Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

171–180 of 239 posts

Re: Stunnel and Airline Wi-Fi

#171

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

Definitely, but it's worth for them to defend against or go after the few people willing to use this method to get free Wi-Fi on planes? IMHO they'll spend more than what they'll gain.

I fear that this would be viewed thru the lens of “PR” & “brand”, thing companies are rightfully keen in protecting. Unfortunately there’s a legal component to all this also. The knowledge itself is cool & even actual instances of a handful of people getting “free” internet probably wouldn’t register on their radar. But the publicity from being on the top of HN... that might be of significant concern

Re: Stunnel and Airline Wi-Fi

#172

Earlier quoted context omitted.

It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.

I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents.

If your door is open can I take a shower and cook a meal for myself in your house?

Re: Stunnel and Airline Wi-Fi

#174
I'm seeing a lot of people say that airplane wifi is overpriced, and I'm kind of baffled. Yes, compared to terrestrial wifi it's expensive. But... you're in a fast moving object communicating with satellites (satellite launches are expensive!) and I don't really understand why people are so eager to call this bad pricing.

Re: Stunnel and Airline Wi-Fi

#175

Earlier quoted context omitted.

Which highlights a fundamental truth to law - it's only enforced to backstop the status quo. Routing around a wifi paywall rocks the boat, performing invasive surveillance on website visitors doesn't. So practically yes, let's be aware that the author could indeed be persecuted under the CFAA. But let's not grandstand and pretend that following that law is some sort of moral imperative that benefits everyone. The com…

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

The thing about morals is that we can disagree. Just because this scenario fits your definition of "stole" does not mean it fits mine.

My perspective is that a fundamental aspect of the Internet and the digital world is that the software-codified rules are basically authoritative. While constructive behavior still does matter - eg knowingly turning off a hospital ventilator is still murder - the only gain here was temporarily obtaining some transit. The real remedy is for the provider to fix their systems.

Re: Stunnel and Airline Wi-Fi

#176

Earlier quoted context omitted.

In this case the “door handle” is marked with “pull to access the internet”, and he is pulling on it. The handle is supposed to have a mechanism to demand payment before opening but in this case it failed and opened right away. Not saying this is ethical (although selling WiFi for 12$ per hour isn’t either) but I wouldn’t go as far as calling this an attack.

>although selling WiFi for 12$ per hour isn’t either Care to elaborate on this? WiFi on a plane isn’t any kind of thing people are dependent on to survive and satellites are pretty expensive. Airplane WiFi is entirely a luxury good. Do you feel that charging $12 to watch a movie in a theatre is unethical as well? How about $150k for a Porsche?

The problem is airplane WiFi has a captive audience with no competition so they can charge unfair rates and there is no free market to balance it.

Re: Stunnel and Airline Wi-Fi

#177

Earlier quoted context omitted.

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

It’s also immoral to force bad pricing down customer throats. And yet that is the definition of the inflight wifi business. EDIT: I’m fairly sure at current prices a single flight could pay for a month’s service for a single plane, probably several times over. The profit margins (& I imagine some the cut to the airline) must be enormous, & there is no pretense of fair terms at sale time because a single corporation c…

> It’s also immoral to force bad pricing down customer throats. And yet that is the definition of the inflight wifi business.

In what bizarro world are people being forced to buy inflight wifi?

Re: Stunnel and Airline Wi-Fi

#178
post #170

Earlier quoted context omitted.

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents. Lol. I don't know where you got this impression, but no, it absolutely is not. Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission. Furt…

>Furthermore, that doesn't really apply in this case because not only was he not given "implicit permission to use it", the in-flight WiFi system explicitly bars you from using the internet without paying for it. Then it should do so. If I connect and I can use the network without paying, that's not my fault.

If you knowingly and with intent use that network without paying, even when knowing that the owner of the network wants all users to pay, it absolutely is your fault. The airline could literally put zero restrictions on their network access, but as long as they put up a sign that says "internet is only for those who pay for it", it would be both illegal and wrong for you to access that internet without paying.

I honestly can't believe we're even having this conversation. It is theft, period. Not only is it illegal, it's blatantly immoral.

Re: Stunnel and Airline Wi-Fi

#179
post #93
post #69

Earlier quoted context omitted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

This is a business and satellite bandwidth is fairly precious. A better analogy would be going into a restaurant with big “No Outside Food” signs with a sandwich you made at home, hiding the sandwich in a false compartment to get past a check at the door, printing the restaurant’s name on your sandwich wrapper so it looks like you bought it there, and then eating it at a table meant for paying customers.

I love these analogies, but that's wrong. A better analogy would be you use their raw ingredients to make your own food, bring your own utensils and plates, and sit at their restaurant to eat. Basically, you're leasing their bandwidth without payment. Airlines are paying viasat or some other company for access to their satellites and expecting customers to pay the cost for usage (and probably make some profit).

Re: Stunnel and Airline Wi-Fi

#180

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

This is a level of probing anyone with a good understanding of HTTPS could do. It's not like mac spoofing or or setting up a honeypot (have fun stopping those). I think you set your bar one or two notches too low for what someone in tech can do. Practically, though, your bar is fine because this isn't actually a "security" vulnerability in the sense that something was leaked (worry more about honeypots), just that one or two people per flight might be mooching, and that's not worth engineering for.

It's interesting that you and your team thought of legal consequences before asking if this is an edge case that's not worth engineering for.

Post reply on HN