Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

161–170 of 239 posts

Re: Stunnel and Airline Wi-Fi

#162
post #69

Earlier quoted context omitted.

> It's illegal to come into my house and take my stuff even if I forget to lock my back door. For some reason, on HN when I've made this argument before, the resulting comments have been that the internet is somehow different, and that real-world analogies don't exist. Using equipment that you don't own in a way the owners don't intend is apparently well-accepted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

What you're describing (someone entering your property, having their lunch in your garden and cleaning up before leaving) meets all the elements of physical trespass if the owner of the property didn't grant permission, and is unlawful. Now, the damages might be minimal, but it's still unlawful.

In the U.S., property law is about the right to control access and use -- harm is a secondary concern.

Re: Stunnel and Airline Wi-Fi

#164
post #31
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

Not a lawyer, but you could argue that he wasn't really accessing the router, he was accessing his own server at home.

These sorts of technicalities don't play well with juries, but neither do large airlines or ~phone companies charging $15 for two hours of 1Mbps internet.

Re: Stunnel and Airline Wi-Fi

#165

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

I don’t think the fact that it’s a defense company is relevant. The company wouldn’t use the same “security” measures if actual defense was at stake. This system was built with certain specifications and down to a certain price.

It’s relevant because it effects their “brand” and also culture plays a role in how they may perceive the situation. I have no idea if this even registers on their radar and it’s pure speculation on my part. Certainly not a sleeping bear I would poke.

Re: Stunnel and Airline Wi-Fi

#166

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

Definitely, but it's worth for them to defend against or go after the few people willing to use this method to get free Wi-Fi on planes? IMHO they'll spend more than what they'll gain.

[deleted]

Re: Stunnel and Airline Wi-Fi

#167

Earlier quoted context omitted.

It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.

I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…

> That's pretty plainly not theft.

There's not a matter of perception or culture as the candy was intentionally left out for a trick or treater to take. And since it's a well known holiday, the intent has been communicated.

Re: Stunnel and Airline Wi-Fi

#168
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

The guy is in high school. They should offer him an internship, not throw the stupid book at him.

Re: Stunnel and Airline Wi-Fi

#169

Earlier quoted context omitted.

Which highlights a fundamental truth to law - it's only enforced to backstop the status quo. Routing around a wifi paywall rocks the boat, performing invasive surveillance on website visitors doesn't. So practically yes, let's be aware that the author could indeed be persecuted under the CFAA. But let's not grandstand and pretend that following that law is some sort of moral imperative that benefits everyone. The com…

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

It’s also immoral to force bad pricing down customer throats. And yet that is the definition of the inflight wifi business.

EDIT: I’m fairly sure at current prices a single flight could pay for a month’s service for a single plane, probably several times over. The profit margins (& I imagine some the cut to the airline) must be enormous, & there is no pretense of fair terms at sale time because a single corporation can entirely monopolize your attention.

Re: Stunnel and Airline Wi-Fi

#170

Earlier quoted context omitted.

I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents. Lol. I don't know where you got this impression, but no, it absolutely is not. Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission. Furt…

>Furthermore, that doesn't really apply in this case because not only was he not given "implicit permission to use it", the in-flight WiFi system explicitly bars you from using the internet without paying for it.

Then it should do so. If I connect and I can use the network without paying, that's not my fault.

Post reply on HN