How is he able to get them to trust the network? Is it common for software to connect to known SSIDs without verifying any other information?
What we give away when we log on to a public Wi-Fi network
11–20 of 112 posts
Re: What we give away when we log on to a public Wi-Fi network
#12Considering how ridiculously cheap an anonymous VPN service is these days I am surprised how many people do not use them.
People struggle with connecting their laptops/tablets to WiFi. Expecting them to configure a VPN on their own is a stretch.
You could start a small SaaS business that could make "lifestyle business" type money if you did this well.
Re: What we give away when we log on to a public Wi-Fi network
#13How was the hacker able to get Facebook credentials? Facebook uses HTTPS and so does Live.com. Even if I'm connected to a malicious router, only me and Facebook know about the data we're sending each other. Am I missing something or should the author of this article provide more evidence on the type of attack?
Edit: SSL does not have to be used on the clone. Most people will not notice/care.
Re: What we give away when we log on to a public Wi-Fi network
#14Are my devices really broadcasting the SSIDs they have been connecting to?
Re: What we give away when we log on to a public Wi-Fi network
#15Are my devices really broadcasting the SSIDs they have been connecting to?
Re: What we give away when we log on to a public Wi-Fi network
#16Considering how ridiculously cheap an anonymous VPN service is these days I am surprised how many people do not use them.
Because it's difficult to setup and configure for most people? People struggle with connecting their laptops/tablets to WiFi. Expecting them to configure a VPN on their own is a stretch. You could start a small SaaS business that could make "lifestyle business" type money if you did this well.
I don't think ease is a barrier anymore. I think it's just lack of education about how necessary these measures are.
Re: What we give away when we log on to a public Wi-Fi network
#17Re: What we give away when we log on to a public Wi-Fi network
#18Considering how ridiculously cheap an anonymous VPN service is these days I am surprised how many people do not use them.
Because it's difficult to setup and configure for most people? People struggle with connecting their laptops/tablets to WiFi. Expecting them to configure a VPN on their own is a stretch. You could start a small SaaS business that could make "lifestyle business" type money if you did this well.
I am not associated with them in any way.
Re: What we give away when we log on to a public Wi-Fi network
#19How was the hacker able to get Facebook credentials? Facebook uses HTTPS and so does Live.com. Even if I'm connected to a malicious router, only me and Facebook know about the data we're sending each other. Am I missing something or should the author of this article provide more evidence on the type of attack?
I suspect it's not plain old sniffing. He might give fake DNS records to point to his own phishing site (facebook clone). It's trivial to re-post the credentials to the real facebook check the password and then actually log them in. curl can be used to do this, as I am sure many others. Edit: SSL does not have to be used on the clone. Most people will not notice/care.
The only way to have done this is by having the user click "continue" or "ignore" or something on an ssl error page. I know from experience that a company full of programmers will happily do that. Only a few percent would go "wait a minute, this is Facebook. That certificate should be valid." Some people here might reply "no way", but HN generally contains the one percent.
Edit: This is almost correct. You can actually prevent being redirected from http to https when typing in "facebook.com" without https:// in front. My bad.
Still though, the attentive user would notice the missing padlock. I check it 3/4 times, and 4/4 times when using a public network. I also refrain from using http sites where I log in (some forums I visit do that). But again, probably less than one percent of the tech people do that.
Re: What we give away when we log on to a public Wi-Fi network
#20How was the hacker able to get Facebook credentials? Facebook uses HTTPS and so does Live.com. Even if I'm connected to a malicious router, only me and Facebook know about the data we're sending each other. Am I missing something or should the author of this article provide more evidence on the type of attack?
I suspect it's not plain old sniffing. He might give fake DNS records to point to his own phishing site (facebook clone). It's trivial to re-post the credentials to the real facebook check the password and then actually log them in. curl can be used to do this, as I am sure many others. Edit: SSL does not have to be used on the clone. Most people will not notice/care.