So, yeah. The wpa_supplicant bug only lets you *impersonate* an AP. It does *NOT* let you MITM it or passively decrypt. This is important.
But I can already walk up to the office and impersonate the local Starbucks SSID and deauth people & MITM all your internet access too :-)
-
-
…well played but yeah the solution is ultimately things like thispic.twitter.com/EVmgW19aLj
-
also, did you see that Google's putting _TLDs_ in the HSTS preload list now like, ones it's intending to open to public registration
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.