Live data from Hacker News

Wi-Fine

wifine.gitlab.io

51–57 of 57 posts

Re: Wi-Fine

#51

Getting owned wise - maybe. Privacy wise - no. Not all web traffic is HTTPS, way too much of it still isn't. Not everything is HTTP(S) even, some nastiness comes from other protocols. DNS is still rarely encrypted. NTP basically* isn't encrypted. And all those combined allow a lot of privacy-invasive profiling to be done. Without WPA3 public, it's also passive and you have no clue.

Its still fairly easy to spoof APs. 802.11w aims to prevent this but support is spotty. And a spoofed AP means now the attacker has access to things that would normally gated behind NAT. Although with use of social engineering, you can set up a gateway page that says something like "Log in to Facebook for free wifi", bypassing the need for any exploits.

> Its still fairly easy to spoof APs. 802.11w aims to prevent this but support is spotty.

Even with 802.11w it's easy to impersonate APs, 802.11w doesn't protect against evil twins. I find it a massive pity that we can't freeload off of web PKI to authenticate AP's.

Re: Wi-Fine

#52
post #43

Oh wow this shit again. @joepie91 you are very wrong about VPNs and this is the sort of mess that gist thread leads to if you ever see this. Has OP never heard of responder? Things other than browsers are actively making and accepting network requests all the time. Plenty of sites by default have port 80 open and redirect to 443 (can be intercepted). Please do not spread harmful information. Never (ever) use an open…

Honestly, browsers are not the worst offenders here or the worst mistake.

MUAs are. There's no MUA-STS, the user interaction required to accept an insecure connection is often too trivial, the authentication methods allow easy credential theft and prolonged reuse.

Re: Wi-Fine

#53
The DNS point is dangerous because you can simulate to be a “legit website” also with SSL, and instead it could be a Man in the Middle attack.

And also with closed Wi-Fi could be dangerous.

I use always my home WireGuard tunnel when I’m with with an unknown Wi-Fi access.

The point is not the Wi-Fi, but what to do with it. If you want to browse Instagram on a public Wi-Fi there’re issues but I wouldn’t buy plane tickets on a public Wi-Fi or browse my online banking account (without a trusted VPN).

Re: Wi-Fine

#54

In this space, if you have WPA3 then there's no benefit to having a "password" for WiFi which actually is public knowledge. In WPA and WPA2 the password means network use is encrypted, which means a completely passive adversary can't just snoop the network so long as there's a password. But in WPA3 even without a password everything is encrypted anyway, your station says "Hey, I'm joining this network here's a number…

https://eduroam.org/

I always don’t understand the name, looks like someone made a type when was writing “eurodam”. Because it’s a EU thing, and could a dam to break to silence/Incommunicability, so with EDUROAM and not EURODAM?!

I’m going crazy every time. I use a lot this network.

Re: Wi-Fine

#55

Earlier quoted context omitted.

https://eduroam.org/

I always don’t understand the name, looks like someone made a type when was writing “eurodam”. Because it’s a EU thing, and could a dam to break to silence/Incommunicability, so with EDUROAM and not EURODAM?! I’m going crazy every time. I use a lot this network.

Education + Roaming [0] = Edu + roam = Eduroam

[0] https://en.m.wikipedia.org/wiki/Roaming

Re: Wi-Fine

#56
post #55

Earlier quoted context omitted.

I always don’t understand the name, looks like someone made a type when was writing “eurodam”. Because it’s a EU thing, and could a dam to break to silence/Incommunicability, so with EDUROAM and not EURODAM?! I’m going crazy every time. I use a lot this network.

Education + Roaming [0] = Edu + roam = Eduroam [0] https://en.m.wikipedia.org/wiki/Roaming

Oh… thank you! I have never thought about this. So it makes sense!

Re: Wi-Fine

#57

Earlier quoted context omitted.

Why?

Because irrespective of the legality of packet sniffing on a network you don't own, airport police have no chill.

They also don’t have the competence to actually figure out that you’re packet sniffing. How would they know?
Post reply on HN