Live data from Hacker News

Bypassing Gogo’s Inflight Internet Authentication

bryceboe.com

11–20 of 57 posts

Re: Bypassing Gogo’s Inflight Internet Authentication

#11
post #9
post #8

Earlier quoted context omitted.

"This bakery's bread is OKish, but $10 is too much to pay for a loaf. But I found a cool trick: when you're offered to take a free sampler, you can actually take the whole lot while the owner is not watching. I sent him couple of postcards telling about this but he never responded, so enjoy this free bread while you can!"

And when you're done sampling, the whole bread is gone, just like in the case of internet access, right?

Internet access on board of a flying plane is non trivial and certainly doesn't come free: you need to install and maintain equipment on board, maintain a network of ground stations, write and debug some software, pay money to other internet providers etc.

With relatively small number of paying customers (yet), you have to keep prices high to maintain the profitability of your business.

Think about this: if nobody pays, they will close this service. Just like the bakery will close if nobody pays for the bread.

Re: Bypassing Gogo’s Inflight Internet Authentication

#12
post #6

Earlier quoted context omitted.

Sheesh, kids these days. 'Responsible disclosure' used to be about not screwing over the numerous people running a piece of software. Then it became about helping websites implementing software to regress us back to centralized computing. And now it's apparently about helping preserve clunky business models by helpfully suggesting exploiting weaknesses in TLS. What's up next, volunteer implementations of using nmap f…

I'm wondering (honest question) why do you believe that Gogo business model is clunky?

Because he wants free shit dammit.

Re: Bypassing Gogo’s Inflight Internet Authentication

#13
post #6

Earlier quoted context omitted.

Sheesh, kids these days. 'Responsible disclosure' used to be about not screwing over the numerous people running a piece of software. Then it became about helping websites implementing software to regress us back to centralized computing. And now it's apparently about helping preserve clunky business models by helpfully suggesting exploiting weaknesses in TLS. What's up next, volunteer implementations of using nmap f…

I'm wondering (honest question) why do you believe that Gogo business model is clunky?

It's a bunch of little niggling aspects that add up into just feeling the whole thing is yet another gimmicky disposable income scoop for out of touch spendthrifts.

1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one.

2. Internet access is only required for most tasks due to people's laziness of using webapps.

3. Alternatively, "yay, I can refresh reddit on a plane"

4. Partial Internet access given before payment, to make it as disruption-free as possible, even though it will necessarily end up admitting things like the original article.

5. These whole "enter your credit card" wifi networks in general. Network access is infrastructure. Yeah, it takes a bit of work to backhaul a plane. But it also took quite a bit of work to build the plane. Just make the infrastructure universal so we can rely on it instead of clouding the thing with massive transaction overhead.

6. Why give the spineless airlines any more money than you have to? This attitude is subject to change when they start sticking up for their customers by giving the TSA the boot.

But honestly I'm doubt I'm going to win any points for these views on HN. I should probably just turn my commenting threshold back down.

Re: Bypassing Gogo’s Inflight Internet Authentication

#14

I've yet to find one of these types of services that you can't access by spoofing the MAC address of a real customer. A while back, Intel removed MAC address spoofing from some of its wireless cards through a driver update, citing vague "security" concerns. I felt very up in arms about it for a while (why on Earth would you hobble your customer's products so you can make sure they can't violate your moral code!), but…

When you say they 'removed MAC address spoofing', do you mean that they removed features that allow the card to work having duplicated an active address, or do you mean that they removed the ability for you to set the address at all? The latter has many uses, including simply not being tracked across every network session. To add this kind of antifeature truly is hobbling their customers' devices in pursuit of someon…

In fact, a story about MAC spoofing for privacy is on front page of HN today: http://erratasec.blogspot.com/2013/01/i-conceal-my-identity-...

Re: Bypassing Gogo’s Inflight Internet Authentication

#15
post #6

Earlier quoted context omitted.

I'm wondering (honest question) why do you believe that Gogo business model is clunky?

It's a bunch of little niggling aspects that add up into just feeling the whole thing is yet another gimmicky disposable income scoop for out of touch spendthrifts. 1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one. 2. Internet access is only required for most tasks due to people's laziness of using webapps. 3. Alternatively, "yay, I can refresh…

>Internet access is only required for most tasks due to people's laziness of using webapps.

Laziness? How is it laziness if the best app for the job happens to be a web app?

Re: Bypassing Gogo’s Inflight Internet Authentication

#17
post #6

Earlier quoted context omitted.

I'm wondering (honest question) why do you believe that Gogo business model is clunky?

It's a bunch of little niggling aspects that add up into just feeling the whole thing is yet another gimmicky disposable income scoop for out of touch spendthrifts. 1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one. 2. Internet access is only required for most tasks due to people's laziness of using webapps. 3. Alternatively, "yay, I can refresh…

Huh? Where do you get this from?

> 1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one.

The device type is a good indicator of bandwidth usage. It's sensible to bill using this model for now. They could use metered bandwith, but something tells me you'd complain about that too.

> 2. Internet access is only required for most tasks due to people's laziness of using webapps.

What does this have to do with anything? People use the internet for all sorts of stupid stuff. I happen to use it mainly for vpn and ssh, but why does it matter?

> 3. Alternatively, "yay, I can refresh reddit on a plane"

So? Again, who cares?

> 4. Partial Internet access given before payment, to make it as disruption-free as possible, even though it will necessarily end up admitting things like the original article.

Partial access is given due to exclusivity deals and that sort of thing. Would you prefer the alternative of just not giving you anything? Who the hell complains about free? Seriously.

> 5. These whole "enter your credit card" wifi networks in general. Network access is infrastructure. Yeah, it takes a bit of work to backhaul a plane. But it also took quite a bit of work to build the plane. Just make the infrastructure universal so we can rely on it instead of clouding the thing with massive transaction overhead.

You do realize that Boeing, Detla, and GoGo are different companies right? Also, it takes a lot more than a "little bit of work to backaul." It took GoGo many many years working with the FAA, ISPs, and others to only just recently get this setup and approved. Look at what's happening with the dreamliner if you want an example of what can go wrong if you do this incorrectly. Finally, most of the planes in a typical airline's fleet are decades old. You can't just bake this cost into the price of the plane (as if that makes sense anyways. not all 747s are passenger planes). With your proposal, we'd maybe get wifi in 2030 (assuming this proposal would be possible at all, which I doubt it would).

> 6. Why give the spineless airlines any more money than you have to? This attitude is subject to change when they start sticking up for their customers by giving the TSA the boot.

OK, seriously, W.T.F. are you talking about? The TSA is employed by the airport, not the airline.

Re: Bypassing Gogo’s Inflight Internet Authentication

#18
post #17

Earlier quoted context omitted.

It's a bunch of little niggling aspects that add up into just feeling the whole thing is yet another gimmicky disposable income scoop for out of touch spendthrifts. 1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one. 2. Internet access is only required for most tasks due to people's laziness of using webapps. 3. Alternatively, "yay, I can refresh…

Huh? Where do you get this from? > 1. Fifteen different prices depending on what alleged type of device you're using, and gasp whether you have more than one. The device type is a good indicator of bandwidth usage. It's sensible to bill using this model for now. They could use metered bandwith, but something tells me you'd complain about that too. > 2. Internet access is only required for most tasks due to people's l…

Re: 6 - I should also say that to "give the TSA the boot", it is the US government who should stick up for its customers and end this security theater.

Re: Bypassing Gogo’s Inflight Internet Authentication

#19
post #16

You could also change your user agent to that of a mobile device and pay $5. Dishonesty is always an (unethical) option. The technical complexity of getting a seamless Wifi connection 30,000 feet above ground warrants its $12.00 in my opinion.

On my last flight, the price had been raised to $20 or so. I'm not sure if it was holiday price-gouging or they've simply raised their prices, but in either case I was not pleased - especially as the service quality seems to have gone down recently.

Re: Bypassing Gogo’s Inflight Internet Authentication

#20
post #7

I'm amazed by some of the comments like "Wow great article. I knew there must be a way to avoid paying." and by author's apparent believe that contacting the support several times via twitter and not getting a response morally justifies sharing his recipe with other people and wishing them "Happy “free” surfing, for now anyway". Stealing is stealing, no matter what "justification" one may have about high prices. edit…

If they are providing the service, it isn't stealing. It is just using the service in a way that was not intended by the provider.
Post reply on HN