Slashdot Mirror


Using Airport and Hotel Wi-Fi Is Much Safer Than It Used To Be (wired.com)

As you travel this holiday season, bouncing from airport to airplane to hotel, you'll likely find yourself facing a familiar quandary: Do I really trust this random public Wi-Fi network? As recently as a couple of years ago, the answer was almost certainly a resounding no. But in the year of our lord 2018? Friend, go for it. Wired: This advice comes with plenty of qualifiers. If you're planning to commit crimes online at the Holiday Inn Express, or to visit websites that you'd rather people not know you frequented, you need to take precautionary steps that we'll get to in a minute. Likewise, if you're a high-value target of a sophisticated nation state, stay off of public Wi-Fi at all costs. But for the rest of us? You're probably OK. That's not because hotel and airport Wi-Fi networks have necessarily gotten that much more secure. The web itself has.

"A lot of the former risks, the reasons we used to warn people, those things are gone now," says Chet Wisniewski, principle researcher at security firm Sophos. "It used to be because almost nothing on the internet was encrypted. You could sit there and sniff everything. Or someone could set up a rogue access point and pretend to be Hilton, and then you would connect to them instead of the hotel." In those Wild West days, in other words, signing onto a shared Wi-Fi network exposed you to myriad attacks, from hackers tracking your every move online, to so-called man-in-the-middle efforts that tricked you into entering your passwords, credit card information, or more on phony websites. A cheap, easy to use device called a Wi-Fi Pineapple makes those attacks simple to pull off. All of that's still technically possible. But a critical internet evolution has made those efforts much less effective: the advent of HTTPS.

60 comments

  1. Thankfully no one can MITM TLS by Anonymous Coward · · Score: 0

    Glad we have that covered - just canâ(TM)t happen according to Sopos.

  2. I recommend the Chinese wifi by WillAffleckUW · · Score: 2

    It comes with laptop maintenance, even if you don't ask for it.

    --
    -- Tigger warning: This post may contain tiggers! --
    1. Re:I recommend the Chinese wifi by Anonymous Coward · · Score: 0

      still safer than american maintenance that comes with forensics

  3. Re:The best use of airport wifi: by Anonymous Coward · · Score: 0

    We're all happy for you.

  4. Strange. by Anonymous Coward · · Score: 0

    I always thought the intention of free public wifi was to enable crime and create plausible deniability.

  5. Missing details by sanf780 · · Score: 1

    How should I connect to motherless for my daily dose of bestiality?

  6. Thanks Internet Man by Anonymous Coward · · Score: 0

    So I can use my credit card on public wifi again? Yay! I feel so free now that some stranger has said I shouldn't worry anymore!

    Thanks for looking out for me internet man!

  7. blank screen by AndyKron · · Score: 1

    Awesome. Wired is a blank screen when I click on it.

    1. Re:blank screen by Anonymous Coward · · Score: 0

      Are you using hotel wi-fi?

  8. Anything important has been encrypted for years. by Anonymous Coward · · Score: 0

    For anything important (let's say anything involving money, and even Facebook), https has been the norm for 8, maybe as many as 10 years. Before that, it wasn't terribly common, and wifi leaked everywhere. Sites like Slashdot didn't encrypt, or encrypted only credentials, so you could get clever tricks like ssl strip... but so what? Let the mast0|r H@k0|~ steal your slashdot credentials... so what?

    2 years ago there were a lot of not so important websites that you could snarf information from. Let's say newspapers, or advertising sites. Are you really concerned about that? Oh no someone knows what article I read on NYT, or knows the movie i looked up on IMDB!

    The problem with security people is they don't understand priorities, and real risks. They think EVERYTHING needs to be secure, and aren't familiar with tradeoffs. Is it better that almost everything uses https now? Of course. But don't over sell it. I'm not really terribly concerned that Wired didn't encrypt my traffic in 2016, and neither is anyone else. My Bank or Financial site however, better be air tight. (And many times it's TERRIBLE)

  9. Still don't trust it by jittles · · Score: 2

    Still don't trust public WiFi no matter how good the security of websites have become. And why should I trust it? There's no reason to. I can either tether to my phone or use the hotel WiFi. Cost to me is about the same. I'll use my phone unless I am in a foreign country and the WiFi is faster than my cellular data. But no matter where I am I always VPN to a "secure network" and use remote desktop to surf the web on a machine on that "trusted network." There's no need to trust someone else's network. Though once it leaves my LAN it ends up in an untrusted network regardless.

    1. Re: Still don't trust it by Anonymous Coward · · Score: 0

      Hint: the vast majority of the Internet is someone else's network.

    2. Re:Still don't trust it by Darkk · · Score: 1

      Using your own personal VPN connected to your home network or rather "secure network" is a good idea. Why bother with remote desktop to another computer connected via VPN when you can set your VPN client to route ALL traffic to the VPN server?

    3. Re:Still don't trust it by Anonymous Coward · · Score: 0

      Indeed I use a VPN service at home, in my home office, and when away from home.

    4. Re:Still don't trust it by jittles · · Score: 1

      Using your own personal VPN connected to your home network or rather "secure network" is a good idea. Why bother with remote desktop to another computer connected via VPN when you can set your VPN client to route ALL traffic to the VPN server?

      For a variety of reasons. My bank account websites do not allow me to connect with a new web browser without authenticating it. It also keeps the website history and other information off of the laptop in case it gets lost or stolen (assuming they can bypass disk encryption). Sometimes I just bring an iPad and this lets me use the desktop at home as a full fledged computer for the times when a mobile browser is not ideal. It really just depends on what I am doing and what I have with me.

    5. Re:Still don't trust it by brunes69 · · Score: 1

      What you say is true when in-country, but not when travelling. International data at LTE speeds is still expensive.

  10. Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

    ...who says, "my site only has recipes on it! Why do I need HTTPS?"

    It's not about you. It was never about you.

    1. Re:Queue Some TechnoLuddite by fwad · · Score: 1

      If you site only has recipes then you don't need HTTPS!

      HTTPS does two things
        a) Identify the remote site
        b) Encrypt the traffic

      If you are browsing recipes you do not need your traffic encrypted
      If you are browsing recipes then you need to be paranoid to require that a third party believes the remote site is who they say they are.

      --
      -- Kernel Panic: Error reading /dev/caffeine
    2. Re: Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

      *cue

    3. Re:Queue Some TechnoLuddite by manu0601 · · Score: 4, Informative

      HTTPS does two things

      You actually forgot a third valuable thing: content integrity. HTTPS makes sure a man in the middle cannot push a malware inside your recipe pages.

      And that is not a James Bond scenario. I have seen a Windows malware running on a PC and infecting the HTTP stream that passes within its reach.

    4. Re:Queue Some TechnoLuddite by swillden · · Score: 1

      HTTPS does three things
      a) Identify the remote site
      b) Encrypt the traffic
      c) Ensure the integrity of the traffic

      FTFY. And the item you forgot is just as important as (a), and generally more important than (b).

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    5. Re:Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

      HTTPS does not "identify the remote site" nor does it "authenticate the remote site". It does provide transport security (ie, encryption and integrity) between the two end points communicating (who may or may not be who you think they are).

      "Identification" and "Authentication" are not things withing the bailiwick of TLS (TLS stands for Transport Layer Security).

    6. Re:Queue Some TechnoLuddite by fwad · · Score: 1

      HTTPS does indeed authenticate the remote site via a chain a trust. This is why when you enter your banks address you can be confident that you really are talking to your bank and not a scam artist.

      --
      -- Kernel Panic: Error reading /dev/caffeine
    7. Re:Queue Some TechnoLuddite by fwad · · Score: 1

      In my head I was bundling this one up with a but I'll grant you this should be separate.

      However this doesn't get away from "it's a cooking recipe site FFS!". The evil plot by ninja hackers to insert too much salt into peoples cooking recipes and thereby kill off the entire western world will be exposed at last.

      I know people are going to talk about ads and tracking the cooking websites I go to so they can blackmail me of the chocolate browny recipes that I downloaded but this is just insane paranoia. Then the next group of people will say but how do I know that I'm getting the correct cookie recipe. Well I'm download a random recipe of the web written by someone I don't know from a website I just googled why should I trust this recipe at all HTTPS or not ? At the end of the day .. it's just a cookie recipe.

      --
      -- Kernel Panic: Error reading /dev/caffeine
    8. Re: Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

      If TLS wouldn't do authentication, MITM would be trivial.

    9. Re: Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

      Which, sadly, it is.

    10. Re: Queue Some TechnoLuddite by Anonymous Coward · · Score: 0

      *cue

      Maybe he wanted the TechnoLuddite to stand in line ...

  11. Who cares? by nospam007 · · Score: 1

    People who care switch on their VPN if it's isn't already on by default and the other get spied on by even more people than usual.

    A VPN costs about 5$month for usually 5 machines concurrently (PCs, cellphones, tablets...)

    1. Re:Who cares? by Anonymous Coward · · Score: 0

      How can you trust your VPN?

    2. Re:Who cares? by Anonymous Coward · · Score: 0

      Last time I checked (~5 months ago), _NONE_ of the current vpn providers protect you from local attacks. By that I mean they don't do even basic things like setup firewall rules blocking all but your gateway. Fact that you're connecting to a vpn at all can be enough to flag you.

      This article is really rather bizare.. Honeypot attempt or trolling?

    3. Re:Who cares? by will_die · · Score: 1

      The only problem with that is all those apps such as facebook, email, etc have already connected so they have sent your info, before you can get the VPN implemented.
      THe device connecting to the wifi would need to block all other traffic until the VPN is connected and there are very few things that do that.

  12. I disagree by OneHundredAndTen · · Score: 1

    It is very easy to set up a hotspot with a convincing name, that people will connect to. Do anything unencrypted in such a connection at your own peril.

  13. Surf with the security services by AHuxley · · Score: 1

    American and British Spy Agencies Targeted in-flight Mobile Phone Use (Dec 7 2016) https://theintercept.com/2016/... .
    Southwinds, Thieving Magpie and Homing Pigeon
    Canada had the wifi part covered.

    --
    Domestic spying is now "Benign Information Gathering"
  14. No End-to-End encryption == Not secure by Anonymous Coward · · Score: 0

    Who issues your trusted domain's HTTPS certificate? HTTPS is epic fail.

    https://news.netcraft.com/archives/2014/02/12/fake-ssl-certificates-deployed-across-the-internet.html

    1. Re:No End-to-End encryption == Not secure by Anonymous Coward · · Score: 0

      Basically, we have a gazillion trusted CAs and we trust certificates signed by all of these guys. If any of these trusted CAs are ISPs or government, you are very well vulnerable.

  15. Pass by nehumanuscrede · · Score: 1

    If I use a public WiFi, the very first thing I do is start a VPN connection up. ( My own server at home )

    If the WiFi disallows it, I disconnect.

    Easy.

    1. Re:Pass by KiloByte · · Score: 1

      If the WiFi disallows it, I disconnect.

      You may want to try iodine (tunnelling over DNS). Handles bogus WiFi pretty well.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    2. Re:Pass by Anonymous Coward · · Score: 0

      IoAC is better performing. See RFC-1149. Smoke signals also have higher bandwidth.

    3. Re:Pass by i.r.id10t · · Score: 2

      Last time I was at a conference center, the DNS request is what blocked your address and forced you to go off to the captive portal. Those of us who had IPs memorized (or a hosts file entry) could connect and SSH/VPN in direct, and once connected get DNS over the VPN/SSH tunnel.

      This of course made the PHBs jealous in the planning meetings (we were setting up to host a large educational conference) so this lowly geek who was wondering why he was even being sent to these meetings suggested "hey, we're about to write this place a check for how many hundreds of thousands of dollars and they want us to pay $20 each for WiFi while we plan this?" Amazing what a provost and college president can do for connections at conference centers... didn't know they had it in 'em.

      --
      Don't blame me, I voted for Kodos
    4. Re:Pass by Anonymous Coward · · Score: 0

      More like they were in on it but bailed the minute any link to them could even remotely be established. Welcome to corruption.

      Hilton got fined for intentionally jamming wireless so people had to pay their bs extortion fees for network access. Yet hotels still do it.

  16. It sure is! by SuperKendall · · Score: 1

    Of course in my case it's because I tether via phone instead of using airport or hotel WiFi.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  17. this is click bait by Anonymous Coward · · Score: 0

    Msmash, by your comments and the fact that your passing this as safe, if I get hacked this season, are you willing to take the liability?

    And if not for me, anyone else?

  18. The advent of... by Trogre · · Score: 1

    So HTTPS is a new thing now?

    Seriously, 2000, you can stop now.

    --
    "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
  19. pwn2own by Anonymous Coward · · Score: 0

    "A lot of the former risks, the reasons we used to warn people, those things are gone now,"

    What the fuck is this idiot smoking? Did he check week old news about pwn2own exploiting phones via captive portal page? HTTPS my ass.

  20. I was following until this by Anonymous Coward · · Score: 0

    "so-called man-in-the-middle efforts that tricked you into entering your passwords"

    What...?
    What the...?
    No. Just, no.

  21. serious? Liability and who's going to assume it? by Anonymous Coward · · Score: 0

    can you litterly see the crap as it falls from your mouth?

    msMash, you are doing this community a disservice now..

    you are promoting methods that are severely compromised.

    Your conveyance of this info is flawed to a HUGE degree.
    Your lacking in the context of your own articles, seems to know no bounds..
    The fact that your willing to promote an activity by people in your community that is fundamentally flawed exposes your lacking of understanding of the situation and how to promote a leadership role to resolve it, not to mention the liability carried by said comments.. /. are you willing to take responsibility and or liability for the crap that falls outta her mouth??
    Really is she that worth it?

    I am also reminded of a Sketch or Skit from the OLD saturdaynight live Crew Dan Akaroid and Jayne Curtain.
    Point/Counterpoint on the News segment in the middle of the show. I wont sink to the level and go through the description, but is is on youtube.
    Perhaps those whom decide to check it out for themselves could possibly draw the parallels, connect the Dots, and come to their own INFORMED conclusion..

  22. Airport Hotel Wi-Fi much safer than it used to be? by najajomo · · Score: 1

    No it hasn't, if your “computer” can still be compromised by opening an email or clicking on a weblink.

  23. Re: Anything important has been encrypted for year by Anonymous Coward · · Score: 0

    This just makes me wish there were more ways to get premium WiFi access. I waited on hold so long I went over my plan and the hold music stopped and I was prompted to get another plan. So now I have no plan and I pay roaming fees whenever I make a call. But then I saw a new all access plan from Verizon that comes with the iPhone SXY with the new AI smart logic so I am in line right now. The only problem is I have to pay these kids to go get me food across the street at the cart vendor.
    Someday I will take my new phone to a Chinese factory and I will learn to make a case for it an extra special case with little soarkles and stripes. But now I am roaming again so I must stop posting

  24. I never trusted ISPs more than hotels by Anonymous Coward · · Score: 0

    Who wanted to mitm DNS, inject ads, and throttle random protocols? Hint; not the people who live and die by actual reviews of the quality of their service.

  25. It was never a problem by gweihir · · Score: 1

    That is, given appropriate safety measures, like using secure shell or a VPN tunnel. You cannot and never could trust the network.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  26. This is how security SHOULD be implemented by Tony+Isaac · · Score: 2

    Done correctly, it should not be necessary to trust intermediate third parties, in order to have a secure connection. Who knows who is carrying your packets between here and Romania! Who even knows if your packets are going through Romania, on their way to Texas! This is the nature of the internet.

    Make it possible to establish a secure connection between two parties, and it doesn't matter whether you are using Joe Shmo's cell phone hotspot with an SSID of Denver International WiFi.

  27. Leaky by Bert64 · · Score: 1

    A lot of corporate laptops leak information when connected to other networks, they try to connect to various internal resources and in doing so disclose either the ip addresses or the dns names.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  28. Except at Work where https decryption is prolific by Anonymous Coward · · Score: 0

    Except at work of course where they use Bluecoat, Redcloak and Cylance to decrypt https with impunity. Workers rights zero as usual

  29. Re: The best use of airport wifi: by Anonymous Coward · · Score: 0

    |[]|
    |[]|
    |[]|
    |[]| flashing in middle of frame

  30. Not exactly by JoePete · · Score: 1

    I think the report misses the point. It's a bit like saying because more people are getting the flu shot these days, we don't need to wash our hands as much. The opportunity for attack over a public network has only increased. Sure HTTPS has reduced a subset, but it is far from an absolute cure-all. The folks most likely to trust a public access point are also the people most likely to ignore a certificate error for example. WPA2-PSK was designed to be used in a trusted environment (i.e. a home network). It was not designed where strangers would share the same the network - as it is done in every coffee shop, conference, etc. Off the bat, the moment you are on a shared network, you expose your device to scanning and attack. More you cannot know whether you have connected to a real access point or an attacker's laptop - unless you are talking certain WPA2-Enterprise options, there is no mutual authentication. Even when seeming to use HTTPS, there can be plenty of non-HTTPS packets/data that will leak. Further HTTPS is not like a VPN encrypting all network traffic. It just handles a specific browser-to-server subset. Yes, on one hand things are better, but on the other, WiFi is so much more prevalent today - we have WiFi enabled diapers for cripes sake - that the overall vulnerability of the average wireless user has only increased.

  31. A problem by Anonymous Coward · · Score: 0

    I used to travel 9 months out of the year and stayed in motels continuously. I remember many times when first connecting to motel wifi system, a message would popup saying that I needed to install some software to use it. I was always suspicious of that and never did. Just after canceling the requirement request, I would be connected to the wifi system anyway. This fake software install requirement ended up being a worm that had been installed on many motel wifi computers.