Live data from Hacker News

Bypassing Gogo’s Inflight Internet Authentication

bryceboe.com

1–10 of 57 posts

Re: Bypassing Gogo’s Inflight Internet Authentication

#2
I've yet to find one of these types of services that you can't access by spoofing the MAC address of a real customer.

A while back, Intel removed MAC address spoofing from some of its wireless cards through a driver update, citing vague "security" concerns. I felt very up in arms about it for a while (why on Earth would you hobble your customer's products so you can make sure they can't violate your moral code!), but eventually decided I couldn't really complain, since the only reason I could think of that I might want such an ability would be to steal internet access.

Re: Bypassing Gogo’s Inflight Internet Authentication

#4

I've yet to find one of these types of services that you can't access by spoofing the MAC address of a real customer. A while back, Intel removed MAC address spoofing from some of its wireless cards through a driver update, citing vague "security" concerns. I felt very up in arms about it for a while (why on Earth would you hobble your customer's products so you can make sure they can't violate your moral code!), but…

When you say they 'removed MAC address spoofing', do you mean that they removed features that allow the card to work having duplicated an active address, or do you mean that they removed the ability for you to set the address at all? The latter has many uses, including simply not being tracked across every network session. To add this kind of antifeature truly is hobbling their customers' devices in pursuit of someone else's security.

Re: Bypassing Gogo’s Inflight Internet Authentication

#5
post #3

don't blow up the spot

Sheesh, kids these days. 'Responsible disclosure' used to be about not screwing over the numerous people running a piece of software. Then it became about helping websites implementing software to regress us back to centralized computing. And now it's apparently about helping preserve clunky business models by helpfully suggesting exploiting weaknesses in TLS. What's up next, volunteer implementations of using nmap for client OS fingerprinting so they're even better able to extra money from more-capable device owners? Or helping to conceal the latest government trojan? Sigh.

Re: Bypassing Gogo’s Inflight Internet Authentication

#6
post #3

don't blow up the spot

Sheesh, kids these days. 'Responsible disclosure' used to be about not screwing over the numerous people running a piece of software. Then it became about helping websites implementing software to regress us back to centralized computing. And now it's apparently about helping preserve clunky business models by helpfully suggesting exploiting weaknesses in TLS. What's up next, volunteer implementations of using nmap f…

I'm wondering (honest question) why do you believe that Gogo business model is clunky?

Re: Bypassing Gogo’s Inflight Internet Authentication

#7
I'm amazed by some of the comments like "Wow great article. I knew there must be a way to avoid paying." and by author's apparent believe that contacting the support several times via twitter and not getting a response morally justifies sharing his recipe with other people and wishing them "Happy “free” surfing, for now anyway".

Stealing is stealing, no matter what "justification" one may have about high prices.

edit: grammar

Re: Bypassing Gogo’s Inflight Internet Authentication

#8
post #7

I'm amazed by some of the comments like "Wow great article. I knew there must be a way to avoid paying." and by author's apparent believe that contacting the support several times via twitter and not getting a response morally justifies sharing his recipe with other people and wishing them "Happy “free” surfing, for now anyway". Stealing is stealing, no matter what "justification" one may have about high prices. edit…

"This bakery's bread is OKish, but $10 is too much to pay for a loaf. But I found a cool trick: when you're offered to take a free sampler, you can actually take the whole lot while the owner is not watching.

I sent him couple of postcards telling about this but he never responded, so enjoy this free bread while you can!"

Re: Bypassing Gogo’s Inflight Internet Authentication

#9
post #8
post #7

I'm amazed by some of the comments like "Wow great article. I knew there must be a way to avoid paying." and by author's apparent believe that contacting the support several times via twitter and not getting a response morally justifies sharing his recipe with other people and wishing them "Happy “free” surfing, for now anyway". Stealing is stealing, no matter what "justification" one may have about high prices. edit…

"This bakery's bread is OKish, but $10 is too much to pay for a loaf. But I found a cool trick: when you're offered to take a free sampler, you can actually take the whole lot while the owner is not watching. I sent him couple of postcards telling about this but he never responded, so enjoy this free bread while you can!"

And when you're done sampling, the whole bread is gone, just like in the case of internet access, right?

Re: Bypassing Gogo’s Inflight Internet Authentication

#10
post #9
post #8

Earlier quoted context omitted.

"This bakery's bread is OKish, but $10 is too much to pay for a loaf. But I found a cool trick: when you're offered to take a free sampler, you can actually take the whole lot while the owner is not watching. I sent him couple of postcards telling about this but he never responded, so enjoy this free bread while you can!"

And when you're done sampling, the whole bread is gone, just like in the case of internet access, right?

Given that GoGo is like 3.1 megabits shared between dozens of people on a plane, yeah.

Also, the "marginal cost of information/bandwidth/etc is zero" is specious. You are not entitled to get things for their marginal cost. I can't take a Prada handbag out of store and leave the $50 marginal cost of the bag + $10 for restocking.

Post reply on HN