Live data from Hacker News

How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

iphonedownloadblog.com

11–20 of 46 posts

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#11
Last week at a conference, I spoke briefly to an engineer from one of the large two US telcos on this issue. He indicated they utilized a variety of methods, including utilized fingerprinting of the IP/TCP headers, and protocol analysis to help identify traffic. Specifically, I heard TTL mentioned, as well. He might be a user here.

There are more knowledgeable people than you working on the issue. That said, I haven't gotten an evil text from using PDAnet, yet. Then again, I don't tether that much and when I do it's not a lot of data.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#13
post #11

Last week at a conference, I spoke briefly to an engineer from one of the large two US telcos on this issue. He indicated they utilized a variety of methods, including utilized fingerprinting of the IP/TCP headers, and protocol analysis to help identify traffic. Specifically, I heard TTL mentioned, as well. He might be a user here. There are more knowledgeable people than you working on the issue. That said, I haven'…

If you want to be safe, run a VPN on the phone and route all your traffic, tethered or not, through that.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#14
post #6

A couple of years back, federal regulators (thanks to the efforts of EFF) declared that jailbreaking an IPhone is not illegal. Since then, Apple has stopped threatening users with jailbroken IPhones, and also, finding and patching new vulnerabilities that allow jailbreaking has become a moot point. In the same vein, has there ever been a verdict on the legality of unofficial (MyWi-like) tethering?

There's a huge difference between jailbreaking an iPhone, which the EFF established doesn't (necessarily) violate the DMCA, and breaking your contract by using services from AT&T that you're not paying for. The first means using something you bought and paid for in a way the manufacturer doesn't want you to. The second means using a service that the provider charges for, but you're not paying for. The law is never go…

The second means using a service that the provider charges for, but you're not paying for. The law is never going to protect the second one.

Unless we get strong wireless net neutrality.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#15
post #6

A couple of years back, federal regulators (thanks to the efforts of EFF) declared that jailbreaking an IPhone is not illegal. Since then, Apple has stopped threatening users with jailbroken IPhones, and also, finding and patching new vulnerabilities that allow jailbreaking has become a moot point. In the same vein, has there ever been a verdict on the legality of unofficial (MyWi-like) tethering?

There's a huge difference between jailbreaking an iPhone, which the EFF established doesn't (necessarily) violate the DMCA, and breaking your contract by using services from AT&T that you're not paying for. The first means using something you bought and paid for in a way the manufacturer doesn't want you to. The second means using a service that the provider charges for, but you're not paying for. The law is never go…

Tethering isn't a service though. The service is the data transfer. Tethering is a feature of the phone (which you own, especially if out of contract).

Here's a metaphor: Imagine if the water company charged you per gallon for water you used, but then added an additional charge for having a shower. Since you own plumbing fixtures to which the shower connects, and pay for every gallon, we would consider it unfair for the water company to charge extra for an "authorized" shower.

As far as theft of service, what on earth have you stolen? You pay for the data you transfer. Tethering is simply an "unauthorized" (by the vendor) use of that data.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#16
post #5

Does anyone know if tethering can be detected on Android phones? I'm curious what other provides do to try to detect tethering on Android phones.

I wrote a non-root tethering app, so I might have a bit of tunnel vision.

First, any good tethering app should be immune to a simple TTL check. The most likely culprits are instead application traffic patterns. The following immediately come to mind:

- Browser user agents

- Automatic status checks under both OS X and Windows

- Application behavior:

* Netflix and Hulu on Android isn't supposed to happen.

* Browsers like Chrome are very aggressive and can open dozens of simultaneous TCP connections. DNS prefetching can also generate dozens of requests over UDP in a very short time window.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#17
Note: TetherMe (native tethering on jailbroken iPhones) sends all tethered data through the same APN as mobile data by default so users won't fall foul of the APN detection method mentioned here.

Of course that wouldn't stop AT&T & Co sniffing browser strings of high data users, but that's a more complicated system to implement.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#18
post #6

A couple of years back, federal regulators (thanks to the efforts of EFF) declared that jailbreaking an IPhone is not illegal. Since then, Apple has stopped threatening users with jailbroken IPhones, and also, finding and patching new vulnerabilities that allow jailbreaking has become a moot point. In the same vein, has there ever been a verdict on the legality of unofficial (MyWi-like) tethering?

There's a huge difference between jailbreaking an iPhone, which the EFF established doesn't (necessarily) violate the DMCA, and breaking your contract by using services from AT&T that you're not paying for. The first means using something you bought and paid for in a way the manufacturer doesn't want you to. The second means using a service that the provider charges for, but you're not paying for. The law is never go…

> The (slightly) more interesting legal question might be whether AT&T could ask a prosecutor to bring criminal charges. My uninformed guess is they could, based on something like "theft of services." If I charged $20 a month for you to come fill up a one-gallon bucket any time you wanted from my well, and instead of a bucket you filled up a tanker truck, it would be theft plain and simple, because you'd knowingly be taking something from me without my permission.

What I don't understand is how they decide how much to charge for tethering, especially for the capped data plans. Presumably, whether you download 2GB of data straight to your phone vs. 2GB of data through your phone to your laptop doesn't affect their ability to provide network service, so why should they care? In that case, they're simply charging more because some people will pay it. I understand that, but it still rubs me the wrong way.

Re: How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones

#19
post #15
post #6

Earlier quoted context omitted.

There's a huge difference between jailbreaking an iPhone, which the EFF established doesn't (necessarily) violate the DMCA, and breaking your contract by using services from AT&T that you're not paying for. The first means using something you bought and paid for in a way the manufacturer doesn't want you to. The second means using a service that the provider charges for, but you're not paying for. The law is never go…

Tethering isn't a service though. The service is the data transfer. Tethering is a feature of the phone (which you own, especially if out of contract). Here's a metaphor: Imagine if the water company charged you per gallon for water you used, but then added an additional charge for having a shower. Since you own plumbing fixtures to which the shower connects, and pay for every gallon, we would consider it unfair for…

However, the water company will most definitely come looking for you if you start selling water to the neighboring town that has higher water prices, since then you are profiting from your subsidized water.

The real problem is that somehow the wireless companies, unlike residential ISPs, have gotten away with not being labeled as pure data transfer companies. It should be none of their business what data you send, but unfortunately that's not (legally) the case.

Post reply on HN