New OPSEC post coming...
Don't use public WiFi.
https://nostr.build/av/3c149dbee38967790d419b8a3b65487f309be51a793de0dcffada2f8f71de413.mp4

New OPSEC post coming...
Don't use public WiFi.
https://nostr.build/av/3c149dbee38967790d419b8a3b65487f309be51a793de0dcffada2f8f71de413.mp4

Or if you do make sure you are connected to a trusted VPN. I run my own wireguard VPN so I'm always connected to home on the go.
VPN is always a good idea but it wouldn't protect against an evil portal attack.
I would never pick a real Google account to login to a wifi, or more or less anything. And even if I got a WebAuth key to protect my main accounts.
But yeah, some might get tricked.
Six people put in real account details over the space of half an hour. No 2FA either.
We're all tech savvy here but normies get rekt. I'm writing about it in the hope plebs spread the word to their normie friends and family.
Most people just blindly trust captive portals and almost every captive portal uses plain HTTP.