The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 1,860 other subscribers

Archive for the ‘Captive-WiFi-Portal’ Category

NeverSSL – helping you get online on WiFi networks requiring authentication

Posted by jpluimers on 2023/07/07

[Wayback/Archive] NeverSSL – helping you get online.

What?

This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type “http://neverssl.com” into your browser’s url bar, and you’ll be able to log on.

How?

neverssl.com will never use SSL (also known as TLS). No encryption, no strong authentication, no HSTS, no HTTP/2.0, just plain old unencrypted HTTP and forever stuck in the dark ages of internet security.

While writing it in 2022, the site would redirect me to http://oldserenewonderousbirds.neverssl.com/online, http://beautifulgrandoldspell.neverssl.com/online and http://majesticsilveroldeclipse.neverssl.com/online, which will change probably each time to deter DNS caching, as per this message when I disabled JavaScript:

⚠️ JavaScript appears to be disabled. NeverSSL’s cache-busting works better if you enable JavaScript for neverssl.com.

Why NeverSSL

Because NeverSSL always uses plain unencrypted HTTP traffic, any captive portal WiFi or wired network can easily sneak in or redirect to authentication.

That way you can logon, after which you can use encrypted HTTPS/SSL/TLS/HSTS traffic.

Via

DNS hijacking can be used too

Leading to the above was this post by b0rk: [Wayback/Archive] how airports lie to you with DNS.

Via:

–jeroen

Posted in Captive-WiFi-Portal, Power User, WiFi | Leave a Comment »