Earlier quoted context omitted.
A fair amount (DNS, etc) is still in the clear, yes. I still see a good amount of clear text web traffic when I do packet captures in airports and the like. Usually image or media files, but the odd time I see some badly conceived automatic update process pulling an exe or msi over plaintext HTTP.
Would something like NextDNS help?
Wi-Fine
11–20 of 57 posts
Re: Wi-Fine
#12I was trying to explain this to someone recently and basically described the same. However, there’s still a privacy risk on a public wifi, correct? As in your neighbor can see the DNS requests (as those are generally unencrypted). If you use a VPN, cool, but now your “free VPN” gets to see that. The only other issues I could think of were ARP poisoning / spoofing and maybe local phishing redirects
A fair amount (DNS, etc) is still in the clear, yes. I still see a good amount of clear text web traffic when I do packet captures in airports and the like. Usually image or media files, but the odd time I see some badly conceived automatic update process pulling an exe or msi over plaintext HTTP.
Of all the places I'd avoid packet sniffing, that's high on the list.
Re: Wi-Fine
#13Earlier quoted context omitted.
A fair amount (DNS, etc) is still in the clear, yes. I still see a good amount of clear text web traffic when I do packet captures in airports and the like. Usually image or media files, but the odd time I see some badly conceived automatic update process pulling an exe or msi over plaintext HTTP.
I think debian does package updates over HTTP in the clear. It's not necessarily a problem if the package is signed and the signature is verified.
In the real world is it embarrassing to have Emacs installed? Or KDE? Or even Tux Racer ? Probably not. But all things being equal we'd rather the program just kept this to itself right?
Re: Wi-Fine
#14I figure if you connect to an open Wi-fi and then to a VPN endpoint, you're put on some government list.
Re: Wi-Fine
#15Not all web traffic is HTTPS, way too much of it still isn't. Not everything is HTTP(S) even, some nastiness comes from other protocols. DNS is still rarely encrypted. NTP basically* isn't encrypted. And all those combined allow a lot of privacy-invasive profiling to be done. Without WPA3 public, it's also passive and you have no clue.
Re: Wi-Fine
#16To me public Wi-Fi is pretty much a honeypot. Most people I know don't rely on it, especially with widespread 4G and mobile phones, so the only people using it are shady figures for whom open and public Wi-Fi is just another step in their OpSec. I figure if you connect to an open Wi-fi and then to a VPN endpoint, you're put on some government list.
Re: Wi-Fine
#17Earlier quoted context omitted.
I think debian does package updates over HTTP in the clear. It's not necessarily a problem if the package is signed and the signature is verified.
But you don't have privacy. If you didn't want anybody to know that you've got clown-fetish-program version 1.6.4 installed, then Debian's package upgrade code fetching clown-fetish-program version 1.6.4.1 update is a disappointing give away. In the real world is it embarrassing to have Emacs installed? Or KDE? Or even Tux Racer ? Probably not. But all things being equal we'd rather the program just kept this to itse…
Not to mention the additional possibility of exploiting apt itself vs. having to exploit the TLS stack (which goes trough a lot more scrutiny).
Re: Wi-Fine
#18Earlier quoted context omitted.
I think debian does package updates over HTTP in the clear. It's not necessarily a problem if the package is signed and the signature is verified.
But you don't have privacy. If you didn't want anybody to know that you've got clown-fetish-program version 1.6.4 installed, then Debian's package upgrade code fetching clown-fetish-program version 1.6.4.1 update is a disappointing give away. In the real world is it embarrassing to have Emacs installed? Or KDE? Or even Tux Racer ? Probably not. But all things being equal we'd rather the program just kept this to itse…
Re: Wi-Fine
#19In this space, if you have WPA3 then there's no benefit to having a "password" for WiFi which actually is public knowledge. In WPA and WPA2 the password means network use is encrypted, which means a completely passive adversary can't just snoop the network so long as there's a password. But in WPA3 even without a password everything is encrypted anyway, your station says "Hey, I'm joining this network here's a number…
Re: Wi-Fine
#20To me public Wi-Fi is pretty much a honeypot. Most people I know don't rely on it, especially with widespread 4G and mobile phones, so the only people using it are shady figures for whom open and public Wi-Fi is just another step in their OpSec. I figure if you connect to an open Wi-fi and then to a VPN endpoint, you're put on some government list.
If people around you tend to have a profile like HN users yes they of course know what they're dealing with.
Bur for the rest of the non-techie 99% of the world, public Wi-Fi is perfectly fine.