4 ms·
If you’re using a mainstream OS that automatically detects standard captive portals, the main reason why you’ll need this is for “tiered” captive portals like t
by m0dest 7y ago
If you’re using a mainstream OS that automatically detects standard captive portals, the main reason why you’ll need this is for “tiered” captive portals like the ones offered on some airplanes.
Those tiered captive portals have unique requirements that conflict with OS behavior:
A) By default, they want to offer some limited Internet access, such as accessing a sponsored site (often a shopping site like Amazon) or streaming videos (from some server on the airplane LAN).
B) For premium, paying users, they want to offer (mostly) full Internet access
For this to work, they have to fool devices in Tier A into believing that they have Internet access, by spoofing responses from standard captive portal detection URLs like captive.apple.com. Otherwise, if the network fails the captive portal test, many devices won’t stay connected to the Wi-Fi network, preventing access to the sponsored sites or LAN streaming apps.
At the same time, they want users to be able to upgrade from Tier A (limited access) to Tier B (full access) at any time. So they enable these upgrades by serving a captive portal page... to every HTTP site _except_ the standard OS captive portal detection pages that would affect OS behavior.
That’s when the user needs to visit an HTTP site other than the standard captive portal pages. One like neverssl.com
It’s obviously a fragile solution and is becoming an increasingly poor experience as sites adopt HTTPS, HSTS, and other standards. At the same time, I don’t know of any upcoming solutions to the tiered captive portal problem. Does anyone know what should replace this?
- danShumway 7y agoAdding another question on top of this, does anyone know how widespread DNS over HTTPS affects this model? I guess you could do filtering based on IP address, but that seems really fragile as well? I'm guessing that the way it works today if you're pointing to a non-standard DNS server like Cloudflare's, is that the portal still just intercepts and modifies those requests anyway.
- 2arrs2ells 7y agoI’ve found that non-standard DNS often prevents access to WiFi portals. Removing the Google/Cloudflare dns settings is step # 2 in my public WiFi debugging checklist (after trying to visit neverssl).
- conradev 7y agoThe closest thing I know of is Wi-Fi Passpoint: https://www.wi-fi.org/discover-wi-fi/passpoint https://www.wi-fi.org/discover-wi-fi/passpoint but I think it lacks the features necessary to do tiered auth
- mttpgn 7y agoI've also used the site to demonstrate cURL and GET requests on a basic level, since there's no TLS handshake to gum up the simplicity of seeing simple HTML returned from a barebones CLI command.
- ay 7y agohttps://tools.ietf.org/html/rfc7710 https://tools.ietf.org/html/rfc7710 tries to solve this at network level..
- m0dest 7y agoUnless I’m missing something, RFC7710 doesn’t offer anything to address this “tiered” captive portal scenario; it just provides a less vendor-dependent protocol for the captive portal checks that are already being performed by the OS.
- tristor 7y agoThanks for this comment, because it explained something I've had passing curiosity about but never bothered to fully investigate or understand. I've been using NeverSSL for ages, but only in one specific scenario, which is in-flight WiFi. I travel a lot so it manages to stay in my top sites, but every other public WiFi network works fine without that workaround. Considering how brittle this solution is, I wonder what airlines are going to do next?
- gpvos 7y agoBut how do you discover which sites are available on the free tier? Better to just serve the portal page to everyone, inform them, and let them select. Although actually I would like all those portal pages to disappear.
- xmodem 7y agoHow do you serve the captive portal page to a user if you don't control a valid certificate for it and it uses HSTS?
- marcosdumay 7y agoFor those, you create a portal URL on a domain you own, and let people upgrade from there. The URL is usually written on the same material that tells you that wifi is available, that you can buy full access and that some sites are free, but it would be even better if your main site also showed a link for upgrading the network (I have never seen this one on practice).