7 ms·
Want to use my wifi? (2013)
- GranPC 9y agoMirror: https://web.archive.org/web/20180104070103/https://thejh.net/written-stuff/want-to-use-my-wifi https://web.archive.org/web/20180104070103/https://thejh.net...
- superdaniel 9y agoThanks
- dang 9y agoDiscussed at the time: https://news.ycombinator.com/item?id=6766106 https://news.ycombinator.com/item?id=6766106
- craftyguy 9y agoSo using HTTPS seems to mitigate everything in this article?
- bonyt 9y agoWell, sslstrip still likely works on websites that don’t use HSTS, or that you’re visiting for the first time. I suppose the HTTPS Everywhere plugin might mitigate this. Do any browsers try https first yet? Now that I think of it, I guess many search engines now use HTTPS with HSTS and will send you straight to the https site if it knows of one, so that’s good. https://moxie.org/software/sslstrip/ https://moxie.org/software/sslstrip/
- geofft 9y agoIf I'm using a wifi network I don't really trust (coffeeshops, airports, etc.), I'll turn on HTTPS Everywhere and further enable "Block all unencrypted requests," effectively giving me "HTTP Nowhere." This works for most things - for a few things I'll open an incognito window in Chrome, which simultaneously turns off extensions and doesn't send my original cookies, and I'll be careful about what I do in that window (certainly no logins to sites I care about). This is generally enough for e.g. reading some random news site that doesn't support HTTPS at all.
- delish 9y agoCan I ask why you don't [seem to] use a VPN? The reason I ask is, I'm under the impression that a VPN definitively mitigates this kind of attack. I'd have to change my habits if it turns out a VPN is not a one-stop-shop solution for this kind of attack. And, in case convenience matters to you: an enabled-by-default VPN is also less configuration and fewer manual steps than turning on HTTPS everywhere and blocking all unencrypted requests.
- geofft 9y agoI haven't evaluated VPN providers enough to decide if there's one I trust. An evil VPN (or an insecure one taken over by evil people) is in an extremely easy position to MITM my HTTP traffic: it's technically easier than MITMing wifi traffic, and they also know my identity (either because I paid with a real-world identity, or they have logs of where I'm connecting from and what I'm connecting to). For performance reasons I don't want an always-on VPN; I trust my home wifi, my phone's hotspot, etc. at least as much as I trust any VPN I could use, so I wouldn't get any benefit from it. I suppose the thing I should actually do is route over an SSH SOCKS tunnel to some server I control, which would work fine. (A thing I have wanted for a while is a configuration that does this for HTTP and lets HTTPS through normally for performance, which now that I think about it, I can probably just write a proxy PAC file to do ... thanks, I'll see if I can improve my setup.)
- js2 9y agoUse Algo on a droplet.
- shujito 9y agohow secure is it?
- laumars 9y ago> I suppose the thing I should actually do is route over an SSH SOCKS tunnel to some server I control, which would work fine. This is what I do. The only danger with that over a regular VPN is anything not part of your browsers standard stream will not be sent over the proxy. This includes browser plugins as well. Thankfully Flash and Java are generally disabled by default, but it's still worth baring that limitation in mind. Despite this, SSH SOCKS is still my preferred method as well.
- IncRnd 9y agoNo. That is only the case when the certificate is pinned, which is the proper mitigation in this case. VPNs do not have stellar records regarding security.
- confounded 9y ago> VPNs do not have stellar records regarding security. I rely on them. Can you elaborate?
- IncRnd 9y agoSure. You can take a look here to see some common issues with VPNs. https://www.theregister.co.uk/2016/02/26/ssl_vpns_survey/ https://www.theregister.co.uk/2016/02/26/ssl_vpns_survey/
- barbegal 9y ago>Probably the easiest, yet most powerful one is to only use the browser in incognito mode while surfing on insecure networks. This way, no information (like passwords or cookies) can leak out and no evil cache entries can sneak in. Is only partially true. If you sign in using incognito mode your passwords and cookies will leak. And you have to remember to open the incognito window after connecting to an insecure network and close it before you connect to a secure network because the cache and cookies are maintained until you close the window.
- bonyt 9y agoHere is an interesting dilemma: should HSTS persist in incognito mode? If not, then this becomes bad advice, because all the attacker has to do to disable HTTPS is not redirect http sites to https ones (sslstrip). If so, then the list of sites for which your browser attempts HTTPS connections without being told to is the list of sites you’ve accessed in the past. This information could become a supercookie allowing sites to identify and track you even in incognito mode. https://nakedsecurity.sophos.com/2015/02/02/anatomy-of-a-browser-dilemma-how-hsts-supercookies-make-you-choose-between-privacy-or-security/ https://nakedsecurity.sophos.com/2015/02/02/anatomy-of-a-bro...
- Klathmon 9y agoUnless the website makes use of HSTS preload
- varenc 9y agoThis is possible! HSTS does apply to incognito to my knowledge Here’s a project that uses this fact to look up browser history: https://github.com/diracdeltas/sniffly https://github.com/diracdeltas/sniffly
- crunchatized 9y agoAt least it only works on chromium-based browsers. Firefox fixed the supercookie problem when opening up a private browsing session back in Firefox 34.0.5 after it was discovered. Which then makes the HSTS preload list and HTTPS Everywhere extension all the more valuable to defend against active attacks.
- drdrey 9y agoWhat about browsing over tor?
- Viper007Bond 9y agotor isn't a VPN service, it's an anonymizer. The end node could still sniff your traffic presumably.
- drdrey 9y agoYeah but that would protect you from the insecure wifi attacker, no?
- IncRnd 9y agoNo, it wouldn't. You still need to protect that you are connecting to the wifi access point and not a spoofed one, due to arp or DNS poisoning.
- icebraining 9y agoWhy? Protocols like Tor and HTTPS include authentication layers just to make sure your connection is secured even over an insecure channel.
- IncRnd 9y agoGreat question. I used the word "to" when it is more correct to use "thru" the AP. You need https for cert pinning, so when I mentioned cert pinning that automatically included https. The reason to pin the certificate is to ensure that the server certificate presented today is the same server certificate that was seen yesterday. Otherwise the server may be spoofed and still pass the certificate checks. This is generally mitigated via certificate pinning. See Twitter's history and implementation of such. I am not saying to NOT use another layer on top of this, as defense in depth is always important. There are ways to get around VPN use and ways to get around cert pinning, but using both makes the attacker's job far more difficult. Implementing cert pinning is something that needs to be done by app developers, and what you mention are definitely good first measures one should take to protect their OWN systems in a hostile environment. By themselves, though, they don't completely mitigate all threats in the threat model.
- chakalakasp 9y agoHow I Learned to Stop Worrying and Love the VPN
- dannyw 9y agoAn even easier way is to subscribe to a reputable VPN. There are often various sales where you can pick up annual packages at steep discounts. Having a VPN is also useful for troubleshooting network connectivity, and bypassing content-based throttling. I like Private Internet Access.
- js2 9y agoRun Algo on a droplet. https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-that-works/ https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th...
- shujito 9y agohow secure is it?
- thinkloop 9y agoAny reason to use droplet in particular over other vms?
- js2 9y agoNot particularly. Droplets are $5/mo and very easy to set up.
- paulgerhardt 9y agoThe price is competitive but I've found another important factor when VPN shopping for VMS's is if that data center tends to be abused by scraping projects. Craigslist for instance is very slow when accessing via a VPN on Digital Ocean but quick when accessed via one hosted on Rackspace. Google Scholar may send you through captcha hell for 10 rounds or so every few minutes if you're hoping on from a fishy ip. The only time I had trouble with sites protected by Cloudflare was when viewing through Tor or AWS.
- radec 9y agoDoesn't seem like this would be as anonymous as something like PIA....assuming you can trust pia. Still thanks for the idea, going to look into it more.
- IncRnd 9y ago> Probably the easiest, yet most powerful one is to only use the browser in incognito mode while surfing on insecure networks. This way, no information (like passwords or cookies) can leak out and no evil cache entries can sneak in. This isn't true, as incognito can leak cookies. The proper mitigation is for site and app designers to use cert pinning.
- f4rker 9y agoopera (and vivaldi?) have built in free vpns
- ce4 9y agoFYI, this piece is from Jann Horn - known for the recent intel cpu bug disclosure at Google project zero.
- leni536 9y agoI believe that it's that site's responsibility to set the cookie's secure attribute. Otherwise I'm surprised nobody mentioned disabling 3rd party cookies as a mitigation on the client side. Using a VPN provider, a VPS or even your self-hosted VPN in your home (your home ISP) is just choosing who you trust.
- dspillett 9y agoMy solution has always been to use a VPN, not just on an untrusted network but on any wireless network (for any comms using an insecure protocol any wireless network, even one run by yourself to the highest standards, is an untrusted network anyway). When WEP was broken it didn't affect me because the WLAN was just a transport and my traffic was protected by the VPN. When WPA was broken it didn't affect me because the WLAN was just a transport and my traffic was protected by the VPN. Of course this creates two problems which make it impractical for the man-on-the-street: choosing the solution and host (in my case OpenVPN with end-points running on my home network and a hosted VM as a backup in case that link is down) and keeping yourself (your server, your client, your configuration) up-to-date as new exploits are found. But I'm not a man-on-the-street in this instance so it works for me. There are a number of solutions that claim to provide out-of-the-box methods that the untrained can use without any effort, but there is still the "which service do I trust?" issue to contend with from both security and reliability points of view. A side problem is client support on devices, particularly mobile phones, though from my selfish PoV that is a lot easier now: OpenVPN seems reliable on my Android devices, Windows Phone is effectively dead, and I never had an iDevice so haven't needed to care. The final problem is a human one: remembering to turn it on if you don't have ti on all the time automatically. The same works when providing wireless access to or via a network you care about, such as wireless access in an office environment. The access point could be left as open as open can be (though security in depth: there is no harm in turning WPA2 on as an extra layer of protection) but don't let it route anything that doesn't look like your VPN traffic and let the VPN handle security. If you need to provide wireless access for guests (visiting clients for instance) have a separate WLAN with all the usual protections that doesn't route to your other local network legs at all (without going out and back in via a VPN of course). Beyond that, their security is their problem.
- aglionby 9y agoI'm with you on the majority of your comment, but I'd contend that VPNs are definitely accessible for your average person, assuming they're are actually aware of them and how they help. Sure you don't get the same guarantee regarding logs etc. if you use a commercial option instead of rolling your own, but that's a different threat to the one described in the article. In terms of trust, I'm happy going with bigger names which have more to lose if they turn out to not be doing what they say. Private internet access (no affiliation) for me ticks this box, is a really simple install on my phone + laptop, and has anonymous payment methods as well if that's something that's important to you.
- bclemens 9y agoAll of this and more has been explored with BEEF. An easy way to demonstrate these sorts of attacks is with BEEF + MITMF. http://beefproject.com/ http://beefproject.com/ https://github.com/byt3bl33d3r/MITMf https://github.com/byt3bl33d3r/MITMf
- Bromskloss 9y agoAren't all these problems that exist for all unauthenticated traffic, wifi or not?
- deleted 9y ago[deleted]