How Many Ways Can OneZone Fail?
November 9th, 2009
Stop me if you’ve heard this one… I’m at the court house waiting to find out if I’ll be selected for jury duty. The only WiFi network available is OneZone, but:
- The signup pages are all HTTP, not HTTPS (which means my credit card information and home address just flew threw the ether unencrypted), and
- Once I sign up (yeah, I did it anyway, I’m that desperate for bandwidth) the system echoes back my user ID and password on another unsecure page in plaintext.
Who are these people? And why are they still employed? *sigh*
Later: it may be insecure, but at least it’s slow…
I’d never heard of them but their website says they’re COGECO. That would explain it.
This is the employer / developer side of a common issue:
http://www.schneier.com/blog/archives/2009/08/risk_intuition.html
“Given this accurate risk analysis, any rational employee will regularly circumvent security to get his or her job done. That’s what the company rewards, and that’s what the company actually wants.”
This hypothesis supported by the fact that, despite your security concerns, you signed up for the service.
I used my Boingo account to authenticate.
The page you enter data on, does not have to be itself secure. Only the destination of the form post. Even the resulting page does not have to be secure if it was re-directed. Did you browser throw an error about posting insecure content? (did you disable this some time in the past?)
Showing you your login information view plain HTTP is not ideal, but as long as that information can’t be used to retrieve your account info, it’s not that bad (bad, just not epic bad).
I have not confirmed any of this stuff as I’m not near one of those hot spots at the moment.
I’ve never had One Zone perform acceptably. Part of it is the distance limitations of WiFi I think. As much as Rogers is reviled I have switched to almost always tethering over my iPhone. I get decent Internet everywhere there’s a cell signal.
OneZone was always marginal. Since the deal with iPass, it has become totally useless. I have stood under one of their barrels at 1 in the morning and observed throughput as low as ONE KILOBIT! That would be deemed very poor even for dialup! Since my company pays for it, I can only grumble and bitch, not switch.
Rogers is fine a) if you have money to throw away, and b) if you NEVER need support. Blood suckers. Rumour has it that half the people at old Ted’s funeral were there to make sure he was really dead.