Captive portals are even worse than you thought.

I just came across this article about captive portals (these annoying websites that force you to a “accept TOS” page on public wifis) that we all hate so much.

I can only agree with what’s said in there, to 200%, but it’s even worse than that: A captive portal is a real danger to the security of your mobile device.

An attacker could easily setup a microcomputer for 15$ to run as access point, and send out the SSID of a well known public WiFi, and then redirect every client to a version of that WIFI’s captive page that has malicious things built it. It could trick you into giving away your credit card information, social security number, or any other valuable information, or maybe even worse, install backdoors on your device.

Say NO to captive portals.

