Live data from Hacker News

Gogo injects false SSL certificates for google.com domains

twitter.com

51–52 of 52 posts

Re: Gogo injects false SSL certificates for google.com domains

#51
On gogo wifi right now and I'm not able to replicate the results. After paying for access I've tested several google services with no certificate issues(checked with latest Chrome, and openssl's s_client).

I opened another laptop(I travel with two), and without paying I started testing outbound connections with openssl's s_client and curl. It appears that the gogo wifi system will allow between 5-10 ssl connections before starting to block all outbound ssl connections. Without paying all http requests include a redirect to the captive portal, but at no time did I see a self signed cert for any of the https connections attempts.

Re: Gogo injects false SSL certificates for google.com domains

#52
post #27

Seems like someone should instigate a class-action lawsuit against them for DCMA / HIPPA violations.

DMCA doesn't apply here; there is no copyrighted media being copied. HIPAA doesn't apply either; the in-flight wifi carrier is not a health care provider.

DMCA is more than copyright....its also about "Anti-circumvention", the idea that a supposed secure connection being circumvented.

For HIPAA: What happens when you search google for your healthcare issue that they intercept? Since they have your name (from your credit card info), now their severs have sensitive healthcare info...are they HIPAA compliant?

Post reply on HN