Live data from Hacker News

NeverSSL

fdbhclmrkstnvwxz.neverssl.com

51–60 of 206 posts

Re: NeverSSL

#51
Huh, I've had that problem before but recently found that if you visit a local (non-routable, I guess) address then it picks up the captive portal.

For me that means type "1", the browser fills the rest, hit enter: boom, captive portal.

YMMV, of course.

Re: NeverSSL

#52
post #35

http://example.com also does this, albeit without the promise of never switching

In both Chrome and Firefox, when I type "example.com" into the URL bar, I go to https://example.com , probably because I've visited the https site before and they remember that. So I do not recommend example.com .

I don't think the IANA domains make use of HSTS or anything of the like.

    HTTP/2.0 304 Not Modified
    cache-control: max-age=604800
    date: Sat, 02 Nov 2019 22:22:19 GMT
    etag: "3147526947+gzip"
    expires: Sat, 09 Nov 2019 22:22:19 GMT
    last-modified: Thu, 17 Oct 2019 07:18:26 GMT
    server: ECS (sjc/4E71)
    vary: Accept-Encoding
If you type "example.com" into the URL, both Firefox and Chrome will try HTTPS first. If you want plain HTTP, you just need to ask for it: "http://example.com"

Re: NeverSSL

#53

"This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type " http://neverssl.com" into your browser's url bar, and you'll be able to log on." I don't get it. How does browsing to http://neverssl.com help you to log in to other websites?

On some public wifi networks, you need to load a captive portal page and hit a button (usually to accept terms and conditions) before network to route you to any actual sites. The network often enforces this by redirecting you to that page whenever you try to visit something else. However, this doesn't occur properly when accessing a page with HTTPS. The easiest way to to directly to to the captive portal is to try to go to a non-HTTPS site, but fewer and fewer sites provide this (for obvious securityv reasons). The purpose of this site is to provide an easy-to-remember domain that the owner guarantees will never use HTTPS so that users of such networks can type it in as a way to load the captive portal. I've used it a number of times when using wifi on Amtrak trains.

Re: NeverSSL

#54
post #38

So, sites like this are useful. (It's certainly better than memorizing the URL that various hotels use for their wifi portals, which I have done before, sadly.) But is there anybody working on solving this problem transparently to the end user? It seems user-hostile to require people to remember a non-HTTPS URL, especially as more and more sites move.

> But is there anybody working on solving this problem transparently to the end user?

Yes. RFC 7710 defines a DHCP option to supply a URI for a captive portal page.

https://tools.ietf.org/html/rfc7710

Re: NeverSSL

#55
post #53

"This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type " http://neverssl.com" into your browser's url bar, and you'll be able to log on." I don't get it. How does browsing to http://neverssl.com help you to log in to other websites?

On some public wifi networks, you need to load a captive portal page and hit a button (usually to accept terms and conditions) before network to route you to any actual sites. The network often enforces this by redirecting you to that page whenever you try to visit something else. However, this doesn't occur properly when accessing a page with HTTPS. The easiest way to to directly to to the captive portal is to try t…

Apple devices try to go to http://captive.apple.com/ for this purpose.

Re: NeverSSL

#60

My favorite to use is http://perdu.com/ I don’t know where I found it, but it’s charming!

I’ve used http://www.fake.com for years just because it worked. If that London-based artificial plant company ever goes out of business, I don’t know what I’ll do! ;)
Post reply on HN