Live data from Hacker News

CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

coffeeshopwifi.com

11–20 of 85 posts

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#11
My favorite version of this trend remains http://alwayshttp.com because https://alwayshttp.com doesn't work since alwayshttp.com:443 doesn't connect.

On the other hand, it's possible to reach https://coffeeshopwifi.com and (with a cloudfront certificate error) https://neverssl.com which makes me wonder if something in whatever I'm using is trying to upgrade to HTTPS when I fail to reach them.

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#12
post #2

I like the straightforward explanation this site provides. That said, I tend to use http://example.com to trigger captive portals because it's an IANA reserved domain [1] that other people can't register. This gives me confidence to browse to it without fear that the domain could lapse in the future and get taken over (e.g. in a watering hole attack). [1]: https://www.iana.org/domains/reserved

iOS (and macOS?) use http://captive.apple.com/

Yea I use this manually some times as well.

Great for low bandwidth tests Just displays clean “success”

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#13

I don't understand how this (and other similar sites mentioned) work. What is going on with the network that makes visiting a non-SSL site make it work? Anyone care to offer an explanation or have a link to one?

Basically, because the captive portal tries to redirect the browser to a page for authentication, but the browser won't let this through on a https connection for security reasons.

https://en.wikipedia.org/wiki/Captive_portal#Require_Web_Bro...

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#14

Earlier quoted context omitted.

iOS (and macOS?) use http://captive.apple.com/

Yea I use this manually some times as well. Great for low bandwidth tests Just displays clean “success”

Clean "Success" sssSsss

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#16

My favorite version of this trend remains http://alwayshttp.com because https://alwayshttp.com doesn't work since alwayshttp.com:443 doesn't connect. On the other hand, it's possible to reach https://coffeeshopwifi.com and (with a cloudfront certificate error) https://neverssl.com which makes me wonder if something in whatever I'm using is trying to upgrade to HTTPS when I fail to reach them.

httpforever.com is the one I use. https connection gets redirected to http to ensure that it gets captured.

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#17
post #2

I like the straightforward explanation this site provides. That said, I tend to use http://example.com to trigger captive portals because it's an IANA reserved domain [1] that other people can't register. This gives me confidence to browse to it without fear that the domain could lapse in the future and get taken over (e.g. in a watering hole attack). [1]: https://www.iana.org/domains/reserved

iOS (and macOS?) use http://captive.apple.com/

I've used this on Linux as well.

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#18
> Coffee Shop Wifi always connects with HTTP instead of secure HTTPS. This allows guest wifi networks to show you their internet login page.

I always go to http://paulgraham.com when I need to connect to guest WiFi for the exact same reason..

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#19

My favorite version of this trend remains http://alwayshttp.com because https://alwayshttp.com doesn't work since alwayshttp.com:443 doesn't connect. On the other hand, it's possible to reach https://coffeeshopwifi.com and (with a cloudfront certificate error) https://neverssl.com which makes me wonder if something in whatever I'm using is trying to upgrade to HTTPS when I fail to reach them.

httpforever.com is the one I use. https connection gets redirected to http to ensure that it gets captured.

I think you're misunderstanding the GP. The HTTPS connection will not be redirected when you are behind a captive portal, you'll receive an invalid certificate error (when the captive portal tries to serve itself at that address) or the website will simply not respond. Only if the HTTPS response is cached in your browser would the redirection work behind a captive portal.

Re: CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi

#20
I used to use purple.com for this. Anyone who used it back in the golden age of the internet knows it was ideal for such purposes. It even had that squirrel game. Anyway after many many years of serving that masterpiece over plain http the guy sold the domain to some fucking matress company who insists on SSL.
Post reply on HN