109
submitted 6 months ago* (last edited 6 months ago) by coffeeClean@infosec.pub to c/cybersecurity@infosec.pub

I plugged into ethernet (as wifi w/captive portal does not work for me). I think clearnet worked but I have no interest in that. Egress Tor traffic was blocked and so was VPN. I’m not interested in editing all my scripts and configs to use clearnet, so the library’s internet is useless to me (unless I bother to try a tor bridge).

I was packing my laptop and a librarian spotted me unplugging my ethernet cable and approached me with big wide open eyes and pannicked angry voice (as if to be addressing a child that did something naughty), and said “you can’t do that!”

I have a lot of reasons for favoring ethernet, like not carrying a mobile phone that can facilitate the SMS verify that the library’s captive portal imposes, not to mention I’m not eager to share my mobile number willy nilly. The reason I actually gave her was that that I run a free software based system and the wifi drivers or firmware are proprietary so my wifi card doesn’t work¹. She was also worried that I was stealing an ethernet cable and I had to explain that I carry an ethernet cable with me, which she struggled to believe for a moment. When I said it didn’t work, she was like “good, I’m not surprised”, or something like that.

¹ In reality, I have whatever proprietary garbage my wifi NIC needs, but have a principled objection to a service financed by public money forcing people to install and execute proprietary non-free software on their own hardware. But there’s little hope for getting through to a librarian in the situation at hand, whereby I might as well have been caught disassembling their PCs.

(page 2) 50 comments
sorted by: hot top controversial new old
[-] Doom4535@lemmy.sdf.org 7 points 6 months ago* (last edited 6 months ago)

This sounds odd to me, unless you connected to an Ethernet port behind a desk or somehow forced open a network closet… They also might not like it if you disconnected one of the public computers to use its cable/port; otherwise if this was an open and public port, you used it as designed and the librarian probably has watched too many Hollywood hacking movies. I have to admit, I never thought of this as a way to bypass the captive portal (sorta just assumed everyone going through the public network would have to hit it, kinda of the equivalent to having everyone sign a liability waiver).

With that said, I can see some institutions not liking connections that aren’t part of the more traditional/commercial networking (but it doesn’t sound like the library took issue with your traffic, just the librarian didn’t like the PHY link you chose to use). For the SMS thing (I haven’t seen that used in a while, you might be able to use some sort of burner number app if they don’t filter them).

[-] DoomBot5@lemmy.world 5 points 6 months ago

I have to admit, I never thought of this as a way to bypass the captive portal (sorta just assumed everyone going through the public network would have to hit it, kinda of the equivalent to having everyone sign a liability waiver).

That's because if that library's network was properly configured it would work exactly like your expectation.

[-] Dukeofdummies@kbin.social 6 points 6 months ago

I'm not surprised. I know people who don't even know what an ethernet cable is. I've worked enough IT to realize that a tangled mess of 6 cables can be as horrifying as a Predator to people. It doesn't help that everything is slowly going to POE, POE+ and even ++ now so it's doubling as power as well. In analog video days I could look at the back of a random device and instantly figure out it's purpose. That's rapidly becoming a rarity. For a worrisome section of the population, plugging in an ethernet cable is the equivalent of building a table or performing a back flip.

And when it comes to hacking, good god nobody knows anything. I remember we had a dozen students in high school (around 2000ish?) get suspended for "hacking" and really it was just that a section of the student body found a network storage location without any password protection and were using it as a flash drive on school grounds. Literally they just suspended anybody who signed their name on the homework assignments stored there.

The real crime was that drive had lunch pins for all the accounts in plain text to run their system, without a password!

[-] jol@discuss.tchncs.de 6 points 6 months ago

10+ years ago you had to bring your own ethernet cable to the University library because the WiFi couldn't handle all the students at peak times. Wo der if it's still the case.

[-] hagar@lemmy.ml 3 points 6 months ago

have a principled objection to a service financed by public money forcing people to install and execute proprietary non-free software on their own hardware

You are on spot there, but sadly even legislators are far from understanding the reasons why this matters so much, let alone the general public.

Whatever security policy they have, it shouldn't require you installing a random executable to your system. And it was flawed enough that it didn't care to give your device access.

And by the way, it's so awesome you carry an ethernet cable around!!

[-] LoamImprovement@beehaw.org 2 points 6 months ago

I mean, I asked at a library if I could plug into the Ethernet because my laptop had an RJ45 port and I needed to download something sizable for work and the WiFi was dropping it. They let me hook up on one of the library computer ports and I left it the way I found it.

load more comments (1 replies)
[-] just_another_person@lemmy.world 2 points 6 months ago

It's not the librarians issue to worry about. It's the IT team supporting your library. If there wasn't a sign that said "not for customer use", then it's fine.

[-] xor@infosec.pub 2 points 5 months ago

it's clearly there to be used, a lot of places have ethernet jacks for that...
the librarian is just a luddite and you probably had a black hoodie and a terminal open so she assumed you were selling fentanyl to pedophile ransomware communists...

load more comments
view more: ‹ prev next ›
this post was submitted on 29 Apr 2024
109 points (100.0% liked)

cybersecurity

3231 readers
1 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 1 year ago
MODERATORS