Live data from Hacker News

What we give away when we log on to a public Wi-Fi network

decorrespondent.nl

1–10 of 112 posts

Re: What we give away when we log on to a public Wi-Fi network

#5
post #4

Are my devices really broadcasting the SSIDs they have been connecting to?

You could brute force it by using common network names and seeing which ones get bites. Take it a step further and generate expected patterns ie. "2WIRE123". I'd expect "linksys" alone would grab a surprising amount to start, though.

Re: What we give away when we log on to a public Wi-Fi network

#6
How was the hacker able to get Facebook credentials? Facebook uses HTTPS and so does Live.com. Even if I'm connected to a malicious router, only me and Facebook know about the data we're sending each other.

Am I missing something or should the author of this article provide more evidence on the type of attack?

Re: What we give away when we log on to a public Wi-Fi network

#8
post #6

How was the hacker able to get Facebook credentials? Facebook uses HTTPS and so does Live.com. Even if I'm connected to a malicious router, only me and Facebook know about the data we're sending each other. Am I missing something or should the author of this article provide more evidence on the type of attack?

sslstrip might explain that, but don't most major sites use HSTS these days?
Post reply on HN