Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #179713 > unrolled thread

Captive network account (w/ login redirect) and HSTS

Started byMarc SCHAEFER <schaefer@alphanet.ch>
First post2017-04-02 19:10 +0200
Last post2017-04-03 15:00 +0200
Articles 7 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-02 19:10 +0200
    Re: Captive network account (w/ login redirect) and HSTS Brian <ad44@cityscape.co.uk> - 2017-04-02 21:00 +0200
      Re: Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-02 21:30 +0200
        Re: Captive network account (w/ login redirect) and HSTS David Wright <deblis@lionunicorn.co.uk> - 2017-04-02 22:30 +0200
          Re: Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-03 12:40 +0200
        Re: Captive network account (w/ login redirect) and HSTS <tomas@tuxteam.de> - 2017-04-03 09:30 +0200
    Re: Captive network account (w/ login redirect) and HSTS Darac Marjal <mailinglist@darac.org.uk> - 2017-04-03 15:00 +0200

#179713 — Captive network account (w/ login redirect) and HSTS

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2017-04-02 19:10 +0200
SubjectCaptive network account (w/ login redirect) and HSTS
Message-ID<trRaO-3jk-13@gated-at.bofh.it>
Hello,

with a basic Debian jessie install and a recent Firefox, I observe the
following:

   [1] Debian has no specific support for detecting captive networks
       (e.g. Android, iOS) and redirecting automatically the browser to
       the captive login page

   [2] launching Firefox on the default page doesn't work (doesn't get
       redirected properly to the login page but fails with a HTTPS
       certificate error), if there is a recent HSTS[*] security
       configuration cache for the default domain page (e.g. google.com)

[1] is not really an issue: I wouldn't like myself that connecting to
a WiFi captive network starts a browser. Also, open captive networks are
messing up, dangerous, a WPA/RADIUS auth would be much better.

However, open captive networks are quite commons in hotels, airports,
parks, etc.  So it cannot be dismissed.

[2] the only fix is to type an URL you know is HTTP, not HTTPS and does
not configure HSTS, and does not support DNSSEC. In my case I used
ptiturl.ch

Maybe this could be in the Debian User manual somehow?

Feel free to contact me if you want help in writing the documentation.

https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

[toc] | [next] | [standalone]


#179715

FromBrian <ad44@cityscape.co.uk>
Date2017-04-02 21:00 +0200
Message-ID<trSTf-4gk-3@gated-at.bofh.it>
In reply to#179713
On Sun 02 Apr 2017 at 18:36:25 +0200, Marc SCHAEFER wrote:

> with a basic Debian jessie install and a recent Firefox, I observe the
> following:
> 
>    [1] Debian has no specific support for detecting captive networks
>        (e.g. Android, iOS) and redirecting automatically the browser to
>        the captive login page
> 
>    [2] launching Firefox on the default page doesn't work (doesn't get
>        redirected properly to the login page but fails with a HTTPS
>        certificate error), if there is a recent HSTS[*] security
>        configuration cache for the default domain page (e.g. google.com)
> 
> [1] is not really an issue: I wouldn't like myself that connecting to
> a WiFi captive network starts a browser. Also, open captive networks are
> messing up, dangerous, a WPA/RADIUS auth would be much better.
> 
> However, open captive networks are quite commons in hotels, airports,
> parks, etc.  So it cannot be dismissed.
> 
> [2] the only fix is to type an URL you know is HTTP, not HTTPS and does
> not configure HSTS, and does not support DNSSEC. In my case I used
> ptiturl.ch
> 
> Maybe this could be in the Debian User manual somehow?
> 
> Feel free to contact me if you want help in writing the documentation.
> 
> https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

Probably the best place for this is the wiki. Anyone can create a page
on the topic of captive networks there. Maybe there one is in existence
which can be added to. Feel free to add to such a page or start a new
one.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#179716

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2017-04-02 21:30 +0200
Message-ID<trTmh-4Gv-3@gated-at.bofh.it>
In reply to#179715
On Sun, Apr 02, 2017 at 07:51:40PM +0100, Brian wrote:
> Probably the best place for this is the wiki. Anyone can create a page
> on the topic of captive networks there. Maybe there one is in existence
> which can be added to. Feel free to add to such a page or start a new
> one.

I did not find any, so I created:

   https://wiki.debian.org/CaptivePortal

Thank you for the suggestion.

[toc] | [prev] | [next] | [standalone]


#179717

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-04-02 22:30 +0200
Message-ID<trUil-5is-1@gated-at.bofh.it>
In reply to#179716
On Sun 02 Apr 2017 at 21:20:30 (+0200), Marc SCHAEFER wrote:
> On Sun, Apr 02, 2017 at 07:51:40PM +0100, Brian wrote:
> > Probably the best place for this is the wiki. Anyone can create a page
> > on the topic of captive networks there. Maybe there one is in existence
> > which can be added to. Feel free to add to such a page or start a new
> > one.
> 
> I did not find any, so I created:
> 
>    https://wiki.debian.org/CaptivePortal

That was quick!

IIRC I have in the past typed   ip route show
and then pasted the IP of the default route into the browser.
Am I remembering correctly, and would that IP address obey
your conditions outlined earlier?

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#179721

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2017-04-03 12:40 +0200
Message-ID<ts7yV-5Em-1@gated-at.bofh.it>
In reply to#179717
On Sun, Apr 02, 2017 at 03:20:56PM -0500, David Wright wrote:
> IIRC I have in the past typed   ip route show
> and then pasted the IP of the default route into the browser.
> Am I remembering correctly, and would that IP address obey
> your conditions outlined earlier?

That would work too, even if default router is
not the captive portal itself.  Let's put that in the doc.

[toc] | [prev] | [next] | [standalone]


#179719

From<tomas@tuxteam.de>
Date2017-04-03 09:30 +0200
Message-ID<ts4B4-3Mv-17@gated-at.bofh.it>
In reply to#179716
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun, Apr 02, 2017 at 09:20:30PM +0200, Marc SCHAEFER wrote:

[...]
> I did not find any, so I created:
> 
>    https://wiki.debian.org/CaptivePortal

\o/

Thanks!
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAljh+dcACgkQBcgs9XrR2kbBFACfan9XUNfJg4n0LM8rc9R6OuH/
+rIAnjb3Jw48xjIYvEGt1PwMevadTff+
=7WUV
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179735

FromDarac Marjal <mailinglist@darac.org.uk>
Date2017-04-03 15:00 +0200
Message-ID<ts9Kq-6Yw-5@gated-at.bofh.it>
In reply to#179713
On Sun, Apr 02, 2017 at 06:36:25PM +0200, Marc SCHAEFER wrote:
>Hello,
>
>with a basic Debian jessie install and a recent Firefox, I observe the
>following:
>
>   [1] Debian has no specific support for detecting captive networks
>       (e.g. Android, iOS) and redirecting automatically the browser to
>       the captive login page
>
>   [2] launching Firefox on the default page doesn't work (doesn't get
>       redirected properly to the login page but fails with a HTTPS
>       certificate error), if there is a recent HSTS[*] security
>       configuration cache for the default domain page (e.g. google.com)
>
>[1] is not really an issue: I wouldn't like myself that connecting to
>a WiFi captive network starts a browser. Also, open captive networks are
>messing up, dangerous, a WPA/RADIUS auth would be much better.
>
>However, open captive networks are quite commons in hotels, airports,
>parks, etc.  So it cannot be dismissed.
>
>[2] the only fix is to type an URL you know is HTTP, not HTTPS and does
>not configure HSTS, and does not support DNSSEC. In my case I used
>ptiturl.ch
>
>Maybe this could be in the Debian User manual somehow?
>
>Feel free to contact me if you want help in writing the documentation.
>
>https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
>

I believe the way Android works is, when the network interface changes,
a request is fired off to a known page on Google. If that page returns a
known HTTP code (200, I think), then everything is OK. But if it returns
301 (Moved Permanently), 302 (Found) or, preferably 511 (Network
Authentication Required), then a one-shot browser is opened.

I think this would be a great feature request for Network-Manager (which
has the abiliity to monitor the network AND has a GUI AND is part of the
default Debian).

-- 
For more information, please reread.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web