Live data from Hacker News

NeverSSL

fdbhclmrkstnvwxz.neverssl.com

81–90 of 206 posts

Re: NeverSSL

#81
If you’re using a mainstream OS that automatically detects standard captive portals, the main reason why you’ll need this is for “tiered” captive portals like the ones offered on some airplanes.

Those tiered captive portals have unique requirements that conflict with OS behavior:

A) By default, they want to offer some limited Internet access, such as accessing a sponsored site (often a shopping site like Amazon) or streaming videos (from some server on the airplane LAN).

B) For premium, paying users, they want to offer (mostly) full Internet access

For this to work, they have to fool devices in Tier A into believing that they have Internet access, by spoofing responses from standard captive portal detection URLs like captive.apple.com. Otherwise, if the network fails the captive portal test, many devices won’t stay connected to the Wi-Fi network, preventing access to the sponsored sites or LAN streaming apps.

At the same time, they want users to be able to upgrade from Tier A (limited access) to Tier B (full access) at any time. So they enable these upgrades by serving a captive portal page... to every HTTP site _except_ the standard OS captive portal detection pages that would affect OS behavior.

That’s when the user needs to visit an HTTP site other than the standard captive portal pages. One like neverssl.com

It’s obviously a fragile solution and is becoming an increasingly poor experience as sites adopt HTTPS, HSTS, and other standards. At the same time, I don’t know of any upcoming solutions to the tiered captive portal problem. Does anyone know what should replace this?

Re: NeverSSL

#82
post #49

Here is another similar site i've been using for years: http://amionline.net/

Well now that text isn't very helpful, might be cached by any middlebox or endpoint. I expected at least a time like "Yes as of 2019-11-03T19:19:19Z" (I have a subdomain, http://time.lucb1e.com, that does I use for this)

Re: NeverSSL

#83
post #66

http://neverssl.com/changes > I also want to keep neverssl.com ad free, but as it's now costing me about $2,000 a year to host it, […] Wait, how could hosting a static website cost $2k/year?!

AWS costs add up over time. $166 per month is not bad, especially if it's a high volume traffic site.

Re: NeverSSL

#89
post #66

http://neverssl.com/changes > I also want to keep neverssl.com ad free, but as it's now costing me about $2,000 a year to host it, […] Wait, how could hosting a static website cost $2k/year?!

Bandwidth, maybe? That page is 53.8 KB total. $2k does seem high though.

When used "properly" it should take even less bandwidth.

Re: NeverSSL

#90
post #53

"This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type " http://neverssl.com" into your browser's url bar, and you'll be able to log on." I don't get it. How does browsing to http://neverssl.com help you to log in to other websites?

On some public wifi networks, you need to load a captive portal page and hit a button (usually to accept terms and conditions) before network to route you to any actual sites. The network often enforces this by redirecting you to that page whenever you try to visit something else. However, this doesn't occur properly when accessing a page with HTTPS. The easiest way to to directly to to the captive portal is to try t…

Thanks for the explanation - I've definitely encountered that situation. Do you know why it works that way?
Post reply on HN