Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

91–100 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#91
post #12

The author claims to be a computer security engineer, yet is deliberately setting up a tool to defeat security -- not an abstract tool, useful in surveying and thus improving your own security and incidentally capable of being used for mischief, but nothing more than a list of identifiers and passwords. The only indicator you can gain from this is that someone betrayed your trust. If this profession had a board of et…

WiFi passwords aren't about security for the people using the network, they're about blocking people who haven't paid for it. If, as an attacker, one of your targets is using JFK's airport WiFi, getting the password for that WiFi is the least of your problems. Whether it's ethical to hand out passwords to people who haven't paid for WiFi is another question entirely, but wouldn't it be sweet if businesses just let an…

> wouldn't it be sweet if businesses just let anyone join their WiFi? Bike repair shops always leave a pump outside for anyone to use, not just customers.

That's a flawed analogy. It'd be sweet if I could do any prohibited thing whenever I feel like it.

How frequently is the pump oversubscribed that it causes a queue and blocks the sidewalk? If this happened, the repair shop would soon stop leaving a pump outside.

With a WiFi network in an airport you have regular situations where demand outstrips capacity. This isn't something that is discovered later, it's common sense before you even operate the service. Users attempt to download movies at the last minute for their flights, and in many cases each person will attempt to connect multiple devices to the hotspot. The hotspot provider setup things to support their clientele. They'd have set it up differently if they wanted it available for use by all.

Re: A Map of Wireless Passwords from Airports and Lounges

#92
post #63

Earlier quoted context omitted.

A password that has already been handed out to thousands or tens of thousands of customers isn't "security".

In the physical world social convention is used all the time instead of real security. If my boss needs some peace and quiet he closes his door. It is not locked, but people know not to enter. If it is open I can walk in and have a chat. A WIFI password is a social convention asking you to not share. Everyone knows that it is not secure. But it is much easier than having a captive portal login system. By respecting t…

I think I understand the ethos behind pushing for traditional social norms to not be discarded in the digital age, to resist stratification of security and convention between us all.

Conversely, I also think I understand the rationale for distilling the digital network security flaws and laying them open with the goal of changing and updating the social conventions which can now be completely bypassed and still accomplish a successful intrusion.

Re: A Map of Wireless Passwords from Airports and Lounges

#93

Earlier quoted context omitted.

Well, in europe most airports have free wifi with no restrictions. They are usually offered by the Airport administration company. In my home country, almost all airports administration companies offers time-restricted-but-free-wifi too.

I've travelled all over Europe and Asia and I don't think I've ever come across an airport without at least half decent, free, open wifi. Is this predominantly a US thing?

Yes. It's not limited to airports.

There are many reason why a hotspot provider in the US wouldn't want the liability of anyone other than a know user accessing their service. These issues are probably more limited elsewhere in the world, although it's probably the case that they are just lagging in coming up with better security practices/policy. Some home internet providers in the US like Comcast have a public WiFi service, but you have to authenticate to use it.

Re: A Map of Wireless Passwords from Airports and Lounges

#94
post #24

Earlier quoted context omitted.

Do I need to explain risks using foreign local networks in HN ? I see it quite unfair to get a downvote for this.

Yes. Having a properly secured laptop on public wifi is no different than having a server on the public internet. It's not difficult to reason about the threat model here, and operating systems are fully capable of rejecting potentially harmful traffic.

Rejecting harmful traffic is only one of the threats. There are many other attacks that can be conducted when you control the network and DNS. Only security-conscious users think of ways to counter those threats.

Re: A Map of Wireless Passwords from Airports and Lounges

#95

I'm not sure this is a good thing to do, but airports that don't have free open wifi annoy me. It's so useful to have internet access when you arrive in a foreign country, for figuring out how to get into the city, or to communicate with a hotel etc, and sometimes its unfeasible to use your own sim abroad. It just seems a petty thing for airports to do, to try and make a few dollars or euros or pounds that way.

I also hate people who put an open wifi requiring an SMS token in an Airport... You know, the only place where you have a good chance of your SIM Card not working for being abroad...

Exactly! I'm looking at you, Delhi Airport! The f'n morons advertise "free wifi! free wifi!!" everywhere, but when you actually want to use it, they demand a phone number to send an SMS message. Are the people in charge there really that clueless??

Re: A Map of Wireless Passwords from Airports and Lounges

#96

I'm not sure this is a good thing to do, but airports that don't have free open wifi annoy me. It's so useful to have internet access when you arrive in a foreign country, for figuring out how to get into the city, or to communicate with a hotel etc, and sometimes its unfeasible to use your own sim abroad. It just seems a petty thing for airports to do, to try and make a few dollars or euros or pounds that way.

> It just seems a petty thing for airports to do, to try and make a few dollars or euros or pounds that way.

Doesn't the party on the other side of the transaction – i.e. you and I who do not want to pay for an Internet connection – have the same attitude?

Re: A Map of Wireless Passwords from Airports and Lounges

#97

Earlier quoted context omitted.

I also hate people who put an open wifi requiring an SMS token in an Airport... You know, the only place where you have a good chance of your SIM Card not working for being abroad...

Exactly! I'm looking at you, Delhi Airport! The f'n morons advertise "free wifi! free wifi!!" everywhere, but when you actually want to use it, they demand a phone number to send an SMS message. Are the people in charge there really that clueless??

I got burned by this exactly a couple of years ago. Flight into Delhi was delayed, desperately needed wifi to communicate with my ride upon arrival, but no wifi without an active SIM card. Infuriating.

Re: A Map of Wireless Passwords from Airports and Lounges

#98
post #65
post #21

Is it possible to set up a trap where someone who inputs a leaked password will be automatically blocked or put on a naughty list? If you owned a coffeeshop, you would want your Wi-Fi users to be for customers only.

Said trap would hit any former returning customer who saved the wifi password.

Not if you limit it to trap-only passwords you leaked yourself.

Perhaps would work better if you severely slow piggybackers down instead of outright blocking them. If they think your connection is just bad they won't know they need to escalate.

Re: A Map of Wireless Passwords from Airports and Lounges

#99
post #73

I needed to connect an Apple TV to a blocked wifi at a hotel, Just sharing, here are the instructions using a macbook to get past hotspot auth, since there isn't a browser on an Apple TV 1. Disconnect from ap by option+click status bar wifi icon 2. Write down your current wifi mac address ifconfig en0 | grep ether 3. Switch macbook to Apple TV mac address sudo ifconfig en0 ether [apple tv mac address] 4. Connect to w…

> ... blocked wifi ...

I use Hootoos when travelling. They combine a powerbank with a tiny MIPS device creating a wifi hotspot. Then upstream it can either connect to a wifi network or ethernet. It does NAT etc between the two.

The massive advantage is that my devices all know about the hootoo wifi network. I then just have to connect the hootoo to the upstream network which is easy, and you can do browser logins etc from behind it.

This is the model I like: https://www.hootoo.com/hootoo-tripmate-ht-tm05-wireless-rout...

Re: A Map of Wireless Passwords from Airports and Lounges

#100
post #54

Earlier quoted context omitted.

I would find something like this to be helpful. As a frequent traveler often you don’t have any sort of cell service when you land. Being able to quickly hop on WiFi is often a godsend for quick communication and navigation to final destinations in foreign countries. As an example, in Copenhagen airport there is free WiFi but you have to go to wifi.cphairport.com to access it and if you don’t see one of the signs aro…

Sometimes the resason that you don't get redirected to the wifi network's captive portal is that your browser is trying to access a page using HTTPS. Trying to connect to a HTTP-only site (like http://neverssl.com/ ) can solve this.

Yeah. And this is a complete shitshow as everyone on earth pushes https as hard as possible. How do people who haven't heard of neverssl manage to connect to these captive portals? Sooner or later, the drive toward secure http is just going to kill off anything with a captive portal for most internet users.
Post reply on HN