• 3 Posts
  • 15 Comments
Joined 7 months ago
cake
Cake day: June 29th, 2025

help-circle






  • SSL stripping, DNS spoofing, captive portal attacks, leaky metadata attacks (which can and have been reported to happen with popular VPNs)

    Lest we forget more and more companies are firing their senior devs and replacing them with college grad vibe-coders? Leading to an uptick in exploits and botched code.

    Probably the biggest vulnerability is the captive portal. There is no way to verify you’re connecting to an official Starbucks router.

    And of course there’s the zero days we don’t even know about.

    What if your system has an unpatched vulnerability? You postponed that Windows update, or your Linux kernel is behind on patches, or even your firmware is vulnerable. Maybe you forgot to install the firmware update, or maybe your hardware vendor doesn’t support your specific NIC anymore. A compromised router could exploit network-facing bugs to attack you directly.

    I personally wouldn’t connect to a public router if you held a gun to my head.