Live data from Hacker News

NeverSSL

fdbhclmrkstnvwxz.neverssl.com

101–110 of 206 posts

Re: NeverSSL

#101
post #75

When I’m having trouble logging into a Wi-Fi network I just go to 128.1.1.1. Seems to work every time.

I always used my own IP until I got to a portal that didn't work with that. Now I use a subdomain of my site. Then one very smart captive portal "moved permanently"'d that and my browser cached it, as it should, and on the next WiFi it tried to load the old one's captive portal x_x. Not sure what the solution is for that, it would happen with neverssl or any of the alternative domains mentioned here as well. I guess…

NeverSSL already does that for you.

Re: NeverSSL

#102

Earlier quoted context omitted.

Bandwidth, maybe? That page is 53.8 KB total. $2k does seem high though.

A GB of outbound transfer on AWS costs about 0.09$. If the page is 55KB, that means that a single GB is about 18K page loads, but let's make that 15K page loads due to various overhead. To spend 2000$, you'd need to send about 22TB, which are about 330M page loads.

But that’s not accounting for gzip.

Re: NeverSSL

#103
post #81

If you’re using a mainstream OS that automatically detects standard captive portals, the main reason why you’ll need this is for “tiered” captive portals like the ones offered on some airplanes. Those tiered captive portals have unique requirements that conflict with OS behavior: A) By default, they want to offer some limited Internet access, such as accessing a sponsored site (often a shopping site like Amazon) or s…

Adding another question on top of this, does anyone know how widespread DNS over HTTPS affects this model? I guess you could do filtering based on IP address, but that seems really fragile as well?

I'm guessing that the way it works today if you're pointing to a non-standard DNS server like Cloudflare's, is that the portal still just intercepts and modifies those requests anyway.

Re: NeverSSL

#104
I've been using nossl.google.com even before I worked at Google. Somehow I found out about it in the crazy wild west internet of the 2000s and most of my colleagues didn't even know about it. Still works today.

Re: NeverSSL

#105
post #35

http://example.com also does this, albeit without the promise of never switching

In both Chrome and Firefox, when I type "example.com" into the URL bar, I go to https://example.com , probably because I've visited the https site before and they remember that. So I do not recommend example.com .

For Firefox, this may occur when the address bar autocompletes from history, pulling the https:// entry. As far as I can tell, it doesn’t have anything to do with prioritizing HTTPS, just whichever is more frequent in your history (if you visit the HTTP enough times it will switch to picking that for autocomplete). If you don’t use the autocomplete entry (for example, by tab-completing it but deleting the trailing slash), then it will use HTTP unless you actually typed https://.

Re: NeverSSL

#107

Earlier quoted context omitted.

Bandwidth, maybe? That page is 53.8 KB total. $2k does seem high though.

A GB of outbound transfer on AWS costs about 0.09$. If the page is 55KB, that means that a single GB is about 18K page loads, but let's make that 15K page loads due to various overhead. To spend 2000$, you'd need to send about 22TB, which are about 330M page loads.

> To spend 2000$, you'd need to send about 22TB, which are about 330M page loads.

That equates to 330M/365d = ~900k loads per day.

> it's now grown to about 6 million hits per day, and that's just the traffic that makes it through to the landing page [0]

So he's paying a discount, even.

[0] http://neverssl.com/changes

Re: NeverSSL

#108

"This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type " http://neverssl.com" into your browser's url bar, and you'll be able to log on." I don't get it. How does browsing to http://neverssl.com help you to log in to other websites?

You don't use a lot of hotel, airplane, airport, guest or otherwise captive portals do you? Most will gracefully redirect but a lot are painful. Add in things like HSTS (can't just go to Google), HTTPS Everywhere, etc and it's downright annoying to get to the portal.

NeverSSL is a huge frustration reducer, especially as I've been able to just tell less technical able co-workers to just go there.

Re: NeverSSL

#110
post #87
post #56

http://example.com is my captive portal triggering website go-to. IANA reserved and will be there when I need it forever .

Doesn't work for me, seems to fail to resolve. https://i.ibb.co/KmBk7DB/Screenshot-20191103-002332.png

your recursive resolver may be doing funny things. It's a valid and resolvable host:

https://www.whatsmydns.net/#A/example.com

Post reply on HN