Earlier quoted context omitted.
If your app does that then it's not particularly safe over an encrypted wifi either. The solution is to fix that app, not to rely on a very weak defense that may help you in a fraction of the possible attack scenarios.
Good luck fixing your bank app. For a consumer it’s a lot easier to avoid situations where your communication is easily intercepted than it is to change the code of their banking apps.
Advice to avoid public Wi-Fi is mostly out of date
111–117 of 117 posts
Re: Advice to avoid public Wi-Fi is mostly out of date
#112I remember in 2005 when you could just start up Ethereal, run it for a minute, and get many people's email passwords, email, everything... I think Wi-Fi security is going to be a major FUD talking point for the telecoms as they try to justify high prices, 5G, and the rest of their trip. 5G as it exists now does little to compete with WiFi because (in the millimeter wave form) it doesn't pass through walls. The overwh…
But 5G is not meant for in house consumption. It is meant for crowded spaces like train stations, supermarkets to offload other bands. Then you get micro cells installed indoors inside of supermarkets. (what I mean by supermarket means mall and all those kind of shopping centers) It is meant also for all kinds of smart sensors in area, but not like home sensors but utilities. We have that with LoRa, but it is really…
I was part of a group that installed some radio gear on the roof of the local mall and I can say that the building manager of the mall was a tough customer. It really helped that he liked our (union) electrician and was certain we wouldn't contribute any leaks to the roof.
Carriers used to use the IBEW and CWA and had some standards for the quality of work done. Today carriers tend to use non-union contractors -- some of those people are excellent to OK but some are real idiots that any property owner would want to keep far away.
So far as serious IoT goes I think the coverage problems will still dog IoT. With fiber you can get 100% coverage -- it costs money, but there is no site that can't be served.
Will cell phones carriers will tell you they cover 98% of POPs, when you investigate it might be more like they cover 89% of POPs. With wireless systems you make a rather large capital investment that rapidly erodes in value to get to that 89% coverage but then the cost explodes from there.
Re: Advice to avoid public Wi-Fi is mostly out of date
#113Earlier quoted context omitted.
It's amazing how well such companies can repulse developers: - Everyone works on 8GB windows machine and sticky keyboard - Remote desktop - "You wanna install your IDE? Yeah contact IT, gonna take few days" - Can't install any of cli tools - Atlassian suite - Spend half a day in meetings - Scrum Then they complain how hard it is to get a good developers...
am I the only developer(ish) who likes JIRA?
However, I hear other companies like the configurability too...and their crappy processes were so easily configured that it became a crappy tool for their poor developers.
Re: Advice to avoid public Wi-Fi is mostly out of date
#114Earlier quoted context omitted.
It's amazing how well such companies can repulse developers: - Everyone works on 8GB windows machine and sticky keyboard - Remote desktop - "You wanna install your IDE? Yeah contact IT, gonna take few days" - Can't install any of cli tools - Atlassian suite - Spend half a day in meetings - Scrum Then they complain how hard it is to get a good developers...
am I the only developer(ish) who likes JIRA?
Re: Advice to avoid public Wi-Fi is mostly out of date
#115Sure, it's not as dangerous as it was... Or is it? All the tools are mature now. Documentation is rife. A seven year old with a Raspberry Pi can set up a hotspot and spike your DNS. This thread contains a litany of security papercuts across the whole stack. DNS, shitty apps, crappy server configs and sites that just don't care.
So yeah, it's no 1999. You're probably not getting your FTP password sniffed off a public network these days, but there are still plenty of reasons for me to use 4G or WireGuard instead of trustless networks.
Public Wi-Fi will remain firmly on my "list of things to worry about" until I can audit all traffic from my devices.
Re: Advice to avoid public Wi-Fi is mostly out of date
#116Earlier quoted context omitted.
Am Turkish, and not really. There is no evidence of Turkey caring about what the individual citizens visit (except in case of a crime investigation etc.) Bans in Turkey works like this: Turkey sees something they don't like on the Internet, Turkey reaches the company / individuals behind it (they can be anywhere in the world) and tells them "take it down or we will block your access to Turkish citizens and you'll los…
I feel like asking the site to take something down ... is effectively caring about who sees it. Otherwise you wouldn't do that.
Re: Advice to avoid public Wi-Fi is mostly out of date
#117 "You would be safe in active war-zone (eg. syria) because you are civillian and do not carry any weapons with you"
No, you are not safe at all.
Lets assume public wifi requires acceptance of terms and conditions.- Redirects all pages (from your Mac/Ip address) to their server
- There is checkbox on the page for ToS/ToC approval and 'Continue' button
- Behind the scenes clickjacking/framebusting happens [0]
- You get PWNd or monetized.
- also being fingerprinted by company. eg: amiunique.org
Given conditions, they can inject ads/cookies to track you even after you go away. (eg. at home)