MoritzGiessmann, German
@MoritzGiessmann@mastodon.social avatar

I spent a considerable amount of time in WiFi captive portals.

freddy,
@freddy@security.plumbing avatar

@MoritzGiessmann Did Firefox's portal detection kick in? If so, did it help you? If not, do you know why?

MoritzGiessmann,
@MoritzGiessmann@mastodon.social avatar

@freddy I did not use Firefox. On iPhone it’s a Safari web view I guess and the same on MacOS I guess?

madonius,
@madonius@chaos.social avatar

@MoritzGiessmann How many of those were trivial to circumvent?

MoritzGiessmann,
@MoritzGiessmann@mastodon.social avatar

@madonius I’d say about 40% were just clicking a button or checking a checkbox before that. About 30% required more data like a name, mail, phone number where most of the time fake data like bla@example.com worked well. Some of the nasty ones verified mail addresses. Some by magic, a few by actually sending a mail with a verification link…

madonius,
@madonius@chaos.social avatar

@MoritzGiessmann I've had situations where the captive portal permitted UDP/53 and my VPN could just connect 🤷‍♂️

MoritzGiessmann,
@MoritzGiessmann@mastodon.social avatar

@madonius I should’ve tried that.

MoritzGiessmann, (edited )
@MoritzGiessmann@mastodon.social avatar

@madonius Some required actual cell phone numbers from a specific country and the worst were the: “you can have 300mb of data and after that you have to pay $BIGDOLLAR to get more”, which raised the question of how they actually identify recurring devices (afaik the iPhone sends chaning MAC addresses?).

cy,
@cy@chaos.social avatar

@MoritzGiessmann @madonius maybe they just tie it to the single session and hope people dont use a device with such a feature?

MoritzGiessmann,
@MoritzGiessmann@mastodon.social avatar

@cy @madonius I am sure they could identify my device multiple times in multiple captive portals. It would be interesting to find out how they did it. Unfortunately I could not find a simple way to debug the web views to see if they use any web trickery.

cy,
@cy@chaos.social avatar

@MoritzGiessmann @madonius technically they could do stuff like browser fingerprinting while you access the captive portal (?)
i don't know how the client handles the portal, but i guess its a http services, so it probably falls back to safari?

MoritzGiessmann,
@MoritzGiessmann@mastodon.social avatar

@cy @madonius Yup, but Safari web view. That’s probably sandboxed somehow.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • ama
  • thenastyranch
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • ethstaker
  • Youngstown
  • mdbf
  • slotface
  • everett
  • rosin
  • ngwrru68w68
  • kavyap
  • khanakhh
  • cubers
  • provamag3
  • tacticalgear
  • osvaldo12
  • GTA5RPClips
  • cisconetworking
  • modclub
  • Durango
  • Leos
  • normalnudes
  • megavids
  • tester
  • anitta
  • JUstTest
  • lostlight
  • All magazines