Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…
Definitely, but it's worth for them to defend against or go after the few people willing to use this method to get free Wi-Fi on planes? IMHO they'll spend more than what they'll gain.
Stunnel and Airline Wi-Fi
171–180 of 239 posts
Re: Stunnel and Airline Wi-Fi
#172Earlier quoted context omitted.
It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.
I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…
If your door is open can I take a shower and cook a meal for myself in your house?
Re: Stunnel and Airline Wi-Fi
#173Re: Stunnel and Airline Wi-Fi
#174Re: Stunnel and Airline Wi-Fi
#175Earlier quoted context omitted.
Which highlights a fundamental truth to law - it's only enforced to backstop the status quo. Routing around a wifi paywall rocks the boat, performing invasive surveillance on website visitors doesn't. So practically yes, let's be aware that the author could indeed be persecuted under the CFAA. But let's not grandstand and pretend that following that law is some sort of moral imperative that benefits everyone. The com…
Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.
My perspective is that a fundamental aspect of the Internet and the digital world is that the software-codified rules are basically authoritative. While constructive behavior still does matter - eg knowingly turning off a hospital ventilator is still murder - the only gain here was temporarily obtaining some transit. The real remedy is for the provider to fix their systems.
Re: Stunnel and Airline Wi-Fi
#176Earlier quoted context omitted.
In this case the “door handle” is marked with “pull to access the internet”, and he is pulling on it. The handle is supposed to have a mechanism to demand payment before opening but in this case it failed and opened right away. Not saying this is ethical (although selling WiFi for 12$ per hour isn’t either) but I wouldn’t go as far as calling this an attack.
>although selling WiFi for 12$ per hour isn’t either Care to elaborate on this? WiFi on a plane isn’t any kind of thing people are dependent on to survive and satellites are pretty expensive. Airplane WiFi is entirely a luxury good. Do you feel that charging $12 to watch a movie in a theatre is unethical as well? How about $150k for a Porsche?
Re: Stunnel and Airline Wi-Fi
#177Earlier quoted context omitted.
Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.
It’s also immoral to force bad pricing down customer throats. And yet that is the definition of the inflight wifi business. EDIT: I’m fairly sure at current prices a single flight could pay for a month’s service for a single plane, probably several times over. The profit margins (& I imagine some the cut to the airline) must be enormous, & there is no pretense of fair terms at sale time because a single corporation c…
In what bizarro world are people being forced to buy inflight wifi?
Re: Stunnel and Airline Wi-Fi
#178Earlier quoted context omitted.
>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents. Lol. I don't know where you got this impression, but no, it absolutely is not. Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission. Furt…
>Furthermore, that doesn't really apply in this case because not only was he not given "implicit permission to use it", the in-flight WiFi system explicitly bars you from using the internet without paying for it. Then it should do so. If I connect and I can use the network without paying, that's not my fault.
I honestly can't believe we're even having this conversation. It is theft, period. Not only is it illegal, it's blatantly immoral.
Re: Stunnel and Airline Wi-Fi
#179Earlier quoted context omitted.
Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.
This is a business and satellite bandwidth is fairly precious. A better analogy would be going into a restaurant with big “No Outside Food” signs with a sandwich you made at home, hiding the sandwich in a false compartment to get past a check at the door, printing the restaurant’s name on your sandwich wrapper so it looks like you bought it there, and then eating it at a table meant for paying customers.
Re: Stunnel and Airline Wi-Fi
#180Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…
It's interesting that you and your team thought of legal consequences before asking if this is an edge case that's not worth engineering for.