I feel like this "workaround" site is designed to draw attention to the problem at hand more than it is meant to be useful for the task at hand?
I feel like this "workaround" site is designed to draw attention to the problem at hand more than it is meant to be useful for the task at hand?
There is a better solution: No captive portals.
I'm hopeful that these kinds of public analytics could lead to solutions, or at least who to start talking to.
Good idea by the way!
The problem isn't even so much with captive portals, but only with those actively trying to circumvent captive portal detection provided e.g. by iOS (as pointed out above). "Regular" captive portals will be captured by iOS and you can log-in via the mini browser before any requests to Facebook etc. go through - problem solved (albeit in a very hacky way).
The problem only (re-)materialises when some smartass developers actively try (and succeed) to break portal detection (my guess is that they do it because iOS will close the portal once the Internet connection works, so all the nice ads they want to display just disappear).
Like it or not, a lot of places do that.
There are some obvious cases in which this is unacceptable, but they are few and far between. The overwhelming majority of captive portals I see are just trying to get your contact info... so now you have two reasons why they should disappear.
Everyone goes to the mall, not to shop, it would seem, but to use the free wifi and bask in the comfort of free aircon.
Captive portals are here to stay in places around the world, and like it or not, they are a widely used solution that is not going away any time soon. I for one applaud the author of this website's attempts to shine light on the problem of authenticating to this network type.
IIRC in some countries they're required (by law) to do so, because, y'know, terrorists.
Normally you would think it would just be easier to set a wifi password and skip the captive portal nonsense, but so many vendors harbor the fantasy that other people will pay for the wifi so they have to leave it open and put a "buy 24 hours of internet for only $30!" link in there.
I hate captive portals. They are such a nuisance, especially when you have your machine configured to always connect via VPN.
> but $2 would be a more appropriate price tag for a few hours of Internet
Correct. That's (one of the reasons) why Starbucks coffee is pricier.
I think we should move towards considering Internet access as a general service that people make available for their guests/customers.
Do you think hotels and restaurants can deliver reliable internet without charging for it?
Is it reasonable to assume that companies that don't charge for wifi can afford the staff to make sure that users don't abuse it?
I am considering your proposal & I don't see it working at all.
It's almost an inverse relationship, in my experience. The economy to medium-priced "business travel" hotels (the sort found near most U.S. airports) usually have free wifi, while the fancy "luxury" hotels often charge for it.
I simply choose better hotels.
Absolutely. 100% of the hotels that I've stayed at in the last five years have had free wifi. Almost half of those have still had captive portals.
Hell, my gym provides free wifi. The captive portal is literally just a button that says "Continue to the Internet" and redirects you to their Facebook page (not even a terms of use).
Every Starbucks I've been in recently has free wifi. Every library I've visited has had captive portal-free wifi.
I don't understand what sort of "scaling" you're referring to.
Yes. Because most already do.
> Is it reasonable to assume that companies that don't charge for [[tap water]] can afford the staff to make sure that users don't abuse it?
Sorry to post the snarky response, but with internet access, as with all shared goods like access to water or noise in a semi-shared space such as a hotel, yes, I do expect they can handle it and not have it be a big deal.
Internet WIFI should be treated as a condiment. A business that can't afford condiments probably shouldn't be in business.
Many do. I've never seen a restaurant charging for Wifi, and I've seen plenty offering it for free. Quality varies, some are good, some suck. Hotels are all over them map, but I just stayed at the hotel that advertises free high quality Wifi (and it indeed was fine) as one of the amenities.
US-centric, of course, in some places I guess it many be too expensive for restaurants to do this.
Although a restaurant can get by without wifi, most modern restaurants have it for managing OpenTable, monitoring yelp reviews, ordering supplies online, etc.
I guess the signal might get a bit worse the farther away you get from the wifi router, but in general, providing wifi to customers shouldn't cost any additional money.
Heck, most McDonalds restaurants have free wifi these days, and that's about as cheap as it comes.
If you really want payment, then post a URL wherever you post a sign about the SSID, and/or make the SSID "Go To example.com after connecting".
This is a captive portal. But worse, because even HTTP sites don't send you to the portal.
* no MITM attack
* no TLS cert errors
* no "do I need to hard-refresh? what's the key for that?"
* no question if network access is working or not
* one reliable clear action to get access
See the various comments about work-arounds for work-arounds. Random plain-http intercept-check sites because some captive portals try to make iOS not pop up the mini sandboxed captive portal browser. The endless confusion.This stuff would be a lot simpler if people weren't always trying to make it needlessly "easy" and fucking it up even more every time.
No, for fairly obvious reasons. If you MITM traffic, clients will correctly flag security errors. No method exists or ever should exist for a network to cause clients to not flag such security errors. Any such method would defeat one of the primary purposes of TLS: to protect against hostile networks.
> Our portal would let you log on but you'll still fail to connect to anything as we have to inspect it.
For what purpose? I have not seen any legal jurisdiction sufficiently draconian to impose such a requirement. (I've seen a few terrible ones that might require logging IP addresses.)
I know MITM should never be silent of course but some kind of interaction flow would be good. When you try to add a school account to your android it won't let you if you don't install the MDM client. A similar thing for the network would be great (of course, the MDM will install the cert).
I'd love if I could also pin our MITM cert to only be valid when the client is on our IP address' which if using ipv6 could work very nicely.
I don't travel often (Christmas and maybe once or twice a year outside of that), but it's when I encounter this. It's very frustrating because I'll be walking, pass a store I've previously connected to Wifi, and suddenly lose Internet, then hunt for a website to get the portal to pop up.
I'm annoyed that captive portals have been commonly using DNS hacking since 802.11b and I'm surprised a better solution hasn't been standardized. I have no idea where in the stack it should go (DHCP, wireless standards, or whatever) but DNS hacking drives me nuts.
The most sensible option would be a DHCP extension that indicates you are behind a portal and gives the IP to load, but this requires updates to every DHCP server and client, so it would take many years before it works reliably. Also, it fails for IPv6, but a modification to the Router Advertisement message could maybe do the same thing. It's a little scarier in this regard because it would be even easier to abuse.
The experience has gotten a lot better. I see Apple's pop up covering a lot more corner cases, but after years I see have problems almost every time I travel.
Can I set one up on a home network with a regular router without WifiDog or some other OpenWRT firmware?
Maybe somehow use one of the computers on the network to run a DNS server that all requests go through??
To do this properly either your router or switch/AP need to be configured to do the necessary rewriting as well as maintain a list of authenticated clients. Your best bet to do this with something in the consumer(ish) price range without a custom firmware like OpenWRT is something like a Uni-Fi access point which can handle the captive portal interception itself.
All I want to do is make a system which "takes attendance" via the phones automatically trying to join the local network, and I use the session is to look up the user. People would have accounts where they log in once via the captive portal and then the attendance would happen automatically.
Basically I want to make a captive portal with regular routers so I can sell the solution to regular venues.
How do these guys do it:
There are a lot of social wifi solutions now
The closest you could get would be to use another computer with 2 network cards as the actual router (running something like PFSense), and set up a consumer WiFi router as an access point instead of a router. This would only work as long as you don't mind the clients being able to connect to the rest of you local network; if that's an issue you really need something like a captive portal aware AP/switch or a VLAN.
However this solution doesn't make much sense in the end, as it would be much cheaper to buy one of the cheaper commercial-grade APs (UniFi's are around $80) and use your "regular router" with WiFi disabled than it is to buy a computer for that purpose. Those APs are also better quality than any consumer router you could find, and scale up much better for larger venues.
Also TBH if you're not aware of how captive portals work and why it can't be done by a random computer on your network, this is probably not a good business venture for you. This isn't an unsolved (or expensive to solve) problem to begin with.
Consider a building or cruise ship with an existing network. It's a much harder sell to say "replace all your routers" or "flush all your routers and install our firmware" than to say "use your existing router and just set up our DNS server on a computer".
If you can MitM connections on your network just by connecting a client to it, with no particular participation from the router, your network sucks.
Your linked site notes that they provide the router hardware.