WA man set up fake free WiFi at airports and on flights, police allege
theguardian.com
theguardian.com
On the other hand - people make mistakes and learn. And these types of folks are decently effective at what they do - although I will say the fact they got caught demonstrates they're not THAT good.
I'd probably pass on this specific person for the latter reasons.
Very bad Opsec, literally did his crime at the most surveilled places in the world and at his former job lmao.
Well good might be pushing it since it would have been better for him to fly to another city then drive to the destination to leave less of a paper trail.
If you use a random domain sure it works, but it's also fishy. I guess most people won't notice...
A few years ago I read a statistics that most (90%+) computer users just do things based on rote memorization of sequences of actions, not understanding what happens in the background. I wonder how it is nowadays.
Maybe AI that can "smell" if you're on a scammy site (e.g. prompts to enter your Google/FB/Amazon password) would be useful, but then again the implementation might end up being like MS's "let us record your screen, for AI!" horseshit..
I guess it's overcomplicating things, though. Most people will just not notice that whatever domain they use is not legit.
But on the flip-side, if there's an expert on the flight, they'd notice it's a spoof site and chances are higher they'll report it to the crew. I can imagine the trick is to show a page that says "For free WiFi, follow our Instagram account, click here for our account", and the click will fail because there's no connection (if we're on the plane), but the click can trigger some Javascript to say "If you couldn't follow our Instagram, login using your Google/Amazon account: Username: ____ Password: ____". Or a more sophisticated trick would be to show a DIV that looks like Instagram and the "follow" button, which will then show the fake login...
The privacy-wary IT expert will look at the "Follow our Instagram" and think "Fuck off, I'm not doing that!" and might miss the spoofed login prompt...
I always suspicious of these flows for specifically this reason. The flows are secure as long as you know you are talking to the correct identity provider, but I think most laymen would not understand that concept.
I don't think HSTS will help if he is running his own WWW site on his laptop with a proper CA signed cert. If I understand correctly his laptop was presenting a proper WWW login page presumably over HTTPS after victims connected to his WIFI. What he was probably faking was the redirect to the Identity Provider (IDP) by staying on his own properly credentialed HTTPS site which would pass all HSTS checks. He may have also been faking DNS responses to keep users where he wants them.
HSTS will only make a HTTPS connection. Without the valid certificate, they should get a warning.
The only way this "works" is if a captive portal pops up a browser to a site that looks the same like amaz0n.com. Password manager wouldn't popup, but many people don't use them.
Faking DNS also won't help with the TLS warning, they won't have the certificate.
Basically, this shouldn't be possible with HSTS.
No need. People probably don't look closely at the domain name.
This experience would just redirect the user to a site they've never been to before, say: wa-man-likes-your-data.com. This could have a legitimate signed cert from anywhere and look legitimate to the device with a lock icon. Put the airline's logo and a form for PII, wait a couple of hours and you've collected a plane load of data.
I used to think about doing something similar but as an education campaign. Similar to Phishing Simulators at large corporates, I had the idea to display a captive page that explained what the user did and how they can learn to avoid it in future.
Apple & Google should really make it clearer on phones that users are joining untrusted networks, especially any network not implementing Wi-Fi Certified Passpoint (Hotspot 2.0).
so that the captive portal can intercept and write their own login.
Just do a captive portal redirect to "google.johnsmith.example.com" with a properly signed certificate, add google logo and login fields, and after a user enters his credentials, just redirect them to actual google.com.
Most people don't look at domains in the url. You can actually probably register a domain like "freegooglewifi.com" or something.
And that's just one of the many possible scenarios. When you control someone else's Internet, there is a lot of things you can do. Google's certificate transparency is going to help a lot here, but only as much as what happens in a browser.
I get home and all the sudden my phone won't connect to my wifi and when I try to connect it to my home wifi, it says, "incorrect password" and its connection was intermittent. It would come back for a second if I turned the wifi on and off again.
Eventually I deleted every known wifi network from my phone and its been solid since. But what the heck happened at home depot?
Best bet is to turn off WiFi/Bluetooth when not needed or off when you leave the house. Decent list below:
https://www.terranovasecurity.com/blog/wi-fi-pineapple-cyber...
That doesn't explain how his phone auto connected to the network despite new connections being blocked, nor does it explain why it broke the saved configuration for his home network
It’s the entry level MiTM. Routers have vulnerabilities that do not get patched. Idk what phone, VPN, or network setup he has.
Apple: Known networks will be joined automatically. If no known networks are available, you will be notified of available networks. Option 2: notified -> asked. Option 3: manually select a network.
I should have been notified when asked to join the network at hd, I didn’t consider it a known network. Only wifi network I’ve ever connected to is from home. Don’t trust the rest…
The ramifications of hijacking the wifi used by frequent flyers/tech workers between Seattle <-> SJC/NYC/etc have a very different 'vibe' to it than the actual one in the article.
My second reading was an assumption that it was a US state code (maybe I could have arrived at Washington if I thought for long enough about it) and that there'd be a comment here very much like yours but complaining about 'US defaultism'.
So no, it probably isn't that common outside of Australia, but this is so so common, and bear in mind it's usually a US thing. (Anything 'national' or talking about 'the nation' generally means 'the US' on HN, for example.)
Anyone with knowledge of Australia's legal system that could please explain how this is a crime?
> The 42-year-old has been charged with unauthorised impairment of electronic communication; possession of data with the intent to commit a serious offence; unauthorised access or modification of restricted data; dishonestly obtaining personal financial information; and a possession of identification offence.
Intent is a critical piece of prosecution, though. Hard to argue that you were storing passwords for any good faith purpose, so I’d expect that charge to stick.
https://www.newyorker.com/news/news-desk/how-the-legal-syste...
None of this is to say that overkill doesn't exist in the intelligence/policing communities. But this guy was running a Kali Linux social engineering party trick from 2013; it's about as clear-cut of a computing crime as you can get.
Three counts of unauthorised impairment of electronic communication, contrary to section 477.3 of the Criminal Code Act 1995 (Cth). The maximum penalty for this offence is 10 years’ imprisonment;
Three counts of possession or control of data with the intent to commit a serious offence, contrary to section 478.3 of the Criminal Code Act 1995 (Cth). The maximum penalty for this offence is three years’ imprisonment;
One count of unauthorised access or modification of restricted data, contrary to section 478.1 of the Criminal Code Act 1995 (Cth). The maximum penalty for this offence is two years’ imprisonment.
One count of dishonestly obtain or deal in personal financial information (being usernames and passwords) contrary to section 480.4 of the Criminal Code Act 1995 (Cth); The maximum penalty for this offence is five years’ imprisonment; and
One count of possession of identification information with the intention of committing, or facilitating the commission of, conduct that constitutes the dealing offence, contrary to section 372.2 of the Criminal Code Act 1995 (Cth). The maximum penalty for this offence is three years’ imprisonment.
I think even your example would fall under these, since these types of laws are not about technicalities. [1] https://www.afp.gov.au/news-centre/media-release/man-charged...
https://blog.anthares101.com/how-to-setup-the-flipper-zero-f...
My car has the ability to be loud and annoying, but I’d have to cut the muffler off first.
The dev board is not some obscure or custom part. It’s sold alongside the flipper zero. I think mine came as an official bundle and you need it to do pretty much any coding for it. Every review promotes it for WiFi pen testing.
This has no comparison to junk car mods.