11 ms·
Captive Portals
- Ellipsis753 4y agoLet's plug one of my "joke" domains: http://amibehindacaptiveportal.com http://amibehindacaptiveportal.com If you get any response other than "No" then you're behind a captive portal.
- stop50 4y agoToo bad there is no standard that is used to prevent these workarounds.
- CGamesPlay 4y agoIndeed. This should really be the responsibility of the Wifi stack, which imposes the restriction and sits on a lower level than the HTTP stack. My gopher connections never work when I am behind a captive portal!
- stop50 4y agoThere is the standard 8952. But it nowhere implemented yet. it uses https, dhcp and ra to give the client the captive portal information.
- captivehacker1 4y agoIt is though. I've implemented a captive portal that uses this successfully for sending modern mobile OS like Android and iOs through captive portal. Marcos works fine too, also newer windows.
- LtWorf 4y agoMany of those networks block most ports except http, https basically.
- wichert 4y agoThe WISPr[0] standard was created for this purpose, and is (or was by now?) used by companies such as iPass to their customers to transparently log in to most WiFi hotspots. I don't think that standard is accessibly anywhere these days. I made a Python implementation [1] that should still work. [0] https://en.wikipedia.org/wiki/WISPr https://en.wikipedia.org/wiki/WISPr [1] https://github.com/wichert/wispr https://github.com/wichert/wispr
- lukeboi 4y agoThere is a dhcp option that can be used as an alternative that was recently (~2yr ago) introduced but it’s not supported by any major OSes except android
- captivehacker1 4y agoIt took some time to adopt, but works at least on recent mobile OS and MacOS.
- stop50 4y agoThere is rfc 8952, but its not official yet. Including the others which are referenced. The dhcp option is also not official yet.
- bhhaskin 4y agoI currently live on a boat. Dealing with captive portal bs from the marine is always a nightmare. You have to buy the correct wifi extender/repeater otherwise you have to connect each device directly to the network.
- voltagex_ 4y agoWhat repeater worked for you?
- gingerlime 4y agonot OP but I’m using a GL.iNet travel router. It’s tiny. USB powered so can be plugged to a power bank. It has an Ethernet connection as well, can use your phone’s tethering as well. Great little gadget for travel.
- voltagex_ 4y agoI found the GL.inet gear underpowered, although I've only used their cheap stuff and finicky re: firmware -the last one had removed OpenWRT luci by default
- 3np 4y agoThe firmware is a huge mess and it's especially unfortunate that there seems to be some undocumented custom drivers or something else I haven't been able to identify yet which is missing from upstream OpenWRT, making it unusable for certain of their devices. The gl.inet firwmare itself has a lot of missing updates and I am yet to successfully make custom builds of it (though in theory it should be possible through what's on their public Github repos, save for a handful of packages they provide as binary-only). They do not respond to issues or PRs on GitHub. I should have taken better notes on building a firmware but I think what eventually allowed me to replicate and make custom build was to just build as if a normal openwrt dist from https://github.com/gl-inet/openwrt https://github.com/gl-inet/openwrt with a fork of https://github.com/gl-inet/gli-pub https://github.com/gl-inet/gli-pub. Ended up ditching their custom hacky wireguard/tor functionality and mostly treating it as an openwrt dist. Still stuck on a fork of the custom 19.07 (4.x kernel) for E750 (despite my efforts to bring it to 21.02). MT1300 doesn't seem to have had any issues on vanilla openwrt 21.02, though. The mwan3 stuff can be worth keeping and extending on using the uci module, though. It really is a shame as there are so many great things with the E750 and it has potential to be the perfect travel router. If there is anyone else who wants to take this to the next level, I could be down for making this ore structured and collaborate on making a more open, accessible, secure and hackable dist either just for the E750 or glinet in general.
- nurgasemetey 4y agoIf captive portal is not opened in Linux, find gateway IP and paste this IP in the browser. It will open captive portal.
- benknight87 4y agoI kind of hope one day personal data plans render public wifi obsolete. Every time you connect to a new wifi network you just never know what awaits. It might be a slow connection, it might be a shitty device that only kind of works, it might be a security nightmare… Wouldn't it be great if all our devices, laptops, tablets, mobile phones, had digital SIMs and we could just purchase a single data plan for all of them!
- vladvasiliu 4y agoI think we're getting there in some countries, at least for "mobile" needs (read: when outside the home / office). In France, I have a 40 GB mobile plan for €10. I know I'm likely below your average phone user, but the most I used out of this was about 4 GB when my home connection was dead, and I was working from home. If I'm not mistaken, an 80 GB plan is less than €20. To me, that's basically unlimited. I can get an extra SIM for €2 a month attached to the same plan. I never bothered because an internal WWAN card for my laptop is outrageously expensive, and since I don't need it often, I just share from my phone.
- BlueTemplar 4y agoEven more relevant perhaps : how many of these plans allow you to piggyback on the closest router's guest connection (from the same ISP) as long as you are in Wifi range. (Some of these routers even work as mini cell towers !)
- vladvasiliu 4y agoI think that's usually the case, but it's not transparent. You'll have to connect to a specific SSID and enter some credentials which aren't always your usual credentials and / or use some app. I've tried this once or twice a few years ago, but it was so slow that I went back to using my mobile plan.
- bigiain 4y agoI used to be involved in the captive portal at Marvel Stadium in Melbourne (previously Etihad Stadium). Usage is _very_ demographically aligned. At football games, we’d see connected device numbers somewhere around 10% of ticket sales. At a Justin Bieber show it was over 90%. I have always had more mobile data available than I need, and I can’t remember the last time I bothered using a venue’s wifi (that wasn’t for work/testing purposes) Back in the pre-Netflix days here I .au, I used to have a Raspberry Pi with a USB wifi dongle and a high gain antenna pointed at the local Mac Donalds - that’d monitor MAC addresses on their wifi waiting for one to stop transmitting, then it’d update its own MAC address to piggyback someone else’s T&C agreement, and run bit torrent until the connection ran out of its bandwidth quota, then it’d go back into monitor mode. I pirated the first couple of seasons of GoT ~500MB at a time that way…
- lukeboi 4y agoI am currently writing captive portal support for a big-name internet provider. This article only scratches the surface of how difficult it all is. Each OS is different, and each is painfully undocumented
- pretext-1 4y agoCan you provide some examples?
- lukeboi 4y agoSure. Rambling off the top of my head: On mobile OSes, the captive portal is opened in a sandboxed embedded browser. OS designers want to prevent the captive portal from being used maliciously, so they understandably block off a lot of functionality. Problem is they don’t tell you what features they turn off. I.e As far as I can tell iOS blocks off external links and ajax requests (!) On iOS you can’t close the captive portal programmatically. The user must submit an html form (or similar) and navigate to a new page. Only then will the OS check /mobile-hotspot-detect and realize that the user is connected to the internet and present the user a button to close the captive portal. This is very clunky and makes it impossible to make a sleek user experience Android automatically closes the captive portal when it detects a connection. This often confuses the user (why did my page suddenly disappear?) and makes it impossible to make a consistent mobile captive portal experience between iOS and android Androids kernel seems to have two separate, independent captive portal checks iOS only checks the content of the connectivity check endpoint, while android also checks for any form of a DNS redirect in its requests Microsoft checks against two different domains for a captive portal Many Non-stock android distros check against their own custom (and undocumented) endpoints There was a dhcp option recently introduced to help clean up this mess. Problem is, nobody supports it. Not even Apple (who seemed to have played a hand in the RFC) supports it Linux is a lost cause Figuring this all out took over a month of trial and error. Even then many of my conclusions are probably wrong. None of this is documented or standardized!
- smashed 4y agoI've been there. I can relate to everything you said! The DHCP standard was such a waste of time. Ignore it completely, no client support whatsoever. Intercepting all plain HTTP traffic (just drop https) and responding with a 30x redirect to your captive portal web page seems to be the ad-hoc "standard". Your captive portal domain can be served under secured HTTPS just fine. I fully agree with the sandboxed browsers pain and absolute impossibility to get a nice consistent UX across platforms.
- Kadin 4y agoIf I had access to a time machine, while I'd certainly kill Hitler and Stalin first and second, whoever invented the concept of a "captive portal" would end up dead before I ran out of bullets. Just a stupid idea, badly implemented. So many places turned them on not because of any actual mandate from their legal department (how many places with captive portal pages actually have 'Legal Departments', anyway?) to do so, but because the feature was there in their routers, and thus it seemed like the "safe" thing to do. And once it became the standard thing for businesses to do, suddenly every business felt the need to do it. And now, people look at you like you're crazy if you suggest setting up a Guest WiFi network without one. It's just too bad. This is literally why we can't have nice things.
- moring 4y agoThe hidden assumption here is that using a CP doesn't actually give you at least some legal protection or at least an advantage if you end up in court. Also, instead of blaming the restaurant owner who gets fire from all sides all the time, why not blame - lawmakers and courts for not stating clearly whether using a CP is expected, or what the alternatives are - OS, browser and access point vendors for inventing a more sane alternative than automated MitM attacks
- pyrolistical 4y agoI think apple is leaving money on the table. They could expect the captive site to return a meta element redirect to apple.com as most wifi portals return you back to the site it intercepted. I often see the “Success” message and didn’t know that was defined by apple
- captivehacker1 4y agoTo my shame, I must admit that I've implemented a captive portal before. The article fails to mention https://datatracker.ietf.org/doc/html/rfc8952 https://datatracker.ietf.org/doc/html/rfc8952 and https://datatracker.ietf.org/doc/html/rfc8908 https://datatracker.ietf.org/doc/html/rfc8908 which get rid of most of the pain of captive portals on modern OS from a user perspective Still need to support Captive-Portal detection URLs for some edge-cases (Apple, MS, NetworkManager) and older desktops. But at least HTTP redirection becomes obsolete in almost all cases. Also has the nice feature of showing links to venue info page and remaining data volume in Android.
- ericlaw 4y agoHappy to add those, if you can point to some information about actual implementations?
- Karen48 4y ago[dead]
- shaky-carrousel 4y ago> HTTPS is explicitly designed to prevent a Monster-in-the-Middle (MiTM) Monsters don't exist. If people are really committed to erase anything that has the word "man" in it, at least they should try to be less lazy and use a term for people outside kindergarten.
- soylentgraham 4y agoWhat is your suggestion? Bad actor in the middle?
- shaky-carrousel 4y agoPerson in the middle. If you want to replace man with a generic form, use person. Monster is childish, and lazy.
- macguillicuddy 4y agoPerson is lazier - it doesn't even maintain the acronym. Perhaps if you'd suggested Malefactor in the Middle it would have been a more convincing argument? In general I don't consider 'monster' to be childish - it's often used to refer to sexual preditors, for example. What we're seeing in this line of discussion is that language is mutable and subjective - and for that reason the author's use of words is a justified as any other.
- Handytinge 4y agoI've got a simple way for you to maintain the acronym...
- omegabravo 4y agomachine? Machine in the middle is probably even more accurate than man. Keeps the same acronym too which is nice. Person is the obvious alternative that is gender neutral
- macguillicuddy 4y ago
- weberer 4y agoI absolutely hate this nonsense. They cause countess headaches just to make people click an unenforceable "I Agree" button to terms nobody reads. What would be the best way to kill captive portals once and for all?
- hansel_der 4y agoimho either outlawing or automating them
- blue_cookeh 4y agoWhilst I hate Captive Portals in most circumstances (most hotels I stay at have completely broken implementations) we find them to be extremely useful. We run LAN gaming events and a Captive Portal helps us enforce our physical check in procedure. If someone has somehow bypassed checkin, they have no access to our network... puts a bit of a downer at a LAN event.
- weberer 4y agoYou would think modern wi-fi standards would be able to support per-user username and passwords by now.
- blue_cookeh 4y agoYou can do 802.1x user/pass auth. In general though it's far more expensive to run and maintain because your access layer (APs, switches etc) now needs to be fully managed to support 802.1x. That, and a lot of OSs have janky support that doesn't follow the standard well.
- stonewareslord 4y agoHow do you enforce the physical check with captive portal? Do you give everyone a shared password to go into the portal?
- bo0tzz 4y agoWhile those TOS button captive portals are definitely annoying, there are cases where this can be useful - for example, to enroll users for 802.1x certificates.
- somishere 4y agoWhile I generally agree with the prevailing sentiment here I actually managed to implement a captive portal with surprisingly little trouble (ubuntu + haproxy). Use case was an offline WLAN where I needed to direct users through a specific flow / landing page. All up it was less than a day's research and work, plus the landing page build. Found some decent resources in the process such as https://captivebehavior.wballiance.com/ https://captivebehavior.wballiance.com/ Happy to provide further detail if anyone is interested.
- Grumbledour 4y agoPlease do! I wanted to do something similar a few years ago and was shocked that I couldm't find any information on how to. Of course I am also an amateur when it comes to this stuff, but it seemed to me a use case that could be common with SBCs like the raspberry pi and I was sad to not find an easy to follow write-up.
- somishere 4y agoHey sorry for the delay on this - took a while to find the time. Likely not exactly what you were looking for but hopefully some of the way there: https://gist.github.com/theprojectsomething/a8406ba6be3ed3335fb3a2e5efea4b41 https://gist.github.com/theprojectsomething/a8406ba6be3ed333... Also posted as a show HN if you had any thoughts :) https://news.ycombinator.com/item?id=32208258 https://news.ycombinator.com/item?id=32208258
- ralphdas 4y agoWhat I don't see mentioned here is the issue to redirect the user from the captive portal browser back to its own (preferred) browser to display a landing page after acknowledging the TOS. On Android this seemed completely impossible and I noticed several implementations where there was simply requested to copy a link. On Apple any link with target blank would open a new Safari window. I'am wondering if this changed with later Android releases