Skip to content

Notes ·

A Fake Airline Hotspot Picked the Worst Possible Flight

Ars Technica reports that a rogue Wi-Fi hotspot impersonating Delta’s onboard network was discovered on a flight carrying passengers home from DEF CON.

The technique is an evil twin attack: broadcast a network that looks like the legitimate one and wait for people to connect. Delta actually instructs passengers to join a network named DeltaWiFi.com, making an identically named rogue access point especially convincing.

What makes this story notable is not the attack. Evil-twin Wi-Fi has existed for years.

It is that somebody apparently tried it around a crowd unusually qualified to notice.

DEF CON itself warns attendees about duplicate and malicious SSIDs, and its network team routinely sees people broadcasting networks designed to impersonate familiar services.

Ars appropriately describes the DEF CON connection as suspected. Finding the rogue hotspot does not establish who operated it or prove that a conference attendee was responsible.

Still, there is something wonderfully stupid about attempting a fake-hotspot attack on a flight potentially full of security researchers who just spent several days looking for exactly this kind of thing.

The attack got noticed.

Sometimes the threat model fights back.

Read the Ars Technica report.

All notes