▲ 676 ▼ Usually connect to Walmart's WiFi but they changed their policy I guess, won't be doing that now... (lemmy.ml) submitted 2 years ago by trippingonthewire@lemmy.ml to c/privacy@lemmy.ml 224 comments fedilink hide all child comments
[–] Catsrules@lemmy.ml 0 points 2 years ago (1 child) How would they do man in the middle attacks? Don't you need to trust their certificate first? permalink fedilink source parent hideshow 2 child comments replies: [–] Da_Boom@iusearchlinux.fyi 1 point 2 years ago That mechanism only happens after you connect to it, you have to connect to the wifi in order to download the certificate to connect. And it doesn't apply to all open WI-FI. A someone can still spoof the wifi. The fun part is when they set up their own false "I agree to the usage" pop up page that just steals your data - standardised systems like this are easily spoofed, especially when it comes to open and insecure wifi. They could even send you a bogus certificate that routes all the traffic through their gateway, allowing them to spy on the secure connections. permalink fedilink source parent
[–] Da_Boom@iusearchlinux.fyi 1 point 2 years ago That mechanism only happens after you connect to it, you have to connect to the wifi in order to download the certificate to connect. And it doesn't apply to all open WI-FI. A someone can still spoof the wifi. The fun part is when they set up their own false "I agree to the usage" pop up page that just steals your data - standardised systems like this are easily spoofed, especially when it comes to open and insecure wifi. They could even send you a bogus certificate that routes all the traffic through their gateway, allowing them to spy on the secure connections. permalink fedilink source parent