|
|
|
|
|
by CaveTech
1800 days ago
|
|
I believe NCSI probes are also purposefully HTTP because captive portals MITM all traffic to force authentication. If it was HTTPS the probe would fail with a certificate error. The whole point is that the url can be hijacked. This is not really a vulnerability, they have just independently discovered this feature. |
|
Opening the browser automatically is a big bug, that should be easy to fix.