4 ms·
Question: What is the innate security risk of using airport wifi? From the article's conclusion: It takes just one mistake — forgetting to use Tor, leaving you
by trop 14y ago
Question: What is the innate security risk of using airport wifi? From the article's conclusion:
It takes just one mistake — forgetting to use Tor, leaving your encryption keys where someone can find them, connecting to an airport Wi-Fi just once — to ruin you.
- napoleond 14y agoWhenever you use a WLAN (or any network, really), you're more or less at the mercy of that network's administrator(s). In the context of the article, it would be easy for whoever is in charge of airport WiFi to connect your MAC address to the Gmail address you thought you were using anonymously.
- blake8086 14y agoWhat if you use a VPN?
- napoleond 14y agoI'm not a security guy, but I don't see what would stop a determined adversary with control of the LAN from performing a MITM attack. Obviously, a VPN is still more secure than no VPN.
- Jach 14y agoDon't VPNs use public-key authentication like one can do with SSH? If they do, it's immune to MITM attacks.
- napoleond 14y agoSo sub "using airport WiFi" with "using airport without a public-key encrypted VPN" or "using airport WiFi with a public key encrypted VPN, but from a new device were the key isn't listed yet". The point is, people make mistakes.
- kansface 14y agoThe entire Internet is a MiTM. SSL protects against such an adversary (unless you click your browser's ignore button when given the popup).
- napoleond 14y agoRight, but the source subnet is presumably a more useful position from which to perform a MITM when the goal is connecting a physical person/device to their "anonymous" online behaviour.
- michael_miller 14y agoSSL protects against such an adversary only if the creator of the certificate is not compromised. While I think this is a reasonably safe assumption, there are still vectors for an attack. For example, if a government agency wanted to conduct an MITM attack, they could compel the CA to create a valid certificate.
- detst 14y ago> you're more or less at the mercy of that network's administrator No, you're not. Sure there are additional risks but making broad statements isn't helpful when we're talking about connecting to a service with SSL. > connect your MAC address to the Gmail address How? Again, it's possible but Gmail works over SSL. That connection would have to be compromised to make any connection to your MAC and then they'd have to make a connection from your MAC to your personal identity.
- napoleond 14y agoSorry, I didn't mean to spread FUD. I don't think it's an exaggeration to say that the LAN admin would have a significant advantage relating your online and offline personae, though. Even the URLs you visit (not encrypted, even over SSL) tell a story.
- icebraining 14y agoThe URLs are definitively encrypted. Only the domains aren't, because of SNI[1]. [1]: https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- weinzierl 14y agoThe URLs you visit over SSL are encrypted (http://stackoverflow.com/questions/499591/are-https-urls-encrypted http://stackoverflow.com/questions/499591/are-https-urls-enc...). DNS is requests are a different matter though and therefore the host part of the URL is visible if you don't take extra steps. Apart from that: If I buy hardware from e.g. Apple or Dell, do they keep a database that connects the MAC to my identity? I don't know.
- napoleond 14y agoThanks, you and icebraining just taught me something. I don't know why I thought the entire URL was exposed. As for the MAC database, it doesn't really matter. It would be easier to correlate the MAC address with security camera footage, for example. (I worked on a project for a local network security firm doing exactly that--don't worry, I wasn't doing the security end of things.)
- icebraining 14y agoOn the other hand, it's harder to securely use Tor (and not letting it leak) than to do: apt-get install macchanger macchanger --random eth0 (And there are multiple utilities for Windows too). Of course, you have to know you need to change the MAC, but that's something the article could've mentioned.
- vicengle 14y agoI assumed it was the same risk associated with using the hotel wifi. That's how they identified Broadwell. They knew the IP connecting to the shared GMail account came from a certain hotel on a certain date. Then they looked at other dates where the connection came from a hotel. Then they got all the registered guest lists and found the common guest name. At least that's how the article described the method of identifying Broadwell. The same could be done with airport wifi and passenger lists. Of course it would take more than a one time connection.