Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

181–190 of 239 posts

Re: Stunnel and Airline Wi-Fi

#181

Earlier quoted context omitted.

I think the local culture needs to be taken into account. Suppose I walk onto your porch, see something I want, and take it with me. That's pretty plainly theft, right? Now suppose I am eight years old, taking candy from a bowl left out on Halloween. That's pretty plainly not theft. To somebody unfamiliar with the cultural practice of trick-or-treating, they might assume that it is theft. The internet has different c…

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents. Lol. I don't know where you got this impression, but no, it absolutely is not. Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission. Furt…

Where do you live?

Open WiFi is like a water fountain, or a bench, in a pubic place to me. There's no explicit sign telling you to use it but who'd put it there of it were not to be used? I'm in the UK.

So, for example if I'm out and about and there's an open WiFi I'll connect to it without seeking permission .. in fact I think it would be weird to go and ask (if you could work out who to ask).

Re: Stunnel and Airline Wi-Fi

#182
post #9

Earlier quoted context omitted.

This is almost definitely “hacking” under federal law.

IANAL and all that, but my perception is that "hacking" is usually about breaking into someone else's computer / breaching someone else's privacy / accessing data that isn't yours / etc. If that perception is accurate, then I think it's really a stretch to call this "hacking". You're just moving bits around on network infrastructure designed to move bits around. Maybe I'm just looking for a loophole because wishful t…

The old colloquial term for this is "phreaking."

Re: Stunnel and Airline Wi-Fi

#183
post #174

I'm seeing a lot of people say that airplane wifi is overpriced, and I'm kind of baffled. Yes, compared to terrestrial wifi it's expensive. But... you're in a fast moving object communicating with satellites (satellite launches are expensive!) and I don't really understand why people are so eager to call this bad pricing.

I don't fly enough to care, but the pricing model has become a death of one thousand cuts. I can see why that is bothersome, even if it can be described as fair exchange of value or whatever.

Re: Stunnel and Airline Wi-Fi

#184

Earlier quoted context omitted.

>although selling WiFi for 12$ per hour isn’t either Care to elaborate on this? WiFi on a plane isn’t any kind of thing people are dependent on to survive and satellites are pretty expensive. Airplane WiFi is entirely a luxury good. Do you feel that charging $12 to watch a movie in a theatre is unethical as well? How about $150k for a Porsche?

The problem is airplane WiFi has a captive audience with no competition so they can charge unfair rates and there is no free market to balance it.

So if you go to the top of a mountain and there is a single cabin selling water there, at outrageous prices, you would just help yourself to one bottle, because hey, no competition, captive audience.

Re: Stunnel and Airline Wi-Fi

#185

Earlier quoted context omitted.

>If I have a WiFi connection, leaving it without a password is implicit permission to use it. If I have a server that provides HTTP without authentication, that is implicit permission to access the contents. Lol. I don't know where you got this impression, but no, it absolutely is not. Not only is it not, but you can absolutely be prosecuted and imprisoned for accessing those networks/servers without permission. Furt…

Where do you live? Open WiFi is like a water fountain, or a bench, in a pubic place to me. There's no explicit sign telling you to use it but who'd put it there of it were not to be used? I'm in the UK. So, for example if I'm out and about and there's an open WiFi I'll connect to it without seeking permission .. in fact I think it would be weird to go and ask (if you could work out who to ask).

In the UK, what you're doing is illegal under the Computer Misuse Act. I don't think the police are out scouring the streets for people stealing wifi, so you probably won't be prosecuted for it. But still, it is technically illegal. Example: https://uk.reuters.com/article/uk-britain-wireless/two-cauti...

(It's also very, very, very terrible practice for your own security. Don't do it.)

Re: Stunnel and Airline Wi-Fi

#186

Earlier quoted context omitted.

It is theft of services. Ironical in this website since ycombinator companies are mostly about selling services via the Internet.

I'm a bit flabberghasted that so many commenters in this thread are apparently in favor of committing blatant theft.

This feels more like a complicated version of telling the world some grocery store entered store brand canned sardines wrong in their system and they'll ring up as $0.

Sure, they're free, for now, but do you really want all those canned sardines?

Re: Stunnel and Airline Wi-Fi

#187
post #117

Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of…

We shouldn't let defense companies push around the general public. I'm glad that the author is willing to shoulder that risk, we need more people like them.

I agree with the sentiment. As a fellow geek & rebel, I can empathize. But if the author were my friend, I would point to past examples of how these things typically don’t end well for us. Not worth upending your life for karma or likes or whatever. The world needs more geeks that love what they do and can contribute significantly to society. That does not happen if you’re fighting court cases or on the run from authorities. General Public will rarely, if ever, stand up for you.

Re: Stunnel and Airline Wi-Fi

#188
post #34

Earlier quoted context omitted.

> However the CFAA simply doesn't work that way. "Authorisation" is what the designers intended, and the initial paywall made that intention perfectly clear. That might be the case but it's also nuts. It encourages litigation over better design and makes public enemies out of security professionals, ultimately driving away those professionals from the US and making US developed tech weak.

It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.

> It's illegal to come into my house and take my stuff even if I forget to lock my back door.

This is such a poor analogy. You are conflating access with use... someone "steeling your stuff" is what they do with the access, access is figuring out how to open the door which is the focus of what this guy was doing...

This is where all physical world analogies basically end, the closest would be a lock picking enthusiast, but digital access is a huge complicated world that is conflated with the concept of selling communication.

The so-called US law talks of intent, so why not talk about intent of the "accused" here: This clearly isn't some average freeloader interested in saving $12, the interest is far deeper, the challenge in overcoming the access and then presenting what he found out "isn't this interesting" - is that really the behavior of someone intent on "steeling your stuff". No.

If you really want to talk about what he "stole" as a process of that intent, it's literally utility, like a bathroom with a $12 lock... of which it is of course not even clear how much he used, the focus was all about figuring out how to gain access, not seeing how much netflix he could download.

Re: Stunnel and Airline Wi-Fi

#189

Earlier quoted context omitted.

In this case the “door handle” is marked with “pull to access the internet”, and he is pulling on it. The handle is supposed to have a mechanism to demand payment before opening but in this case it failed and opened right away. Not saying this is ethical (although selling WiFi for 12$ per hour isn’t either) but I wouldn’t go as far as calling this an attack.

>although selling WiFi for 12$ per hour isn’t either Care to elaborate on this? WiFi on a plane isn’t any kind of thing people are dependent on to survive and satellites are pretty expensive. Airplane WiFi is entirely a luxury good. Do you feel that charging $12 to watch a movie in a theatre is unethical as well? How about $150k for a Porsche?

The problem is that it’s $12 for an hour, regardless of whether you end up using it, or whether it works at all (do you get a guaranteed bandwidth along with that, and is there some BS filter that’s gonna interfere with certain sites or protocols despite you having paid?).

Finally it’s just way too expensive at that price.

Re: Stunnel and Airline Wi-Fi

#190
post #90

Earlier quoted context omitted.

> Probably because this is a victimless crime... How is this a victimless crime?

It's not victimless, the loser is the service provider whose bandwidth is consumed. The line many draw is that corporations aren't people and can't be the victim, this is a false analogy. Thus: let's switch who is penalized: everyone else on the flight. Bandwidth isn't unlimited, without payment it's hard to justify increasing bandwidth if it isn't profitable. What should the author do? Report it. If he didn't, maybe…

> "Thus: let's switch who is penalized: everyone else on the flight."

Only if everybody else on the flight was paying for WiFi (doubtful) and bandwidth was maxed out during the flight (plausible.)

Post reply on HN