68 points

None of the actual matters and this attack is rarely used these days. 99.9% of shit is encrypted “over the line”. Unless you have some tls zero day you ain’t getting shit besides leaked DNS.

permalink
report
reply
1 point

Can’t the hacker though spoof some fake websites and trick you into giving your information? If they control the WiFi they control the DNS don’t they?

permalink
report
parent
reply
-1 points

I’m mean sure if they have mapping for every major bank and target they are going for and a good enough fake to back it up.

But it’s such a low success rate with it being easy to be caught is practically not done.

permalink
report
parent
reply
54 points

Well it actually isn’t thaat bad.

Nowadays every website is encrypted

permalink
report
reply
19 points

The connection to the website is encrypted, but you are right, it’s not like pre HTTPS badness

I assume the good ol’ E-Mail Spam Business is still going strong and getting stronger. If more people make business online, the more will fall to the “there’s a problem with your account, please re-enter your credentials” bait.

I’ve even seen phrases like: your account may have been compromised, please enter now your credentials to fix the problem and add a laver of protection to your privacy.

In the last few weeks, I got the same “your account is on hold” ( font in google colors ), always from a different sender, multiple times a day … Flagging these as Spam has no effect.

permalink
report
parent
reply
2 points

Makes sense. How about apps? I often read about popular apps that are not encrypting their traffic.

permalink
report
parent
reply
8 points
*

It’s basically the same. Nowadays there barely is any app that isn’t using HTTPS

This has been a problem like 5 years ago though. Like TikTok hasn’t been encrypted for a long time. If you’re worried, use a VPN-Tunnel that you trust.

Nowadays the only thing that is unencrypted is the site you’re accessing since the DNS protocol isn’t encrypted, but that’s also changing with the adoption of DNS over HTTPS

permalink
report
parent
reply

me when https and all my traffic is encrypted regardless of if I use a VPN or not

Nice try, NordVPN.

permalink
report
reply
18 points

That’s why I use today’s sponsor, privatenordatlastunnel vpn.

permalink
report
reply
6 points

nonono that one is a honeypot!!! unlike my superior vpn company (it pinky swore it doesnt keep logs)

permalink
report
parent
reply
10 points

Everything is encrypted nowadays, with HTTP or similar. They only get DNS requests (if you use DNS over HTTPS or over TLS, not even that). Unless you have a zero day in your encryption scheme or network stack, you’re fine.

permalink
report
reply

Memes

!memes@lemmy.ml

Create post

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

Community stats

  • 13K

    Monthly active users

  • 12K

    Posts

  • 259K

    Comments