▲ 84 ▼ Microsoft warns hackers are targeting hotel Wi-Fi networks: What to know (abcnews.com) submitted 1 week ago by return2ozma@lemmy.world to c/technology@lemmy.world 23 comments fedilink hide all child comments
[–] Septimaeus@infosec.pub 43 points 1 week ago* (last edited 5 days ago) (4 children) Seriously, this is the lowest hanging fruit. Never trust hotel WiFi. E: infants and their alts permalink fedilink source hideshow 8 child comments replies: [–] LordCrom@lemmy.world 9 points 6 days ago (2 children) Wrong. Never download and install any wifi profile package, escpecially if it has certs to install. That is just asking to have all your traffic decrypted and data taken. permalink fedilink source parent hideshow 4 child comments replies: [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @pHr34kY@lemmy.world permalink fedilink source parent [+] Septimaeus@infosec.pub 1 point 6 days ago [deleted] permalink fedilink source parent [–] Scrubber0777@lemmy.ml 23 points 1 week ago Agree with your sentiment especially not trusting hotel Wifi (or heck all open network for this matter). I'd even err on the safe side and suggest not download any certificate and encryption profile at all. Even if I find myself as a tech literate person, I'd not trust my ability to identify the legitimacy of the download. permalink fedilink source parent [–] rozodru@piefed.world 6 points 1 week ago (1 child) extremely low hanging fruit. I travel a lot for work and all my laptops have VPNs with encrypted DNS. Even had to set that up on one of my FreeBSD installs (which was a god damn pain and with the shit wifi on that there really wasn't much of a point at the end of the day). it's even more mandatory for places that have NO captive portals. Those connections are opening themselves up to a can of worms. Looking at you Union Station in Toronto Canada. seriously, fix your shit. One of the biggest transit hubs in all of Canada and their wifi is completely 100% open. permalink fedilink source parent hideshow 2 child comments replies: [–] Septimaeus@infosec.pub 2 points 1 week ago lol same at Union Station WDC and all Amtrak trains (if the wifi even works). Finally switched to a gl.inet (openwrt) hotspot for work travel and haven’t looked back. permalink fedilink source parent [–] pHr34kY@lemmy.world -5 points 1 week ago* (2 children) I don't think anything can monitor or mess with your local web traffic once you have encrypted DNS. VPNs don't add any privacy over HTTPS+DoH. Installing CA certs and whatnot is insane. Stop getting your opsec advice from influencers on youtube. It's snake oil. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 2 points 6 days ago (1 child) "VPNs don't add any privacy over HTTPS+DoH" For someone so smug, you sure say some stupid shit. In what world would wrapping all of your traffic in an encrypted tunnel not provide additional privacy when using a public endpoint? permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world -2 points 6 days ago (2 children) You're routing all your traffic through a single inspection point. They too can scrape anything that isn't HTTPS. They can list every site you visit without DoH. Corporations are just as unaccountable as ISPs and governments. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 3 points 6 days ago That's not what's at argument here. You said that VPNs offer no additional privacy, which is completely incorrect. They have their own pitfalls, yes. But that's not what you were arguing. You can't just move the goalposts when someone points out that you're wrong. permalink fedilink source parent [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @LordCrom@lemmy.world permalink fedilink source parent [–] Septimaeus@infosec.pub 9 points 1 week ago (1 child) Hotel can see every site you connect to and you’re exposed to SNI fingerprinting by their ISP. Metadata leaks over both LAN and WAN (traffic volume, timing patterns, dest IPs, connection frequency) and both netadmin and ISP can infer your browsing habits without actually seeing the content. Other guests with wireshark and too much time on their hands. Moreover, many types of traffic aren’t HTTPS, including NTP, DHCP, SNMP, FTP, SSH (without HTTPS), most IoT devices, VoIP, gaming traffic, many application APIs, apps with embedded DNS overrides (really apps in general, especially mobile apps, especially meta and alphabet apps), even email unless TLS is explicitly configured. And many websites simply don’t serve HTTPS and will attempt to redirect to HTTP. This is without getting into encryption strength and post-quantum standards. And I was referring to 802.1X/MDM enterprise profiles not CA. permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world 4 points 6 days ago* (last edited 6 days ago) NTP, DHCP, SNMP, FTP, SSH NTP just tells you time. No confidential data here. DHCP and SNMP dont go over the internet. A VPN won't save you from this. FTP is dead. Not even web browsers support it anymore. SSH is already encrypted. In some cases, it can literally be used as a VPN. Wireshark is useless on WPA3. Although hotel wifi typically doesn't use it. SNI is encrypted with ECH. I disabled plaintext SMTP on my mail server years ago. Requiring TLS actually reduced spam by 99%. No reputable mail server will use plaintext. Almost nothing uses plain HTTP. The only thing I typically see is my phone's internet connectivity check, which simply returns an HTTP 204 (No content). It's practically a ping. HTTPS + DoH is enough because all of these problems are solved. permalink fedilink source parent
[–] LordCrom@lemmy.world 9 points 6 days ago (2 children) Wrong. Never download and install any wifi profile package, escpecially if it has certs to install. That is just asking to have all your traffic decrypted and data taken. permalink fedilink source parent hideshow 4 child comments replies: [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @pHr34kY@lemmy.world permalink fedilink source parent [+] Septimaeus@infosec.pub 1 point 6 days ago [deleted] permalink fedilink source parent
[–] Septimaeus@infosec.pub 1 point 6 days ago Hi @pHr34kY@lemmy.world permalink fedilink source parent
[–] Scrubber0777@lemmy.ml 23 points 1 week ago Agree with your sentiment especially not trusting hotel Wifi (or heck all open network for this matter). I'd even err on the safe side and suggest not download any certificate and encryption profile at all. Even if I find myself as a tech literate person, I'd not trust my ability to identify the legitimacy of the download. permalink fedilink source parent
[–] rozodru@piefed.world 6 points 1 week ago (1 child) extremely low hanging fruit. I travel a lot for work and all my laptops have VPNs with encrypted DNS. Even had to set that up on one of my FreeBSD installs (which was a god damn pain and with the shit wifi on that there really wasn't much of a point at the end of the day). it's even more mandatory for places that have NO captive portals. Those connections are opening themselves up to a can of worms. Looking at you Union Station in Toronto Canada. seriously, fix your shit. One of the biggest transit hubs in all of Canada and their wifi is completely 100% open. permalink fedilink source parent hideshow 2 child comments replies: [–] Septimaeus@infosec.pub 2 points 1 week ago lol same at Union Station WDC and all Amtrak trains (if the wifi even works). Finally switched to a gl.inet (openwrt) hotspot for work travel and haven’t looked back. permalink fedilink source parent
[–] Septimaeus@infosec.pub 2 points 1 week ago lol same at Union Station WDC and all Amtrak trains (if the wifi even works). Finally switched to a gl.inet (openwrt) hotspot for work travel and haven’t looked back. permalink fedilink source parent
[–] pHr34kY@lemmy.world -5 points 1 week ago* (2 children) I don't think anything can monitor or mess with your local web traffic once you have encrypted DNS. VPNs don't add any privacy over HTTPS+DoH. Installing CA certs and whatnot is insane. Stop getting your opsec advice from influencers on youtube. It's snake oil. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 2 points 6 days ago (1 child) "VPNs don't add any privacy over HTTPS+DoH" For someone so smug, you sure say some stupid shit. In what world would wrapping all of your traffic in an encrypted tunnel not provide additional privacy when using a public endpoint? permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world -2 points 6 days ago (2 children) You're routing all your traffic through a single inspection point. They too can scrape anything that isn't HTTPS. They can list every site you visit without DoH. Corporations are just as unaccountable as ISPs and governments. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 3 points 6 days ago That's not what's at argument here. You said that VPNs offer no additional privacy, which is completely incorrect. They have their own pitfalls, yes. But that's not what you were arguing. You can't just move the goalposts when someone points out that you're wrong. permalink fedilink source parent [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @LordCrom@lemmy.world permalink fedilink source parent [–] Septimaeus@infosec.pub 9 points 1 week ago (1 child) Hotel can see every site you connect to and you’re exposed to SNI fingerprinting by their ISP. Metadata leaks over both LAN and WAN (traffic volume, timing patterns, dest IPs, connection frequency) and both netadmin and ISP can infer your browsing habits without actually seeing the content. Other guests with wireshark and too much time on their hands. Moreover, many types of traffic aren’t HTTPS, including NTP, DHCP, SNMP, FTP, SSH (without HTTPS), most IoT devices, VoIP, gaming traffic, many application APIs, apps with embedded DNS overrides (really apps in general, especially mobile apps, especially meta and alphabet apps), even email unless TLS is explicitly configured. And many websites simply don’t serve HTTPS and will attempt to redirect to HTTP. This is without getting into encryption strength and post-quantum standards. And I was referring to 802.1X/MDM enterprise profiles not CA. permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world 4 points 6 days ago* (last edited 6 days ago) NTP, DHCP, SNMP, FTP, SSH NTP just tells you time. No confidential data here. DHCP and SNMP dont go over the internet. A VPN won't save you from this. FTP is dead. Not even web browsers support it anymore. SSH is already encrypted. In some cases, it can literally be used as a VPN. Wireshark is useless on WPA3. Although hotel wifi typically doesn't use it. SNI is encrypted with ECH. I disabled plaintext SMTP on my mail server years ago. Requiring TLS actually reduced spam by 99%. No reputable mail server will use plaintext. Almost nothing uses plain HTTP. The only thing I typically see is my phone's internet connectivity check, which simply returns an HTTP 204 (No content). It's practically a ping. HTTPS + DoH is enough because all of these problems are solved. permalink fedilink source parent
[–] Assassassin@lemmy.dbzer0.com 2 points 6 days ago (1 child) "VPNs don't add any privacy over HTTPS+DoH" For someone so smug, you sure say some stupid shit. In what world would wrapping all of your traffic in an encrypted tunnel not provide additional privacy when using a public endpoint? permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world -2 points 6 days ago (2 children) You're routing all your traffic through a single inspection point. They too can scrape anything that isn't HTTPS. They can list every site you visit without DoH. Corporations are just as unaccountable as ISPs and governments. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 3 points 6 days ago That's not what's at argument here. You said that VPNs offer no additional privacy, which is completely incorrect. They have their own pitfalls, yes. But that's not what you were arguing. You can't just move the goalposts when someone points out that you're wrong. permalink fedilink source parent [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @LordCrom@lemmy.world permalink fedilink source parent
[–] pHr34kY@lemmy.world -2 points 6 days ago (2 children) You're routing all your traffic through a single inspection point. They too can scrape anything that isn't HTTPS. They can list every site you visit without DoH. Corporations are just as unaccountable as ISPs and governments. permalink fedilink source parent hideshow 4 child comments replies: [–] Assassassin@lemmy.dbzer0.com 3 points 6 days ago That's not what's at argument here. You said that VPNs offer no additional privacy, which is completely incorrect. They have their own pitfalls, yes. But that's not what you were arguing. You can't just move the goalposts when someone points out that you're wrong. permalink fedilink source parent [–] Septimaeus@infosec.pub 1 point 6 days ago Hi @LordCrom@lemmy.world permalink fedilink source parent
[–] Assassassin@lemmy.dbzer0.com 3 points 6 days ago That's not what's at argument here. You said that VPNs offer no additional privacy, which is completely incorrect. They have their own pitfalls, yes. But that's not what you were arguing. You can't just move the goalposts when someone points out that you're wrong. permalink fedilink source parent
[–] Septimaeus@infosec.pub 1 point 6 days ago Hi @LordCrom@lemmy.world permalink fedilink source parent
[–] Septimaeus@infosec.pub 9 points 1 week ago (1 child) Hotel can see every site you connect to and you’re exposed to SNI fingerprinting by their ISP. Metadata leaks over both LAN and WAN (traffic volume, timing patterns, dest IPs, connection frequency) and both netadmin and ISP can infer your browsing habits without actually seeing the content. Other guests with wireshark and too much time on their hands. Moreover, many types of traffic aren’t HTTPS, including NTP, DHCP, SNMP, FTP, SSH (without HTTPS), most IoT devices, VoIP, gaming traffic, many application APIs, apps with embedded DNS overrides (really apps in general, especially mobile apps, especially meta and alphabet apps), even email unless TLS is explicitly configured. And many websites simply don’t serve HTTPS and will attempt to redirect to HTTP. This is without getting into encryption strength and post-quantum standards. And I was referring to 802.1X/MDM enterprise profiles not CA. permalink fedilink source parent hideshow 2 child comments replies: [–] pHr34kY@lemmy.world 4 points 6 days ago* (last edited 6 days ago) NTP, DHCP, SNMP, FTP, SSH NTP just tells you time. No confidential data here. DHCP and SNMP dont go over the internet. A VPN won't save you from this. FTP is dead. Not even web browsers support it anymore. SSH is already encrypted. In some cases, it can literally be used as a VPN. Wireshark is useless on WPA3. Although hotel wifi typically doesn't use it. SNI is encrypted with ECH. I disabled plaintext SMTP on my mail server years ago. Requiring TLS actually reduced spam by 99%. No reputable mail server will use plaintext. Almost nothing uses plain HTTP. The only thing I typically see is my phone's internet connectivity check, which simply returns an HTTP 204 (No content). It's practically a ping. HTTPS + DoH is enough because all of these problems are solved. permalink fedilink source parent
[–] pHr34kY@lemmy.world 4 points 6 days ago* (last edited 6 days ago) NTP, DHCP, SNMP, FTP, SSH NTP just tells you time. No confidential data here. DHCP and SNMP dont go over the internet. A VPN won't save you from this. FTP is dead. Not even web browsers support it anymore. SSH is already encrypted. In some cases, it can literally be used as a VPN. Wireshark is useless on WPA3. Although hotel wifi typically doesn't use it. SNI is encrypted with ECH. I disabled plaintext SMTP on my mail server years ago. Requiring TLS actually reduced spam by 99%. No reputable mail server will use plaintext. Almost nothing uses plain HTTP. The only thing I typically see is my phone's internet connectivity check, which simply returns an HTTP 204 (No content). It's practically a ping. HTTPS + DoH is enough because all of these problems are solved. permalink fedilink source parent