Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

201–210 of 239 posts

Re: Stunnel and Airline Wi-Fi

#202
post #170

Earlier quoted context omitted.

>Furthermore, that doesn't really apply in this case because not only was he not given "implicit permission to use it", the in-flight WiFi system explicitly bars you from using the internet without paying for it. Then it should do so. If I connect and I can use the network without paying, that's not my fault.

If you knowingly and with intent use that network without paying, even when knowing that the owner of the network wants all users to pay, it absolutely is your fault. The airline could literally put zero restrictions on their network access, but as long as they put up a sign that says "internet is only for those who pay for it", it would be both illegal and wrong for you to access that internet without paying. I hone…

>I honestly can't believe we're even having this conversation. It is theft, period. Not only is it illegal, it's blatantly immoral.

It's not theft. It's not immoral either. Open wlan means exactly that, so where is the sign? You are on HN, so using something like a VPN is not uncommon, regardless of what network you are using.

Re: Stunnel and Airline Wi-Fi

#203

Earlier quoted context omitted.

Is it though? The adblocker runs locally on your own computer; it certainly prevents the ads from doing what the designer intended, but it doesn't make the designer's computer (or any computer controlled by the ad network) do anything. Versus tracking does actually do something on your computer (e.g. running JS to discover fonts). Arguably that is a circumvention of the intentions of the user on their own hardware.

You can't look at the legality of it from the point of what the adblocker does. Software doesn't commit crimes; people do. The possible crime (if it is one) would be if you know your browser has adblock, you know authorization to use their server is conditional on not using adblock, and you choose to access it anyway.

> you know your browser has adblock, you know authorization to use their server is conditional on not using adblock, and you choose to access it anyway

Meanwhile the website publisher knows that authorization to run javascript may not include performing surveillance, yet includes circumvention code to perform surveillance anyway. So everybody is violating the law, which is why the CFAA is terrible legislation - it relies completely on selective persecution.

Pontificating about abstract "intent" is not actually useful in the digital realm. Protocols [0] are what ultimately mediate between parties with different desires. The CFAA is merely a relic that gets invoked when some powerful entity gets upset at the outcome of a protocol.

[0] to be clear, I'm talking about de facto protocols as executed, not de jure protocols as written into RFC.

Re: Stunnel and Airline Wi-Fi

#204

Earlier quoted context omitted.

Is it though? The adblocker runs locally on your own computer; it certainly prevents the ads from doing what the designer intended, but it doesn't make the designer's computer (or any computer controlled by the ad network) do anything. Versus tracking does actually do something on your computer (e.g. running JS to discover fonts). Arguably that is a circumvention of the intentions of the user on their own hardware.

You can't look at the legality of it from the point of what the adblocker does. Software doesn't commit crimes; people do. The possible crime (if it is one) would be if you know your browser has adblock, you know authorization to use their server is conditional on not using adblock, and you choose to access it anyway.

This is an extremely naïve, baseless argument- if you could even call it an argument at all.

So let us turn to the ‘proposed’ argument itself: “Software doesn’t commit crimes; people do” The first thing to notice is that the argument has no stated conclusion. What follows? That there should be no software regulation at all? That there should not be any more software regulation than there already is? That the increase in cybercrimes done with ‘software’ is irrelevant to whether or not there should be cyber regulations? Who knows? An argument without a conclusion is by technical basis, not an argument at all.

The statement under consideration clarifies that, when it comes to crimes committed with software , people are the ultimate cause and software is merely a proximate cause—the end of a causal chain that started with a person deciding to commit cyber crimes. But nothing follows from these facts about whether or not software should be regulated. Such facts are true for all criminal activity, and even noncriminal activity that harms others: The ultimate cause is found in some decision that a person made; the event, activity, or object that most directly did the harming was only a proximate cause. But this tells us nothing about whether or not the proximate cause in question should be regulated or made illegal. For example, consider the following argument:

"Bazookas don't kill people; people kill people."

Although it is obviously true that bazookas are only proximate causes, it clearly does not follow that bazookas should be legal. Yes, bazookas don't kill people, people do—but bazookas make it a lot easier for people to kill people, and in great numbers. Further, a bazooka would not be useful for much else besides mass murders. Bazookas clearly should be illegal and the fact that they would only be proximate causes to mass murders does not change this. In fact, it is totally irrelevant to the issue; it has nothing to do the fact that they should be illegal. Why? Because other things are proximate causes to people’s demise, but obviously shouldn’t be illegal. For example, consider this argument (given in the aftermath of a bad car accident):

"Cars don't kill people; people kill people."

Obviously cars should not be illegal, but notice that this has nothing to do with the fact that they are proximate causes. Of course, they should be regulated; I shouldn't be allowed to go onto the highway in a car with no brakes. But all of that has to do what cars are for (they are not made for killing people), what role they play in society (it couldn't function without them) and so on. It's a complicated issue—one to which pointing out that cars are merely proximate causes to some deaths contributes nothing.

In conclusion- people who make the feeble argument “software doesn’t commit crime; people do” have mistaken the relevance of proximate causation

Re: Stunnel and Airline Wi-Fi

#205
post #90

Earlier quoted context omitted.

> Probably because this is a victimless crime... How is this a victimless crime?

It's not victimless, the loser is the service provider whose bandwidth is consumed. The line many draw is that corporations aren't people and can't be the victim, this is a false analogy. Thus: let's switch who is penalized: everyone else on the flight. Bandwidth isn't unlimited, without payment it's hard to justify increasing bandwidth if it isn't profitable. What should the author do? Report it. If he didn't, maybe…

Name the victim, please.

Because it looks like it causes a infinitesimal harm to a corporation whereby no person is harmed to any noticeable extent, aka a victimless crime.

"Victimless crime" doesn't mean there are no negative effects, it means no _person_ is a victim.

Re: Stunnel and Airline Wi-Fi

#206
post #9

Earlier quoted context omitted.

This is almost definitely “hacking” under federal law.

The person I'm replying to specifically said "mess with the WIFI AP" in order to present this as harmful or dangerous (FUD), it is not. It's a trivial header check bypass - whether or not that is "hacking" is a question for lawyers and a judge.

Judges tend to be less impressed by technicalities than seems to be commonly believed. If you know that a network operator intends to route traffic only for paying customers, and you intentionally trick its router into routing your traffic without payment, the judge will probably see that as intentional unauthorized access.

I think that's legally reasonable, almost. It's the intent that matters here; if my use of Cloudflare DNS instead of what your DHCP server provides for performance and privacy reasons happens to bypass your insecurely implemented captive portal that asks for payment, there's no intent. If I employ a complex tunneling scheme specifically designed to bypass your payment check, that's theft.

Where I do have a problem with the law is that its digital nature is given special treatment and greatly enhanced penalties. If I walk into a store and steal a USB Wifi adapter worth $20, I have committed a misdemeanor. If I'm caught, I'll probably be given a summons, not arrested, and my penalty will probably be a fine or community service. If I use that adapter to steal access to $20 worth of in-flight Wifi, I've committed a felony, for which the penalty includes loss of civil rights, and probable incarceration.

Re: Stunnel and Airline Wi-Fi

#207

Earlier quoted context omitted.

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

It’s also immoral to force bad pricing down customer throats. And yet that is the definition of the inflight wifi business. EDIT: I’m fairly sure at current prices a single flight could pay for a month’s service for a single plane, probably several times over. The profit margins (& I imagine some the cut to the airline) must be enormous, & there is no pretense of fair terms at sale time because a single corporation c…

The profit margin for luxury addons is always insane. That doesn't make them unethical. In fact, there's a very good argument to be made that luxury pricing is positively ethical, as it allows the base experience to be offered for a lower price to more price-sensitive customers.

Re: Stunnel and Airline Wi-Fi

#208

Earlier quoted context omitted.

I think it's pretty close to the reality. The lobby is wide open (viasat's payment gateway), but if you just use the viasat lobby key (viasat.com SNI) on any other door (IP address) it allows you access. They could prevent you from getting to the doors in the first place (whitelisting MAC address to access anything other than a whitelist of IPs instead of just TLS SNI whitelisting) but they don't, as it's especially…

Try this: The lobby is not locked. Neither are any of the doors leading out from it. There is a cashier in the lobby and a sign with ticket prices for the different doors.

In that situation, opening the doors without paying is illegal. It would be treated as trespassing or theft of services. You don't have the right to use other peoples' stuff without permission just because it's easy to do.

Re: Stunnel and Airline Wi-Fi

#209

Earlier quoted context omitted.

Is it though? The adblocker runs locally on your own computer; it certainly prevents the ads from doing what the designer intended, but it doesn't make the designer's computer (or any computer controlled by the ad network) do anything. Versus tracking does actually do something on your computer (e.g. running JS to discover fonts). Arguably that is a circumvention of the intentions of the user on their own hardware.

The problem is that the phrase "exceeds authorized access" does not distinguish between the access increasing beyond the authorization and the authorization decreasing below the current access. Suppose I put in my Terms of Service the phrase "Access to this system is contingent on running the delivered webpage, including all first-party and third-party Javascript, without modification." Now, whether or not the HTTP r…

> Access to this system is contingent on running the delivered webpage, including all first-party and third-party Javascript, without modification.

Refusing to fetch a particular resource would be non-access. You cannot punish non-access as unauthorised access, because no such crime of non-access exists.

Re: Stunnel and Airline Wi-Fi

#210

Earlier quoted context omitted.

Following the law may not be a moral imperative, but let's not pretend like the author did anything moral here. He knowingly and with intent stole services from the airline. It not only was illegal, it's blatantly immoral.

The thing about morals is that we can disagree. Just because this scenario fits your definition of "stole" does not mean it fits mine. My perspective is that a fundamental aspect of the Internet and the digital world is that the software-codified rules are basically authoritative. While constructive behavior still does matter - eg knowingly turning off a hospital ventilator is still murder - the only gain here was te…

> My perspective is that a fundamental aspect of the Internet and the digital world is that the software-codified rules are basically authoritative.

Do you think that hacking per se is ever immoral?

Post reply on HN