Live data from Hacker News

Wi-Fine

wifine.gitlab.io

21–30 of 57 posts

Re: Wi-Fine

#21

Earlier quoted context omitted.

A fair amount (DNS, etc) is still in the clear, yes. I still see a good amount of clear text web traffic when I do packet captures in airports and the like. Usually image or media files, but the odd time I see some badly conceived automatic update process pulling an exe or msi over plaintext HTTP.

> I still see a good amount of clear text web traffic when I do packet captures in airports and the like. Of all the places I'd avoid packet sniffing, that's high on the list.

Its where you find the best variety of packets! Far superior to cafes.

Re: Wi-Fine

#22
post #9

Hi! Author of that website here. Can some mod or the OP that submitted this post change the title to "Wi-Fine: it is fine to use public Wi-Fi"? The current one is not very descriptive. Also, let me know if any of you have comments to me specifically.

Email hn@ycombinator.com, they usually respond really quickly.

Re: Wi-Fine

#23
post #9

Hi! Author of that website here. Can some mod or the OP that submitted this post change the title to "Wi-Fine: it is fine to use public Wi-Fi"? The current one is not very descriptive. Also, let me know if any of you have comments to me specifically.

unfortunately, the submission is past a deadline (not so sure) for title change. perhaps @dang can help ?

Re: Wi-Fine

#24

In this space, if you have WPA3 then there's no benefit to having a "password" for WiFi which actually is public knowledge. In WPA and WPA2 the password means network use is encrypted, which means a completely passive adversary can't just snoop the network so long as there's a password. But in WPA3 even without a password everything is encrypted anyway, your station says "Hey, I'm joining this network here's a number…

Small correction: with WPA2, a passive observer can decrypt the traffic between a device and the access point if they know the password and capture the initial connection of that device. Wireshark has built-in support for this.

Re: Wi-Fine

#25
post #14

To me public Wi-Fi is pretty much a honeypot. Most people I know don't rely on it, especially with widespread 4G and mobile phones, so the only people using it are shady figures for whom open and public Wi-Fi is just another step in their OpSec. I figure if you connect to an open Wi-fi and then to a VPN endpoint, you're put on some government list.

Many people do rely on it, they don't probably even know what a password does vs an open network. If people around you tend to have a profile like HN users yes they of course know what they're dealing with. Bur for the rest of the non-techie 99% of the world, public Wi-Fi is perfectly fine.

Perfectly fine for what? I live in Europe, everybody has Internet at home, and if they're out, they have 4G on their phone.

When would one need the coffee shop wifi, especially non-techies that go there just to have a coffee, not to work? Honest question.

Re: Wi-Fine

#26
post #25

Earlier quoted context omitted.

Many people do rely on it, they don't probably even know what a password does vs an open network. If people around you tend to have a profile like HN users yes they of course know what they're dealing with. Bur for the rest of the non-techie 99% of the world, public Wi-Fi is perfectly fine.

Perfectly fine for what? I live in Europe, everybody has Internet at home, and if they're out, they have 4G on their phone. When would one need the coffee shop wifi, especially non-techies that go there just to have a coffee, not to work? Honest question.

The vast vast majority of Europeans don’t have unlimited data plans with unlimited tethering. Not sure why you would think they do.

Re: Wi-Fine

#27
post #14

To me public Wi-Fi is pretty much a honeypot. Most people I know don't rely on it, especially with widespread 4G and mobile phones, so the only people using it are shady figures for whom open and public Wi-Fi is just another step in their OpSec. I figure if you connect to an open Wi-fi and then to a VPN endpoint, you're put on some government list.

Everyone who goes to a coffee shop with their work laptop is probably connecting to a VPN over open WiFi.

Re: Wi-Fine

#28

In this space, if you have WPA3 then there's no benefit to having a "password" for WiFi which actually is public knowledge. In WPA and WPA2 the password means network use is encrypted, which means a completely passive adversary can't just snoop the network so long as there's a password. But in WPA3 even without a password everything is encrypted anyway, your station says "Hey, I'm joining this network here's a number…

I worked in IT support as an undergrad ten years ago and am now going to grad school and using eduroam. It is such a night-and-day difference; I'm so incredibly pleased that there was enough international and inter-institutional cooperation to make it work.

I especially like it when I open up my laptop at a new coffee shop and discover it's already connected to eduroam—in the city I live in (Edinburgh) there are enough university buildings scattered around that a surprising percentage of the city center is covered. The National Library also uses eduroam.

Re: Wi-Fine

#29
post #25

Earlier quoted context omitted.

Perfectly fine for what? I live in Europe, everybody has Internet at home, and if they're out, they have 4G on their phone. When would one need the coffee shop wifi, especially non-techies that go there just to have a coffee, not to work? Honest question.

The vast vast majority of Europeans don’t have unlimited data plans with unlimited tethering. Not sure why you would think they do.

Reception can be pretty spotty in many areas as well, so even if you do have unlimited data and tethering, you might benefit from a public wifi.

Re: Wi-Fine

#30
This something that annoys me to no end about VPN ads. I listen to alot of podcasts so I can't go a day without hearing an ad for ExpressVPN. The ad read always includes a bit about "hackers being able to see your data on an open network".

And while technically true, I could technically run an old http only site and you might happen to be on the same network as a hacker using the decades old Firesheep, so yeah technically that could happen, but it's just so disingenuous when they come out and hammer that point home.

Anyways rant over.

Post reply on HN