Captive Portals
textslashplain.com
textslashplain.com
Monsters don't exist. If people are really committed to erase anything that has the word "man" in it, at least they should try to be less lazy and use a term for people outside kindergarten.
Machine in the middle is probably even more accurate than man. Keeps the same acronym too which is nice.
Person is the obvious alternative that is gender neutral
>The term man (from Proto-Germanic *mann- "person") and words derived from it can designate any or even all of the human race regardless of their sex or age. In traditional usage, man (without an article) itself refers to the species or to humanity (mankind) as a whole.
On a personal level, it may be a few tiny tweaks but also very tiny personal impact. On a global scale, it could be a larger impact but also takes a lot more effort (combined effort of millions of tiny tweaks). Whether that effort is worth the payoff is debatable, especially considering what other initiatives that effort could be directed to.
But the Wikipedia mention links to a Cloudflare blog post from 2019, which is around the time Big Tech started renaming CS terminology.
You can’t use that as proof of long-standing usage.
We run LAN gaming events and a Captive Portal helps us enforce our physical check in procedure. If someone has somehow bypassed checkin, they have no access to our network... puts a bit of a downer at a LAN event.
(Un)fortunately many captive portal are poorly designed, allowing arbitrary traffic to be sent over UDP/53 or ICMP, even when not authenticated. This kind of defeats the purpose of a captive portal, as the tunnel can be operated over UDP/53 (or whatever) and the captive portal can be solved remotely.
On mobile OSes, the captive portal is opened in a sandboxed embedded browser. OS designers want to prevent the captive portal from being used maliciously, so they understandably block off a lot of functionality. Problem is they don’t tell you what features they turn off. I.e As far as I can tell iOS blocks off external links and ajax requests (!)
On iOS you can’t close the captive portal programmatically. The user must submit an html form (or similar) and navigate to a new page. Only then will the OS check /mobile-hotspot-detect and realize that the user is connected to the internet and present the user a button to close the captive portal. This is very clunky and makes it impossible to make a sleek user experience
Android automatically closes the captive portal when it detects a connection. This often confuses the user (why did my page suddenly disappear?) and makes it impossible to make a consistent mobile captive portal experience between iOS and android
Androids kernel seems to have two separate, independent captive portal checks
iOS only checks the content of the connectivity check endpoint, while android also checks for any form of a DNS redirect in its requests
Microsoft checks against two different domains for a captive portal
Many Non-stock android distros check against their own custom (and undocumented) endpoints
There was a dhcp option recently introduced to help clean up this mess. Problem is, nobody supports it. Not even Apple (who seemed to have played a hand in the RFC) supports it
Linux is a lost cause
Figuring this all out took over a month of trial and error. Even then many of my conclusions are probably wrong. None of this is documented or standardized!
The DHCP standard was such a waste of time. Ignore it completely, no client support whatsoever.
Intercepting all plain HTTP traffic (just drop https) and responding with a 30x redirect to your captive portal web page seems to be the ad-hoc "standard". Your captive portal domain can be served under secured HTTPS just fine.
I fully agree with the sandboxed browsers pain and absolute impossibility to get a nice consistent UX across platforms.
I mean, captive portals started out as a hack, then captive portal detection was a hack against that hack... It's effectively an antagonistic relationship.
Respect redirects over HTTP or gtfo.
Have you never considered this scenario?
I do think the internet should be free, but how we sustain that is a pretty viable question. APs need to be installed, configured, and monitored. When spaces grow, APs usually need to be reconfigured or moved.
I know that airlines are fairly low margin businesses, based on what I've read from the recent bankruptcy stuff. I am curious about who owns airports and what their margins look like.
In general, someone needs to take a quick look it the development time and customer support involved really can be motivated from the extra earnings. The trend is that fewer and fewer bother, and just see complimentary wifi as a value add instead.
Airports, cruise ships, and other places where it does make economic sense are better served by real things like 802.11x and per-user QR codes.
i am sorry, this is absurd line or reasoning. This logic has never worked in the history of business. It can only work in lisenced proffeshions like law and accounting where doing something nasty would loose you your lisence and your boss knows that, so literslly noone would agree to do it
secondly, captive portal at prague airport actually has a function - it provides you with up to date information about flights and dates.
You can provide flight information without a captive portal, just stick it on a normal web server. Maybe stick QR codes around the airport to help guide people to it. Bonus: you can access it outside of the airport.
they can and always do find someone else to do it. This line of reasoning literally has never worked
In order for this scheme to work, unions are needed. A professional union which like doctors associations would enforce ethical standards on its members and use collective bargaining to freeze malefactors out of the industry.
It wouldn’t be as good as how doctors have it, with legal weight and governmental recognition, but it would be enough.
The gl.inet firwmare itself has a lot of missing updates and I am yet to successfully make custom builds of it (though in theory it should be possible through what's on their public Github repos, save for a handful of packages they provide as binary-only). They do not respond to issues or PRs on GitHub.
I should have taken better notes on building a firmware but I think what eventually allowed me to replicate and make custom build was to just build as if a normal openwrt dist from https://github.com/gl-inet/openwrt with a fork of https://github.com/gl-inet/gli-pub. Ended up ditching their custom hacky wireguard/tor functionality and mostly treating it as an openwrt dist.
Still stuck on a fork of the custom 19.07 (4.x kernel) for E750 (despite my efforts to bring it to 21.02). MT1300 doesn't seem to have had any issues on vanilla openwrt 21.02, though.
The mwan3 stuff can be worth keeping and extending on using the uci module, though.
It really is a shame as there are so many great things with the E750 and it has potential to be the perfect travel router. If there is anyone else who wants to take this to the next level, I could be down for making this ore structured and collaborate on making a more open, accessible, secure and hackable dist either just for the E750 or glinet in general.
It worked with occasional hick ups, but in the last few years I could always use as many devices as I needed (usually two) for free, and the captive portal support on the Fire TV stick improved, so I haven't had the need for it anymore.
While bits and pieces of this can be found implemented in different repos, there seems to be a gap for a software which does this minimally and generally enough and could provide a base for the community to crowd-source profiles/configs/scripts.
I hope the dish is gold-plated…
The article fails to mention https://datatracker.ietf.org/doc/html/rfc8952 and https://datatracker.ietf.org/doc/html/rfc8908 which get rid of most of the pain of captive portals on modern OS from a user perspective Still need to support Captive-Portal detection URLs for some edge-cases (Apple, MS, NetworkManager) and older desktops. But at least HTTP redirection becomes obsolete in almost all cases. Also has the nice feature of showing links to venue info page and remaining data volume in Android.
http://amibehindacaptiveportal.com
If you get any response other than "No" then you're behind a captive portal.
Found some decent resources in the process such as https://captivebehavior.wballiance.com/
Happy to provide further detail if anyone is interested.
Of course I am also an amateur when it comes to this stuff, but it seemed to me a use case that could be common with SBCs like the raspberry pi and I was sad to not find an easy to follow write-up.
Also posted as a show HN if you had any thoughts :) https://news.ycombinator.com/item?id=32208258
Just a stupid idea, badly implemented. So many places turned them on not because of any actual mandate from their legal department (how many places with captive portal pages actually have 'Legal Departments', anyway?) to do so, but because the feature was there in their routers, and thus it seemed like the "safe" thing to do. And once it became the standard thing for businesses to do, suddenly every business felt the need to do it. And now, people look at you like you're crazy if you suggest setting up a Guest WiFi network without one.
It's just too bad. This is literally why we can't have nice things.
Also, instead of blaming the restaurant owner who gets fire from all sides all the time, why not blame - lawmakers and courts for not stating clearly whether using a CP is expected, or what the alternatives are - OS, browser and access point vendors for inventing a more sane alternative than automated MitM attacks
I often see the “Success” message and didn’t know that was defined by apple
In France, I have a 40 GB mobile plan for €10. I know I'm likely below your average phone user, but the most I used out of this was about 4 GB when my home connection was dead, and I was working from home.
If I'm not mistaken, an 80 GB plan is less than €20. To me, that's basically unlimited.
I can get an extra SIM for €2 a month attached to the same plan. I never bothered because an internal WWAN card for my laptop is outrageously expensive, and since I don't need it often, I just share from my phone.
I've tried this once or twice a few years ago, but it was so slow that I went back to using my mobile plan.
Usage is _very_ demographically aligned. At football games, we’d see connected device numbers somewhere around 10% of ticket sales. At a Justin Bieber show it was over 90%.
I have always had more mobile data available than I need, and I can’t remember the last time I bothered using a venue’s wifi (that wasn’t for work/testing purposes)
Back in the pre-Netflix days here I .au, I used to have a Raspberry Pi with a USB wifi dongle and a high gain antenna pointed at the local Mac Donalds - that’d monitor MAC addresses on their wifi waiting for one to stop transmitting, then it’d update its own MAC address to piggyback someone else’s T&C agreement, and run bit torrent until the connection ran out of its bandwidth quota, then it’d go back into monitor mode. I pirated the first couple of seasons of GoT ~500MB at a time that way…
It'd be really nice if we could get to the stage where usage caps just weren't implemented.
Monopolies are always bad.
I generally want to avoid replacing everything with mobile alternatives, but during a recent trip to the UK, I was pleased to find near-ubiquitous coverage via a basic SIM, purchased from a vending machine for £30 that gave me 100GB of data to use during the few weeks I was there. It was overkill, but I pay that much at home for 5GB data and I run into a lot more coverage issues.
And at least in theory, it's more likely for competitors to put up their own cell towers than it is to run new fiber alongside existing fiber (even if there aren't prohibitive franchise agreements in place) so I would definitely appreciate better mobile options here as well. Normally I'd never replace a fiber (or even cable) ISP with a mobile hotspot, but for travel, it negated the need to use public wifi for the entire 3 weeks I was traveling.
[0] https://en.wikipedia.org/wiki/WISPr [1] https://github.com/wichert/wispr