7 hours ago · 10 min read2039 words · Tech · hide · 0 comments

Hotel Wi-Fi asks us to make a strange trade. We trust a network we have never seen, operated by people we will never meet, using equipment we cannot inspect, because cellular service is weak and we need to answer an email.Sometimes the network has a password printed on the room key sleeve. Sometimes the front desk confirms the network name. Neither one tells us whether the gateway is patched, the guest network is properly isolated, the DNS responses are honest, or somebody else has gained administrative control of the equipment.That is no longer a theoretical warning.Microsoft recently documented a campaign it calls CaptiveCrunch, in which attackers compromised hospitality networks and manipulated the traffic passing through captive portals. Guests were redirected to fake browser and operating system updates, device-code phishing pages, and malware delivery infrastructure. The network itself became part of the attack.This is why I use a VPN on hotel, airport, conference, café, and…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.