http.alpagot.net · port 80 · no padlock, no problem

Plain HTTP,
on purpose.

A page that is deliberately not secure — so the WiFi login screen on your train, plane or hotel can actually reach you.

# the entire conversation this page needs $ curl -v http://http.alpagot.net/ > GET / HTTP/1.1 > Host: http.alpagot.net < HTTP/1.1 200 OK < content-type: text/html; charset=utf-8 < x-served-by: cache-cmh1290021-CMH < x-origin-contacted: never

this copy was assembled at the Fastly CMH POP, just for you

WHY THIS EXISTS

The WiFi login page that never shows up

You sit down on a train, join the free WiFi, and… nothing. No login screen, no terms to accept — just pages that refuse to load. The hotspot is waiting for you to visit its portal, but your browser never gives it the chance.

Keep this page bookmarked. Open it whenever a public network is sulking, and the login screen should appear immediately.

HOW IT WORKS

Why HTTPS gets in the way

Captive portals work by hijacking one of your requests and answering it with their own login page. That trick is exactly what HTTPS is designed to prevent — so when a portal tries it on a secure site, your browser throws up a scary certificate warning that you should never click past.

Since nearly the whole web is HTTPS now, portals have almost nothing left to hijack. This page is the exception: it is served over plain, unencrypted HTTP, so the portal can swap it for the login screen cleanly, with no warnings and no risk.

Nothing sensitive ever travels over this connection — it is a static page with no forms, no cookies and no logins. Insecure by design, and safe precisely because of it.

USE IT

Bookmark it, share it, keep it handy

You are welcome to use this page and link to it from anywhere. The only rule: it must stay http:// — an https:// version would defeat the entire point (and this hostname does not even offer one).

http://http.alpagot.net

Tip: a bookmark keeps the scheme intact. Typing it into the address bar may get upgraded to https:// by some browsers.

UNDER THE HOOD

No origin, no assets, no excuses for being slow

This site has no web server behind it. It runs as a Fastly VCL service where every response — this page included — is a synthetic response built inside vcl_error at the edge. A request arrives at the Fastly POP nearest to you (right now: CMH), VCL writes the HTML straight into the response, and it is on the wire. No origin fetch, no cache miss penalty, because there is nothing to miss.

The page itself is engineered to need exactly one round trip: a single HTML document with inline CSS, an inline SVG favicon, a dozen lines of inline JavaScript, and system fonts. Zero images, zero webfonts, zero subrequests. And with no TLS, there is no certificate exchange either — the first byte follows the TCP handshake almost immediately.

0origin servers
1request, total
<16 KBwhole site
everyFastly POP serves it

Everything else the site answers — robots.txt, llms.txt, sitemap.xml, security.txt, humans.txt, even the favicon — is synthesised in VCL too. The icons are binary, so they ship as synthetic.base64, and every text response is brotli- or gzip-compressed on its way out of the POP by a single X-Compress-Hint header.

It also sends Cache-Control: no-store — counterintuitive for a CDN engineer, but a browser-cached copy would stop the portal from ever seeing your request. Every visit must go out over the network. That is the product.

WHO BUILT THIS

Richard Alpagot

Senior Cloud Engineer at Fastly, helping customers make the web faster and safer — and occasionally, very deliberately, less encrypted.