

Sometimes the resason that you don't get redirected to the wifi network's captive portal is that your browser is trying to access a page using HTTPS. Trying to connect to a HTTP-only site (like http://neverssl.com/) can solve this.

Re: A Map of Wireless Passwords from Airports and Lounges

#55
post #43
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I think this is a red herring. Not using encryption is unacceptable. Sharing public information is not unethical.

Not using encryption to hide your public service is perfectly acceptable. If you come to my house, you can access my wifi network. No password needed. It's my gift to you.

This information is not public. It is a set of shared secrets. And now it has been shared to everyone in the world, rather than those who the owners wanted it to be shared with.

Re: A Map of Wireless Passwords from Airports and Lounges

#56
post #44

Earlier quoted context omitted.

At that point it is public information, and sharing it more widely is just journalism or publishing.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries. As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs aro…

> I would find something like this to be helpful

I would find a scheme where I am simply allowed to help myself to any goods or services I wish to consume, for free and without permission, helpful, too.

Re: A Map of Wireless Passwords from Airports and Lounges

#57
post #43
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

I think this is a red herring. Not using encryption is unacceptable. Sharing public information is not unethical.

What's the red herring here?

Re: A Map of Wireless Passwords from Airports and Lounges

#58
post #35
post #32

Earlier quoted context omitted.

If you wanted your Wi-Fi to be for customers only then you'd use WPA2 Enterprise with unique per-user passwords, or at least change the static password every day.

You might want your WiFi to be for customers only, but not have any idea how or enough money to enforce it.

Then you probably won't know enough to setup that trap.

Re: A Map of Wireless Passwords from Airports and Lounges

#59

Earlier quoted context omitted.

What's the name of it?

https://f-droid.org/en/packages/com.juliansparber.captivepor... "It works by simply replacing the action URL from the login form on the web page to a local HTTP server which redirects the request to the original destination. The local HTTP server saves the request, so the app can reproduce the same call next time you connect to the same WiFi network." Uhh... Time to move to iOS, I think.

Why would you move to iOS over that?

Re: A Map of Wireless Passwords from Airports and Lounges

#60

Earlier quoted context omitted.

https://f-droid.org/en/packages/com.juliansparber.captivepor... "It works by simply replacing the action URL from the login form on the web page to a local HTTP server which redirects the request to the original destination. The local HTTP server saves the request, so the app can reproduce the same call next time you connect to the same WiFi network." Uhh... Time to move to iOS, I think.

Why would you move to iOS over that?

Without a rooted phone, there's no better way to "fix" Android's captive portal code, or to automate it.
Post reply on HN