Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, back in the day before HTTPS was common, this used to be a viable attack where people would set up rogue hotspots at cafes and whatnot and intercept all your traffic.


That's only possible for unencrypted networks/SSIDs, though.


I think that's a different attack, where you could passively sniff wifi traffic from networks without WEP. I meant more just hosting your own hotspot with a popular name, forcing clients to connect to it via disconnect/reconnect attacks, and then you're essentially a tiny MITM ISP that can monitor all their unencrypted traffic


> hosting your own hotspot with a popular name, forcing clients to connect to it via disconnect/reconnect attacks

You can only do that for unencrypted networks or those for which you know the passphrase, though.


Yes, like most public hotspot in cafes, schools, libraries, etc where the password is readily shared.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: