8 ms·
WA man set up fake free WiFi at airports and on flights, police allege
- jjbinx007 2y agoWere people entering login details on non-encrypted dummy sites?
- cqqxo4zV46cp 2y agoYes? This is unsurprising and doesn’t represent gross incompetence on the part of the victim. Computers are inscrutably hard to understand. Anyone that’s lost sight of that is in an echo chamber.
- jjbinx007 2y agoI'm not blaming the victims, but at the same time they will have seen several warnings from their browser indicating that the sites are unencrypted and not to send sensitive information.
- alamortsubite 2y agoThe guy's evil-twin sites may have been encrypted. Nothing in the article suggests otherwise.
- lbourdages 2y agoThey may be self-signed but if he rolls out his own self-signed certificate the browser will also put a big warning to not go forward.
- saagarjha 2y agoWhy would they be self-signed
- lbourdages 2y agoWell you can't have a real amazon.com cert ¯\_(ツ)_/¯. If you use a random domain sure it works, but it's also fishy. I guess most people won't notice...
- kube-system 2y agoMake the domain login-to-[airline]-wifi.com, get a real cert, and return a form with <h1>Login with Facebook</h1> and you won't ring alarm bells for the average user
- alamortsubite 2y agoWhat's the imagined obstacle in obtaining a real cert?
- netsharc 2y agoLetsEncrypt cert? The domain could be something like amazon.freeewifi.com, it can have a username/password field and a text above it that says "enter your Google/Facebook/Amazon login", and the majority of users won't realize that this is a 3rd-party site. Experts like us might notice "That's not how 3rd party auth is supposed to work!", but the majority really won't know. A few years ago I read a statistics that most (90%+) computer users just do things based on rote memorization of sequences of actions, not understanding what happens in the background. I wonder how it is nowadays. Maybe AI that can "smell" if you're on a scammy site (e.g. prompts to enter your Google/FB/Amazon password) would be useful, but then again the implementation might end up being like MS's "let us record your screen, for AI!" horseshit..
- lbourdages 2y agoI was imagining them trying to spoof an amazon.com domain using an evil dns server or something of that nature. That would be much harder to detect, but the cert is an issue. I guess it's overcomplicating things, though. Most people will just not notice that whatever domain they use is not legit.
- netsharc 2y agoYeah, just like "I'm a prince who needs your help to move money" scams are riddled with poor grammar, it's easier to keep it dumb, to attract the unsuspecting. But on the flip-side, if there's an expert on the flight, they'd notice it's a spoof site and chances are higher they'll report it to the crew. I can imagine the trick is to show a page that says "For free WiFi, follow our Instagram account, click here for our account", and the click will fail because there's no connection (if we're on the plane), but the click can trigger some Javascript to say "If you couldn't follow our Instagram, login using your Google/Amazon account: Username: ____ Password: ____". Or a more sophisticated trick would be to show a DIV that looks like Instagram and the "follow" button, which will then show the fake login... The privacy-wary IT expert will look at the "Follow our Instagram" and think "Fuck off, I'm not doing that!" and might miss the spoofed login prompt...
- QuadmasterXLII 2y ago
- sunaookami 2y agoHTTPS is not and never was a sign for trustworthyness.
- kube-system 2y agoI wouldn't say "never was". EV certs were an attempt to do exactly that for a time period of about 10 years. And many users were explicitly trained to trust EV certs as indicating that the site was independently validated as trustworthy, during that time period.
- goldpizza44 2y agosounds like he was simulating openid-connect flows by saying "login with Google" or "login with Facebook" and then storing the credentials entered which would be cleartext. I always suspicious of these flows for specifically this reason. The flows are secure as long as you know you are talking to the correct identity provider, but I think most laymen would not understand that concept.
- kevincox 2y agoThis is why using a password manager with browser integration is critical. If the password doesn't auto-fill something is wrong.
- tomr75 2y agoor use a passkey
- WolfeReader 2y agoGotta be careful with that too. If your password manager offers to auto-fill on the base domain - for example, *.google.com, it would be fooled by any phishing site hosted on google sites or google forms.
- marshmellman 2y agoWow, that seems like a huge security risk for Google that people can create phishing sites on their auth domain. I don’t think Google Forms allows login forms, but I’m surprised Google Sites would offer hosting on the primary Google domain.
- ianschmitz 2y agoHSTS is a great mechanism to help protect against this. Although it assumes the user has visited the site previously within the HSTS expiration period. There’s also the HSTS preload list: https://hstspreload.org/ https://hstspreload.org/
- beachy 2y agoHow does this help if the evil portal is an entirely new destination for the victim?
- goldpizza44 2y agoInteresting site on hsts. I don't think HSTS will help if he is running his own WWW site on his laptop with a proper CA signed cert. If I understand correctly his laptop was presenting a proper WWW login page presumably over HTTPS after victims connected to his WIFI. What he was probably faking was the redirect to the Identity Provider (IDP) by staying on his own properly credentialed HTTPS site which would pass all HSTS checks. He may have also been faking DNS responses to keep users where he wants them.
- omegabravo 2y agoHow would they have got a proper CA signed cert for a domain they don't own? HSTS will only make a HTTPS connection. Without the valid certificate, they should get a warning. The only way this "works" is if a captive portal pops up a browser to a site that looks the same like amaz0n.com. Password manager wouldn't popup, but many people don't use them. Faking DNS also won't help with the TLS warning, they won't have the certificate. Basically, this shouldn't be possible with HSTS.
- rahimnathwani 2y ago> How would they have got a proper CA signed cert for a domain they don't own? No need. People probably don't look closely at the domain name.
- willhackett 2y ago
- erikaww 2y agoPretty sure they can glean some info just by looking at dns requests. Maybe could infer who is who by MAC address. Though, I think you need to act like a router. I think could just listen to all of this on public Wi-Fi though
- nunez 2y agoProbably fake login portals
- appstorelottery 2y agoThis is called an evil portal, it's super simple to do - Flipper has inbuilt functionality for this. It's super simple, broadcast an SSID with "Amazon Free Wifi" - when the user connects serve up a simple login page with Amazon logo, prompt for username and password - save the username and password, and just do nothing... end user doesn't understand why it didn't work, but it's too late at this point. Remarkably simple.
- netsharc 2y agoSeems he was able to do the technical part, but not the not getting caught part. He's is probably not so smart if he's doing it on flights. The police would just need 2 reports from 2 different flights, and then check the passenger lists to find that he was on both flights...
- anVlad11 2y agoPlease don't spread misinformation about Flipper Zero, there is enough of that already. The device has no Wi-Fi capabilities without hardware modifications.
- opless 2y agoThere's a widely used add-on to the flipper zero that adds wifi capabilities though.
- martin293 2y ago...
- gruez 2y agoBut the original claim was "Flipper has inbuilt functionality for this"?
- opless 2y agoStill, it's capabilities are extended by the WiFi dev board https://blog.anthares101.com/how-to-setup-the-flipper-zero-for-wi-fi-attacks/ https://blog.anthares101.com/how-to-setup-the-flipper-zero-f...
- nyjah 2y agoMaybe someone here can enlighten me. I usually don't bring my phone into stores. But the other day I went to Home Depot and I had my phone on me. Despite my settings of "Do not connect to any wifi network", I look and I am shocked to find that my phone is connected to some random wifi network. Odd. I get home and all the sudden my phone won't connect to my wifi and when I try to connect it to my home wifi, it says, "incorrect password" and its connection was intermittent. It would come back for a second if I turned the wifi on and off again. Eventually I deleted every known wifi network from my phone and its been solid since. But what the heck happened at home depot?
- instagib 2y agohttps://shop.hak5.org/products/wifi-pineapple https://shop.hak5.org/products/wifi-pineapple Best bet is to turn off WiFi/Bluetooth when not needed or off when you leave the house. Decent list below: https://www.terranovasecurity.com/blog/wi-fi-pineapple-cyber-security-threat https://www.terranovasecurity.com/blog/wi-fi-pineapple-cyber...
- gruez 2y ago>https://shop.hak5.org/products/wifi-pineapple https://shop.hak5.org/products/wifi-pineapple That doesn't explain how his phone auto connected to the network despite new connections being blocked, nor does it explain why it broke the saved configuration for his home network
- instagib 2y agoLet’s say he’s a high value target. Put one at a place he goes regularly and 7 more outside his home to be stronger than the home network. It’s the entry level MiTM. Routers have vulnerabilities that do not get patched. Idk what phone, VPN, or network setup he has. Apple: Known networks will be joined automatically. If no known networks are available, you will be notified of available networks. Option 2: notified -> asked. Option 3: manually select a network.
- 2y ago
- padre24 2y agoOptus should employ this guy.. or Medibank, or Latitude Finance. Lots of opportunities for him.
- cynicalsecurity 2y agoCyber criminals are usually not wanted by companies. It's not so hard to guess why.
- clemailacct1 2y agoI've been in infosec for the past 14+ years and hiring these types are pretty nuanced and complex. On one hand, you have a person who shows their ethics are questionable at best. Do you want those folks having the proverbial "keys to the kingdom"? On the other hand - people make mistakes and learn. And these types of folks are decently effective at what they do - although I will say the fact they got caught demonstrates they're not THAT good. I'd probably pass on this specific person for the latter reasons.
- gruez 2y agoHow did they find the guy? After all it could be anyone on the flight.
- 542458 2y agoIt article says “domestic flights [plural], and at other locations that police said were linked to the man’s previous employment”, so it’s possible they checked passengers in common between two or more flights that had reports of bad portals as well as other locations that pointed to this guy.
- nope1000 2y ago> The fake pages were allegedly set up at Perth, Melbourne and Adelaide airports, on domestic flights, and at other locations that police said were linked to the man’s previous employment. Very bad Opsec, literally did his crime at the most surveilled places in the world and at his former job lmao.
- true_religion 2y agoIsn’t that good opsec? He already had a reason to be on those flights as opposed to them finding out this one guy is always traveling as a tourist where there are issue. Well good might be pushing it since it would have been better for him to fly to another city then drive to the destination to leave less of a paper trail.
- talldayo 2y agoWiFi's signal strength can be used as a proximity sensor for the source. It doesn't give you a direct location of your signal source, but the less amplitude your client radio reports needing is the closer you're likely getting to the emitter.
- Molitor5901 2y agoInteresting, but does this rise to the level of a crime? Only in Australia? What if I put a box that says fill out this card and be entered into a drawing to win a free car. Instead I steal the data. It sounds like fraud, but there's no exchange of money and the data itself would have diminutive value. Only when I use the data might it rise to the level of a crime. Anyone with knowledge of Australia's legal system that could please explain how this is a crime?
- mingus88 2y agoThe article: > The 42-year-old has been charged with unauthorised impairment of electronic communication; possession of data with the intent to commit a serious offence; unauthorised access or modification of restricted data; dishonestly obtaining personal financial information; and a possession of identification offence.
- Molitor5901 2y agoThank you, I missed that part. I get some of that but "possession of data with the intent to commit a serious offence" seems awfully weak and broad.
- mingus88 2y agoYeah, I believe many charges get added on to work towards plea deals, at least in the U.S. “disturbing the peace” is pretty common here and can be applied to anything. Intent is a critical piece of prosecution, though. Hard to argue that you were storing passwords for any good faith purpose, so I’d expect that charge to stick.
- Molitor5901 2y agoAh good point, like the FBI's overkill in charging people; obstruction of justice, lying to an agent, withholding information, etc. https://www.newyorker.com/news/news-desk/how-the-legal-system-failed-aaron-swartzand-us https://www.newyorker.com/news/news-desk/how-the-legal-syste...
- Havoc 2y agoSurprised that the airline picked up the rogue network
- ac29 2y agoSomeone probably complained that it didnt give them internet access
- starttoaster 2y agoWA is the state code for Washington in the US, by the way. Is WA commonly thought of as "Western Australia" worldwide outside of the US? If not, maybe consider using less overloaded abbreviations in your titles.
- kube-system 2y agoIt looks like the article was written by and for Guardian Australia. Local abbreviations are frequently used in news written with a local audience in mind, and when syndicated to a larger audience, this situation frequently pops up.
- eterm 2y agoI'm sure you wouldn't be making this complaint if it were the other way around. Rather than demanding the rest of the world avoid abbreviations that coincide with US states, perhaps just accept others can use their own abbreviations.
- textlapse 2y agoIn fairness, this site skews super US/SV-centric, so a majority of people might read it as Washington :) Nothing against local abbreviations. The ramifications of hijacking the wifi used by frequent flyers/tech workers between Seattle <-> SJC/NYC/etc have a very different 'vibe' to it than the actual one in the article.
- starttoaster 2y agoI understand you being offended. I'm sure internet users outside of the US are annoyed by US posters using terms/abbreviations that mean different things to different countries. However, I did purposefully add the question "Is WA commonly thought of as \"Western Australia\" worldwide outside of the US?" as a form of olive branch to people outside of the US, in case I'm the one being ignorant here. So in this case, I kind of think your inflammatory comment is unwarranted though.
- Rygian 2y ago
- deleted 2y ago[deleted]