Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

151–160 of 239 posts

Re: Stunnel and Airline Wi-Fi

#151

Earlier quoted context omitted.

How is this different from trying a door handle to see if it's open.

In this case the “door handle” is marked with “pull to access the internet”, and he is pulling on it. The handle is supposed to have a mechanism to demand payment before opening but in this case it failed and opened right away. Not saying this is ethical (although selling WiFi for 12$ per hour isn’t either) but I wouldn’t go as far as calling this an attack.

>although selling WiFi for 12$ per hour isn’t either

Care to elaborate on this? WiFi on a plane isn’t any kind of thing people are dependent on to survive and satellites are pretty expensive. Airplane WiFi is entirely a luxury good.

Do you feel that charging $12 to watch a movie in a theatre is unethical as well? How about $150k for a Porsche?

Re: Stunnel and Airline Wi-Fi

#152
post #31

Earlier quoted context omitted.

Not a lawyer, but you could argue that he wasn't really accessing the router, he was accessing his own server at home.

IMHE Judges don't have much of an appreciation for clever circumvention of the law.

How about a plausible interpretation of the law?

Re: Stunnel and Airline Wi-Fi

#153

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

Lifehacker posted a similar article (linked in the OP). https://lifehacker.com/get-free-unlimited-wi-fi-on-flights-a...

That’s not the same system or company.

Re: Stunnel and Airline Wi-Fi

#154
post #79

Earlier quoted context omitted.

Because a prosecutor hasn't tried to use it in that way.

Which highlights a fundamental truth to law - it's only enforced to backstop the status quo. Routing around a wifi paywall rocks the boat, performing invasive surveillance on website visitors doesn't. So practically yes, let's be aware that the author could indeed be persecuted under the CFAA. But let's not grandstand and pretend that following that law is some sort of moral imperative that benefits everyone. The com…

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

Re: Stunnel and Airline Wi-Fi

#155
post #141

Last year I was on a flight and my phone buzzed, which was odd. I looked down and it had somehow connected to the WiFi without my doing anything and started getting chat messages. I tested further and my WiFi was totally unrestricted. I was able to download a show from Netflix at 20Mbps+ ... does anyone know what happened? I didn't even think planes had WiFi that fast and I definitely thought they blocked all streami…

if you're on T-Mobile , then it's possible you got connected via their plan that allows for free GoGo inflight wifi.

No, GoGo is based on HughesNet, whereas OP was using Viasat

Re: Stunnel and Airline Wi-Fi

#157
post #10

This seems quite unethical to me.

It is theft of services. Ironical in this website since ycombinator companies are mostly about selling services via the Internet.

I'm a bit flabberghasted that so many commenters in this thread are apparently in favor of committing blatant theft.

Re: Stunnel and Airline Wi-Fi

#158

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

He is in high school. The defense company should offer him an internship.

I absolutely hope that’s the outcome of this whole thing. Unfortunately beyond the actual security vulnerability, companies often view these things as a “brand” or “PR” issue. I sincerely wish Kevin the best & hope this results positively as an internship or bug bounty.

Re: Stunnel and Airline Wi-Fi

#159
post #86

Earlier quoted context omitted.

You could say the same about adblock then, so lets not open that can of worms

Is it though? The adblocker runs locally on your own computer; it certainly prevents the ads from doing what the designer intended, but it doesn't make the designer's computer (or any computer controlled by the ad network) do anything. Versus tracking does actually do something on your computer (e.g. running JS to discover fonts). Arguably that is a circumvention of the intentions of the user on their own hardware.

What about the reverse of that. When I load a website, I expect it to load the normal information of the page in question (for an article about something, that article). I do _not_ want or grant permission for it to display ads. As such, their host sending ads to my machine is "exceeding authorized access".

I'm curious if it would be feasible to sue a company over sending ads. They have just as much information about what you want displayed on your computer as you have about how they want you to use their apis.

Re: Stunnel and Airline Wi-Fi

#160

The site's down for me. I got a 404 and a few minutes later a Firefox "Did Not Connect: Potential Security Issue" followed by this explanation: Firefox detected a potential security threat and did not continue to potatofrom.space because this website requires a secure connection. What can you do about it? potatofrom.space has a security policy called HTTP Strict Transport Security (HSTS), which means that Firefox can…

The website itself is up https://potatofrom.space/ so looks like the author decided to take it down, odd. Maybe he got a cease and desist from Viasat.

Still available on the GitLab instance linked from the home page: https://gitlab.potatofrom.space/kevin/potatofrom.space/blob/...
Post reply on HN