FlyerTalk Forums - View Single Post - United Club Wifi at EWR is mitm'ing docs.google.com
Old Apr 24, 2015 | 8:07 am
  #1  
mherdeg
All eyes on you!
15 Years on Site
 
Join Date: Jan 2009
Location: LHR (sometimes CLE, SFO, BOS, LAX, SEA)
Programs: Dunkin' Rewards Boosted
Posts: 5,915
United Club Wifi at EWR is mitm'ing docs.google.com

Just a quick note that you probably ought to use a VPN when using the Internet connection in the United Club.

Normally when I visit https://docs.google.com/ I get an SSL certificate issued by "Google Internet Authority G2", for cname *.google.com.

When I try to visit Google Docs from the United Club wifi (ssid united_club in the EWR rotunda) I get an angry warning from my Web browser about the SSL certificate I'm being presented — which is quite reasonable, looking at the cert.

The certificate is for "*.google.com" and is issued by Zscaler Intermediate Root CA.

This is not super cool: it looks like the United Club wifi is using transparent proxy filtering via the vendor Zscaler, who includes bogus SSL certificates for common sites so that the intermediate software can read your supposedly private content.

Now, UA is not transparently intercepting content to other sites (mail.google.com and drive.google.com seem to have fine SSL certificates). And I can more or less just use the drive.google.com endpoint to consume Google Docs, but this is still not great. It seems possible that folks without modern Web browsers — or whose computers have been set up to trust the Zscaler intermediate cert authority because they are part of a corporate network setup that use that vendor — might have their supposedly private traffic intercepted by UA systems.

mherdeg is offline