Hacker News new | past | comments | ask | show | jobs | submit login

There should still exist one well-known unencrypted page. Sometimes, I need to log in to hotel or airport wifi and therefore need to accept a MitM attack. I would prefer this not to be the case.



Apple products use this one for hotspot detection:

http://captive.apple.com/hotspot-detect.html

I just have it bookmarked now. It's the one bookmark I use.


Hotel or airport wifi operates in that way because they can do so without inconvenience too many customers. If it becomes too cumbersome that they need to send in a technician every time a customer is not a sysadministrator who can figure out how to get the wifi to work, then market forces will make sure that they use something else.



I use http://xkcd.com, but that works.


What would one well-known unencrypted page do to mitigate that?


If you go to a http page, and haven't logged it, it will redirect you to the login page. If you try that over https, it just fails.


Oh, now I feel dumb, I thought this was a security comment and not a practical one. Thanks for clarifying.


The solution for all wifi clients is to do what iOS and Mac OS X has been doing for years, which is validate internet connectivity when connecting via wifi. If there's a captive portal standing in the way, it pops up a simple webkit view automatically. You don't even have to open a web browser.

It would be nice to have a more formal standard (e.g. supplying an authentication URL along with the DHCP response) but to be honest, this emerging de-facto standard is perfectly serviceable.


> you don't even have to open a web browser.

It would be nice if that worked consistently, but having just spent 2 weeks in airports and ho[s]tels in the UK & Ireland, it doesn't yet.


On the rare instances where it has failed me, I have diagnosed the problem to be the router allowing (or faking, not sure) a success response from http://captive.apple.com/hotspot-detect.html

If anyone has coded a captive portal to behave differently when it sees captive.apple.com they should be ashamed. All they're doing is making life difficult for everyone unnecessarily.


Google should do it on 8.8.8.8 just to make it more famous, but in general think about the meta websites defined in the W3C/IETF standards, such as: http://example.com


My go to is http://google.org.

Along with the 100 million in grants they write yearly, they provide a valuable social service for those more fortunate.


I use http://purple.com for this. It's easy to remember and always up.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: