NeverSSL – helping you get online
neverssl.com
neverssl.com
FAQ:
1. Why does neverssl.com use Javascript to redirect to a random subdomain?
Over the last year users reported that some networks aggressively cache the fake DNS and pages they use for wifi capture. Neverssl.com now works around this generating a request to a random subdomain - this will bust any DNS cache, and any HTTP cache. It also means that if your browser or ISP caches the Neverssl.com page itself, that's fine.
2. Is NeverSSL.com tracking you or anything like that?
Normal S3 access logging is enabled, so I have a record of every IP address that accessed NeverSSL.com. I aggregate this information by AS number (ISP basically) to "rank" the networks that get the most usage ... this helps me figure out which networks are most broken. I occasionally forward this aggregated data to those network operators to encourage them to fix wifi capture. There's no other tracking, but you are trusting me on that. I am a founding director of Digital Rights Ireland, we sue governments and win for better user privacy.
3. Can I put ads on NeverSSL.com?
I thought about this, but I think it'd degrade the experience too much. I am thinking of maybe putting some rotating art, or inspiring poems, something to add a bit of soul to our day. Ideas welcome!
4. Shouldn't I use example.com?
I predict that example.com/org/net will all go HTTPS, as they are intended to service as canonical examples of internet standards.
5. What happens if NeverSSL.com gets pwned?
I don't understand this risk; it's not setting cookies, there's no passwords, or any personal information.
I agree with you technically, but in practical terms imagine if you changed the web page to look like a Google-style search engine window.
You can expect all the less-sophisticated users to try typing site names and even URLs into that text widget.
And if you give them back what looks like a link to the place they wanted, they absolutely will click it, and most of them will happily trust that having typed "My Bank" and clicked a link labelled "My Bank: A secure bank" in the resulting "search results" the site they've reached, fake.mybank.neverssl.com must obviously be their bank, and they will cheerfully give you their bank credentials.
I'm not suggesting this as a criticism, it's purely an observation, that in practice NeverSSL getting pwned would be a real problem, the same exact way it's a problem when some Hollywood actress (who doesn't know the first thing about medicine) tells women not to vaccinate their kids. People are dumb, and we have to allow for that.
Like what?
So I found it better to use some domain dedicated exactly for this (and I hope even if the person running neverssl.com chooses to stop doing so someone will probably take over).
This doesn't do anything to prevent a MITM at all, just that if neverssl.com starts serving crap you have a nonzero chance of loading it when trying to use it to generate a redirect. If there's a local MITM you're in trouble either way.
I'm kind of amazed no one has implemented a better system for this yet. Public WiFi is very common, and relying on intercepting HTTP requests to show users a login screen seems very hacky to me.
What if a device pinged the gateway IP on a certain port whenever it connected, and received a small payload with details on connectivity authorisation URL, etc. etc.? For backwards compatibility if that ping fails it could just assume the network is open. It would take years for all the public routers out there to be updated, but you kind of need to start somewhere.
For paid wifi, on the other hand, wouldn't they want to ensure you can connect? Most airlines charge for wifi. Yet I find myself typing "example.com" on almost every single flight.
But the existence of a better solution doesn't stop people doing something crummy that kinda-works for them. That's what you're seeing today, it's what you see in most places, most of the time. That's people.
The homepage is fairly innocuous, it’s always http, and if it loads I also know the WiFi doesn’t have some crappy web filtering software running on it.
On the other hand, they don't guarantee that they won't implement an HTTPS redirect someday. Seems like that's the major selling point here.
I wonder how this site is funded. They have the ability to gather (presumably valuable) statistics on WiFi hotspot usage...
The only tracker on the page is from Twitter (for the follow button). I don't know what metrics they give you, but other than that it looks to be whatever can be grabbed from the server side logs.
I've been using this for several years now both to test internet connectivity and to force captive portals to load - I didn't know about example.com until today though!
Thumbs up for this website.
Can anyone here explain the idea behind those?
I have used NeverSSL in the past, but I haven't seen those...