Hacker News new | ask | show | jobs
by tripzilch 4254 days ago
Because the "WiFi in de trein" network could be anywhere. It's the name of the free wifi of one of the large public transport / train corporations in the Netherlands.

The only solution is to not autoconnect, ever, or some sort of clever certificate pinning type of solution. Like, I could download the certificate from the (https) site of the train company, and be sure that the network I see claiming to be "WiFi in de trein" is in fact theirs. Ziggo (a Dutch ISP) does something like that when they turn all their customers' wifi-routers into semi-public access-points (for Ziggo customers). Unfortunately their solution has a few snags, as well (but it's really cool, I basically don't need a data plan).