The reason I say that about the latter is that all a threat actor needs
to do is stand up an AP with a honeypot that mimics your captive
portal's login screen, and then goes to a page that says, "Oops,
something went wrong. Click here to try again" a...