On 2011-12-21 19:23, Ted Lemon wrote:
Isn't this talking about captive portals? If so, then *after* authentication you
get unmodified DNS and HTTP; before authentication, you get forged DNS responses
that force you to the captive portal.
Just for the sake of discussion...
Captive portals that modify DNS responses are exceedingly rare. Usually, captive
portals work by NATing the destination address of packets emitted from clients
having an unauthenticated link-layer addresses. The reason, I presume, is that
DNS responses get cached by the OS and/or application, so sending "wrong" DNS
responses to clients just doesn't work well.
Simon
--
DTN made easy, lean, and smart --> http://postellation.viagenie.ca
NAT64/DNS64 open-source --> http://ecdysis.viagenie.ca
STUN/TURN server --> http://numb.viagenie.ca
_______________________________________________
mif mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mif