4 ms·
Well https takes care of that. The hotel might be able to see that you visited a certain website but thats about it.
by LordHeini 6y ago
Well https takes care of that.
The hotel might be able to see that you visited a certain website but thats about it.
- nicoburns 6y agoAsssuming they don't MITM your connection.
- bzb6 6y agoWhich you would notice immediately because of the big, scary warnings.
- nicoburns 6y agoRight, but how do you respond to that? Using a VPN seems like a reasonable approach in this situation.
- LiberatedLlama 6y agoIt's a hotel right? I would respond by closing my laptop, then my eyelids, then checking out the next morning.
- monocasa 6y agoYou respond primarily with non technical means, making a giant stink that a hotel that generally lives and dies on corporate money is man in the middling their WiFi.
- LordHeini 6y agoAssume my hotel has some MITM running with the right (broken) certificates and so on. Which is not that trivial to begin with. How hard would it be to take over the dns and simulate a fake VPN too? Or just constantly disconnect the vpn and hope the user stops using it for a while.
- lr4444lr 6y agoPresumably, you exchanged certs with the actual VPN over a known secure network prior.
- hahajk 6y agoAnd how would they do that? Your browser should warn you the certs aren’t trusted.
- nicoburns 6y agoAnd if your browser does warn you: what do you do? You use a VPN.
- VectorLock 6y agoYou have now shifted your trust from your VPN provider to certificate authorities. And, I guess, just ignore anything thats not https. Or just be okay if your hotel blocks certain ports or destinations, which I've had happen multiple times.
- hiq 6y ago> You have now shifted your trust from your VPN provider to certificate authorities. Don't you have to trust the CAs in any case?
- rasguanabana 6y agoWell, http(s) isn’t the only traffic going through network.
- seppin 6y agoIt is for 95% of websites most people use.