Hidden device distorts news at hotspots
newstweek.com
newstweek.com
Both of the photos of the supposed perpetrators link to the home pages of the same guys that are in the Copyright notice at the bottom of the page. So far as I can tell this is a total hoax.
Still, it'd be cool if it were true.
So, it's definitely a hoax/satire. It's just kind of not really very funny..
The supposed story about it is hosted on the homepage of the device in question, and I see no other hits for it on Google.
Edit: It looks like ibejoeb has the right of it. It is a hoax in the in the stunt/prank/hype/performance art manner, rather than the malicious deception sort.
Still, the hardware (a Sheeva Plug?) and consequent hack described is very possible, tho I understand that setting up a man-in-the-middle DHCP server to override that on the public hotspot is more straightforward.
From a hardware and security perspective it is, as you say, all of the shelf hardware and techniques, ARP poisoning vs. MitM DHCP server have tradeoffs which have slipped from memory, but you can basically go either way.
The doubt is entirely about the hype and false appearance of a third party news story.
Maybe the intent is to highlight the problems with using unencrypted HTTP? I can dream that it's a well intentioned stunt can't I?
However, the technology described is something that is completely technically possible -- ARP spoofing on an open wireless network and performing MITM content modification.
This made me laugh though:
"a Nokia N900 phone turned in at a police station in the area had a number of images of the device on board, along with these two photos, taken just minutes after one installation in a large Starbucks in the central suburb of Mitte, east Berlin. Note the black hat worn by what may be a colleague in the first photograph."
http://www.news.com.au/travel/news/old-man-boards-plane-leav...
I have no idea what the first picture is originally from. I don't recall any recent stories of anyone replacing their head with a Rubik's Cube.
Reads just like a bad movie script.
Edit: This example may lack wireless, but it's close. Anyone know of better examples?
I have a few, they're pretty cool.
Another possible process would be to issue a self signed certificate when a session is being requested - obviously the user would be notified of the certificate issue, but depending on the level of knowledge of the end user, they may just accept the faked certificate. See http://crypto.stanford.edu/ssl-mitm/
Engineering wise this is really a problem to solve at the local LAN, employing individual vlans or other techniques to strictly segment traffic on top of encryption, or simply implementing port based network access control via 802.1x.