Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

61–70 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#61

Earlier quoted context omitted.

Why would you move to iOS over that?

Without a rooted phone, there's no better way to "fix" Android's captive portal code, or to automate it.

How would root or iOS help you? The problem is that each captive portal is different, so you need the user to "teach" it once. Seems a reasonable approach to me.

Re: A Map of Wireless Passwords from Airports and Lounges

#62

Earlier quoted context omitted.

Why would you move to iOS over that?

Without a rooted phone, there's no better way to "fix" Android's captive portal code, or to automate it.

How do you automate captive portals on iOS then?

Re: A Map of Wireless Passwords from Airports and Lounges

#63
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

In the physical world social convention is used all the time instead of real security.

If my boss needs some peace and quiet he closes his door. It is not locked, but people know not to enter. If it is open I can walk in and have a chat.

A WIFI password is a social convention asking you to not share. Everyone knows that it is not secure. But it is much easier than having a captive portal login system. By respecting the social convention we make life easier for everyone. Respecting a social convention is far less onerous than over zealous security mechanisms that annoy the customer.

Re: A Map of Wireless Passwords from Airports and Lounges

#64
post #47

Earlier quoted context omitted.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries. As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs aro…

Typing 1.1.1.1 or any other IP address usually helps, it automatically redirects to the main login page. If you type a name, your DNS query fails.

Funny you picked that particular IP -- out of all four billion, 1.1.1.1 is the only one (that I know of) that uses HTTPS!

Re: A Map of Wireless Passwords from Airports and Lounges

#65
post #21

Is it possible to set up a trap where someone who inputs a leaked password will be automatically blocked or put on a naughty list? If you owned a coffeeshop, you would want your Wi-Fi users to be for customers only.

Said trap would hit any former returning customer who saved the wifi password.

Re: A Map of Wireless Passwords from Airports and Lounges

#66
post #44

Earlier quoted context omitted.

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

At that point it is public information, and sharing it more widely is just journalism or publishing.

There are a lot of city and town public records. But once they are online and searchable and cross reference able with databases and APIs they become a new kind of public. There’s a lot of data showing this. So maybe it’s public, but not everything that is public needs to be in machine readable format on the internet.

I didn’t explain that well, but maybe you get the point. There’s a balance to be struck.

Re: A Map of Wireless Passwords from Airports and Lounges

#67
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

> not using encryption

Not a viable option, this would allow anyone to intercept traffic.

(To be fair, a lot of wifi routers are broken and will forward you all decrypted traffic from other users anyway on request. Try running WireShark on public wifis.)

The big problem is that Wifi with no password provides no privacy. Ideally we would have a wifi mode that is encrypted, but does not require a password. Just like Https.

Re: A Map of Wireless Passwords from Airports and Lounges

#68

Earlier quoted context omitted.

Without a rooted phone, there's no better way to "fix" Android's captive portal code, or to automate it.

How would root or iOS help you? The problem is that each captive portal is different, so you need the user to "teach" it once. Seems a reasonable approach to me.

Root would allow packet capture without the VPN framework that may not work before there's a network "up" (I should try tShark).

I guess I'm just a bit exasperated about how the lesser-used parts of Android have far less attention to detail (there's no reason this couldn't be a built in feature)

Re: A Map of Wireless Passwords from Airports and Lounges

#69

Any comments on the tech behind this? (I've done a few projects crowd sourcing and distributing information like this and I'm currently thinking about some tools in this space, hence my curiosity.)

Have a look at https://memberapp.github.io/#map

It allows messages tied to locations to be written to the Bitcoin Blockchain. The database is public, anyone can add information and it is uncensorable.

Re: A Map of Wireless Passwords from Airports and Lounges

#70
post #4

Earlier quoted context omitted.

Why? Why would an airport make connecting to the free WiFi they offer harder?

The WiFi isn't offered by the airports, it's offered by private lounges and restaurants, who offer it as a perk to their paying customers.

Well, in europe most airports have free wifi with no restrictions. They are usually offered by the Airport administration company.

In my home country, almost all airports administration companies offers time-restricted-but-free-wifi too.

Post reply on HN