Live data from Hacker News

A Map of Wireless Passwords from Airports and Lounges

foxnomad.com

121–124 of 124 posts

Re: A Map of Wireless Passwords from Airports and Lounges

#121
post #85

Earlier quoted context omitted.

It is controversial but there is something in publicly posting already compromised long-living static credentials. I do not approve nor disapprove of this. It could be unethical, could be even illegal but still - it also may force to not rely on this security-through-obscurity approach and maybe actually start doing things right. Sadly, many people don't learn from theoretical implications - they just ignore those an…

There are degrees of everything. In an ideal world, they probably wouldn't have passwords at all and trust everyone who doesn't have explicit permission to just not use AIRLINE_CLUB or whatever. We don't live in that world. On the other hand, they probably don't want to use some complicated individualized password scheme because that's a headache for everyone. So they pick a happy medium that keeps out the casual web…

I'm not sure. Your vision looks oddly alien to me. It is human to make accidental mistakes, be tempted to break rules and similar. Half of our folklore is about praising deception, playing around the rules, outsmarting or outright cheating. I don't mean those are good things (they're generally not), but those are part of the human nature. Please don't take this personally, but the ideal world of your description would be boring and... I think "sterile" is the word. Not like this is inherently good or bad (I can see both aspects I think) - just alien.

We had plaintext Internet once, but as it grew, it started to fail.So, now most of us cheer for TLS everywhere and believe it's a good idea. Don't see how this is any different.

Re: A Map of Wireless Passwords from Airports and Lounges

#122

Any comments on the tech behind this? (I've done a few projects crowd sourcing and distributing information like this and I'm currently thinking about some tools in this space, hence my curiosity.)

Its just a google map, I dont believe its dynamically updated from users, and doing that would be trivial anyway.

In most cases the tech tends to be trivial, sure. How you check accuracy of incoming information, make sure it's kept up to date in the future, and present it to people tends to throw up lots of very interesting usability problems.

Re: A Map of Wireless Passwords from Airports and Lounges

#123
post #75

Earlier quoted context omitted.

Actually WPA with pre-shared key doesn't provide any security if key is publicly known (as someone can setup mitm device). For wifi without password you should look at WPS.

It's not that someone can set up a MitM device. Wifi with a shared password can be passively captured using a variety of tools and decrypted using WireShark.[1] The "coffee shop" scenario, where a WPA2 Personal password is written where anyone can see it, is essentially as insecure as non-encrypted wireless. WPA2 Personal is only secure if the password is very strong[2] and never given to untrusted parties. The only…

> The only wireless security I put any real trust in is WPA2 Enterprise with 802.1x certificate-based authentication specifically.

802.1x with a certificate for Radius server (TTLS mode, which simply layers the plaintext password via TLS) and plain passwords for users is also good enough.

Re: A Map of Wireless Passwords from Airports and Lounges

#124

Earlier quoted context omitted.

That’s just the law in a lot of countries. I’d have to eat the 50 cents a lot and just receive an international SMS.

Some won't even allow an international phone number. They demand a local phone number... Have fun with that...

Internet over DNS it is.
Post reply on HN