For the number of engineers they have you'd think they'd have figured out how to build a decent wifi network with some actual security in it. Instead every WeWork has the same password for the wifi (literally a variant on `P@ssw0rd`) and it is super easy to spy on other people's connections. The hilarious thing is they actually built a secure wifi network for their staff, so they clearly recognize the need. They also…
I thought I knew this stuff, but now I'm not so sure anymore. If I take care to only visit https sites, what's the risk in being on an open network or a network with a stupid password? They can see what domains I connect to and when, but that's it, correct? No MITM, no further snooping, right?
Once an attacker is in your network, it's more or less trivial to make that software connect to a malicious update server.