Yum (lemmy.world)
submitted 2 years ago by to c/memes@lemmy.ml
 

all 23 comments

sorted by: hot top controversial new old
[–] 68 points 2 years ago (1 child)

None of the actual matters and this attack is rarely used these days. 99.9% of shit is encrypted "over the line". Unless you have some tls zero day you ain't getting shit besides leaked DNS.

  • source
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    Can't the hacker though spoof some fake websites and trick you into giving your information? If they control the WiFi they control the DNS don't they?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 54 points 2 years ago (2 children)

    Well it actually isn't thaat bad.

    Nowadays every website is encrypted

  • source
  • hideshow 4 child comments
  • [–] 18 points 2 years ago

    The connection to the website is encrypted, but you are right, it's not like pre HTTPS badness

    I assume the good ol' E-Mail Spam Business is still going strong and getting stronger. If more people make business online, the more will fall to the "there's a problem with your account, please re-enter your credentials" bait.

    I've even seen phrases like: your account may have been compromised, please enter now your credentials to fix the problem and add a laver of protection to your privacy.

    In the last few weeks, I got the same "your account is on hold" ( font in google colors ), always from a different sender, multiple times a day ... Flagging these as Spam has no effect.

  • source
  • parent
  • [–] 2 points 2 years ago (1 child)

    Makes sense. How about apps? I often read about popular apps that are not encrypting their traffic.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 2 years ago*

    It's basically the same. Nowadays there barely is any app that isn't using HTTPS

    This has been a problem like 5 years ago though. Like TikTok hasn't been encrypted for a long time. If you're worried, use a VPN-Tunnel that you trust.

    Nowadays the only thing that is unencrypted is the site you're accessing since the DNS protocol isn't encrypted, but that's also changing with the adoption of DNS over HTTPS

  • source
  • parent
  • [–] 19 points 2 years ago

    me when https and all my traffic is encrypted regardless of if I use a VPN or not

    Nice try, NordVPN.

  • source
  • [–] 18 points 2 years ago (1 child)

    That's why I use today's sponsor, privatenordatlastunnel vpn.

  • source
  • hideshow 2 child comments
  • [–] 10 points 2 years ago

    Everything is encrypted nowadays, with HTTP or similar. They only get DNS requests (if you use DNS over HTTPS or over TLS, not even that). Unless you have a zero day in your encryption scheme or network stack, you're fine.

  • source
  • [–] 9 points 2 years ago

    Oh no, watch out everyone it's a Wire(less)Shark™

  • source
  • [–] 5 points 2 years ago

    If only the guy knew how to row they might not be stranded in the first place.

  • source
  • [–] 4 points 2 years ago*

    I use Tailscale (or the fully-self-hosted Headscale) to ensure all my data is routed through my home whether my phone/laptop is on cell data, public wifi, or otherwise.

    One can also simply use it to ensure communication between specific devices is always secure and available but I also find it quite useful as a way to secure all my data when away from home.

    It's free for 5 users/100 devices per account with virtually all of the features available to the free plan.

    There is also a paid option which should really only be interesting to businesses/etc which have many users to connect. Alternatively self-host g Headspace has no restrictions at all.

  • source
  • [–] 2 points 2 years ago

    Nice PSA. I'll probably use this, it's very easy to understand

  • source
  • [–] 1 point 2 years ago (2 children)

    Thats why you should use a VPN when you are out and about. 🙏

  • source
  • hideshow 4 child comments
  • [–] 38 points 2 years ago (1 child)

    Make sure you buy it from a youtuber.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    The only reason why open wi-fi is insecure is because of captive Wi-Fi portals and I'm not saying that the Wi-Fi itself or the internet access is insecure it's just that captive Wi-Fi portals are inherently insecure because they block secure http and also with the website you're going on to don't have https so you can easily figure out the password that they want you to enter in or be able to steal somebody else's session so you don't have to pay or you can just get into a Xfinity router or something

  • source
  • [+] 0 points 2 years ago* (last edited 2 years ago)