4 ms·
Good point. I considered adding more details, but felt they were off-topic to the purpose of my post, and didn't want to have the "thank you, brave soul for ru
by sillystuff 4y ago
Good point. I considered adding more details, but felt they were off-topic to the purpose of my post, and didn't want to have the "thank you, brave soul for running an exit node. Your actions might enable other good things that you might not have expected" message lost in noise.
There was a captive portal page (another hacky script running as a CGI) where the user had to agree to, "not be a dick" to continue. And, the user also had to agree that they were aware that others, who were dicks, could be accessing their data if it was not encrypted and gave the example of http vs. https in the address bar of the browser.
There was also a picture of an onion on the captive portal page, and a link to a FAQ which talked about open wifi and Tor. Exit nodes were not geo restricted, so if nothing else, the warnings and explanations allowed the users to understand why sites often seemed to think they were in a different country.
There is a limit to what people are able to digest about a subject that is not one they focus on. But, the warnings (right on the main captive portal page; without having to navigate to the FAQ) were sufficiently scary to encourage caution.
The most likely available alternative would have been public access terminals in the library, or other open wifi for those with portable devices. Public access terminals could be running keyloggers and worse. Even if the public terminal is free of malware, the non-technical user might just close a logged in browser tab/window, not realizing that is not sufficient to log them out.
Yes, even with users being careful about looking for https in the URL bar, some websites are broken and use https for their login page, but use http for their session cookies. But, trying to protect from these incompetent websites would require shutting down all public wifi everywhere (OWE [opportunistic wifi encryption without authentication] did not exist yet).
I think my open wifi (and open wifi generally, as well as Tor) were/are a net good. If, after this additional detail you still disagree, then we will just have to disagree.
- crtasm 4y agoYou went above and beyond with it all, yes I was mainly concerned how informed the users were and agree open wifi and Tor are a net good. Appreciate the writeup!