Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

131–140 of 239 posts

Re: Stunnel and Airline Wi-Fi

#131

Earlier quoted context omitted.

It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.

I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents.

Lol. I don't know where you got this impression, but no, it absolutely is not.

Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission.

Furthermore, that doesn't really apply in this case because not only was he not given "implicit permission to use it", the in-flight WiFi system explicitly bars you from using the internet without paying for it.

Re: Stunnel and Airline Wi-Fi

#132
I can't open this page on my chromebook, I'm getting a

NET::ERR_CERT_COMMON_NAME_INVALID

Subject: dns.google

Issuer: Google Internet Authority G3

Expires on: 10 Sep 2019

Current date: 20 Jul 2019

With a further message that

You cannot visit potatofrom.space right now because the website uses HSTS.

Re: Stunnel and Airline Wi-Fi

#133

I did this as well using Orbot (Tor software for Android) and an OBFS4 proxy. In Southwest (the airline), you connect to the wifi for watching the movie and where you are in air. But if you want internet, you pay. I have some of my applications always Torified on my phone. I opened my 3d printer app to view its status, expecting a hard fail. And... it loaded!

I find that iMessage always works on my flights with United. No images though. I was surprised since the cell was off and it remembered the Wi-Fi but messages came through.

Re: Stunnel and Airline Wi-Fi

#134

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

He is in high school. The defense company should offer him an internship.

Re: Stunnel and Airline Wi-Fi

#135

Earlier quoted context omitted.

It is theft of services. Ironical in this website since ycombinator companies are mostly about selling services via the Internet.

Well, the flip side is that Y Combinator has no qualms about funding companies whose business model relies on ignoring laws that are inconvenient. Here are two different YC startups that relied on tourists smuggling goods to avoid import duties: https://techcrunch.com/2014/08/13/backpack-connects-you-with... https://news.ycombinator.com/item?id=10998377

You will be happy to know the send it on "airplane as luggage with passengers" business models are now seen as failures by most Silicon Valley investors as well as some YC partners. It's been 5 years and there were many of these companies - the investors got burned

How do I know? I run a YC funded company that legally imports :)

Re: Stunnel and Airline Wi-Fi

#136
The site's down for me.

I got a 404 and a few minutes later a Firefox "Did Not Connect: Potential Security Issue" followed by this explanation:

  Firefox detected a potential security threat and did not continue to potatofrom.space because this website requires a secure connection.

  What can you do about it?

  potatofrom.space has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can only connect to it securely. You can’t add an exception to visit this site.

  The issue is most likely with the website, and there is nothing you can do to resolve it. You can notify the website’s administrator about the problem.

Re: Stunnel and Airline Wi-Fi

#137

Earlier quoted context omitted.

The owner gave me a key to the lobby so I could pay to get an all-access key. As it turns out, I can just walk past the lobby and that key actually opens all doors in the building. Whether or not it's illegal to use it to access whatever I want is a question for lawyers and a judge.

That's not what's happening here. This is more like trying the key on every door, finding a cleaning closet unlocked and crawling through the ventilation ducts to get in.

I think it's pretty close to the reality. The lobby is wide open (viasat's payment gateway), but if you just use the viasat lobby key (viasat.com SNI) on any other door (IP address) it allows you access. They could prevent you from getting to the doors in the first place (whitelisting MAC address to access anything other than a whitelist of IPs instead of just TLS SNI whitelisting) but they don't, as it's especially evident when they allow other protocols when the connection is not encrypted.

Re: Stunnel and Airline Wi-Fi

#138

Earlier quoted context omitted.

This is hacking under federal law, as it should be. Likewise that if I break into your house by merely exploiting a weakness in the design of the lock, I am still committing a crime.

If someone charges for tours of part of their house, has two prices of tour, and you change the colour of your badge to let you access the part you haven't paid for, is that a crime?

Well yes, but bandwidth is practically free anyway. I'm not actually stealing computer resources. It's more akin to looking at the Mona Lisa through one of the Louvre's windows using a pair of binoculars.

Re: Stunnel and Airline Wi-Fi

#139

The site's down for me. I got a 404 and a few minutes later a Firefox "Did Not Connect: Potential Security Issue" followed by this explanation: Firefox detected a potential security threat and did not continue to potatofrom.space because this website requires a secure connection. What can you do about it? potatofrom.space has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can…

Archive:

https://web.archive.org/web/20190720140005/https://potatofro...

Re: Stunnel and Airline Wi-Fi

#140
post #121

An alternative to this is to scan for active Mac addresses on the WiFi and steal one and hope it’s someone paying for the premium WiFi already :) This works on almost all hotel WiFi too.

Wouldn’t than both devices “fight” for the access? Who gets the packages?

Yes, it makes both connections highly unstable. Not recommended.
Post reply on HN