3 ms·
The coffee shop router is the thread. Whether it's the coffee shop owner, an employee, somebody who hacked the router or just somebody who tricked you into goin
by chronial 6y ago
The coffee shop router is the thread. Whether it's the coffee shop owner, an employee, somebody who hacked the router or just somebody who tricked you into going into their WiFi which is not actually the coffee shop's.
- ancarda 6y agoI don't have data on this, but I suspect usage of public Wi-Fi is going to keep declining in favor of cellular data as it becomes cheaper and data caps rise/go away So, in that case, would TLS still be useful? It just seems like quite a lot of effort to ensure TLS everywhere because a small number of people use untrustworthy Wi-Fi networks
- cheph 6y ago> So, in that case, would TLS still be useful? Because again the scope of encryption offered by wireless operators is different from TLS. It is like asking if encrypting your disks makes TLS pointless. TLS encrypts traffic between your computer, and some resource on the internet. WPA3 encrypts communication between your computer and the wireless access point, no further. The wireless provider's encryption will similarly only encrypt data between your device and the wireless provider's equipment. They are not designed to do the same thing. Technically WPA3 and and other wireless networking encryption is not needed if you are using TLS, because the scope of encryption of TLS covers the data going to your wireless provider or the wireless access point, but not everything is TLS - and even TLS still leaks DNS in many cases. And even if it was not leaking DNS there are still things that would be better for others to not know when you are using TLS.
- kzrdude 6y agoJust out of curiosity, I wonder how many layers of encryption one can reach in a day-to-day usage scenario.
- kzrdude 6y agoTLS keeps the traffic secret between the client and the server. Encryption on part of the transport - like the cellular net - only covers part of the journey, and is out of your control. It's the difference between sending a box locked or not - the box is routed between different operators and terminals.
- rndgermandude 6y agoI still regularly use Wifi, e.g. on trains in rural areas, because mobile data is a lot more unstable there compared to the train wifi, especially at speed in rural areas. (Trains here usually have better antenna and often uplinks to multiple carriers) Then the mobile carrier/ISP is the threat. I personally do not really trust those DSLAM boxes scattered all around my city, often readily accessible by everybody with the right key/lock pick. E.g. I know the DSLAM box that is serving my house, and I can just walk up to it. And every other hop between you and the destination is the threat as well, and every person having enough access to any such hop, from company employee to external attacker. Also, did China route half the internet through China again, by "accidental" buggy BGP routes. And don't forget your own router, which is a threat (once hacked). Or that "smart" lightbulb or other IoT device in your LAN that may be able to listen to your all your Wifi communication at home depending on your setup. TLS isn't "a lot of effort", it's a minor computational cost e.g. compared to the energy you use to display ads you don't want to see, and end-users do not have a hard time using it. It's a tiny bit of burden for server operators, tho letsencrypt/ACME made it a setup-once kinda thing for a lot of people.