Hacker News new | ask | show | jobs
by arm32 4 days ago
But what about HSTS and HSTS preloading? This sounds more like a deauth/captive portal phish to me.
1 comments

the hotspot was pwned and abused

this is a more detailed, and first order account of things from reliaquest itself.

https://reliaquest.com/blog/threat-spotlight-dns-poisoning-t...

apparently a full funnel VPN policy prevents the workflow.