Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

221–230 of 239 posts

Re: Stunnel and Airline Wi-Fi

#221

Earlier quoted context omitted.

Where do you live? Open WiFi is like a water fountain, or a bench, in a pubic place to me. There's no explicit sign telling you to use it but who'd put it there of it were not to be used? I'm in the UK. So, for example if I'm out and about and there's an open WiFi I'll connect to it without seeking permission .. in fact I think it would be weird to go and ask (if you could work out who to ask).

In the UK, what you're doing is illegal under the Computer Misuse Act. I don't think the police are out scouring the streets for people stealing wifi, so you probably won't be prosecuted for it. But still, it is technically illegal. Example: https://uk.reuters.com/article/uk-britain-wireless/two-cauti... (It's also very, very, very terrible practice for your own security. Don't do it.)

It would be illegal if it were unauthorised, I'm not checking it's authorised because you'd have to be a moron to have published your open router if you didn't intend to have an open router being published. Whilst there's a chance that when I go to McDo that I'm not actually authorised and to use the published open wifi, it's so slim that it's not worth me tracking down the router owner to ask them -- if that were even possible to do.

If you place a bench in public and you don't want anyone to sit on it then you need to notify people explicitly ... it's the same, I don't find the owner of benches and ask them.

Are there any attacks that work just by connecting to someone's wifi, obviously I'm only using it for non-sensitive traffic unless it's a recognised provider, it's certainly part of my security considerations. Are there specific attacks you're thinking of? Such attacks would work equally if I had explicit authorisation, of course.

Re your link, last time I looked it was allowed to have open shared wifi, and the way you indicate it's open for sharing is having it open and shared. That's probably why the police gave cautions, it placates the complainant and they didn't have to lose in court.

Re: Stunnel and Airline Wi-Fi

#222
post #90

Earlier quoted context omitted.

It's not victimless, the loser is the service provider whose bandwidth is consumed. The line many draw is that corporations aren't people and can't be the victim, this is a false analogy. Thus: let's switch who is penalized: everyone else on the flight. Bandwidth isn't unlimited, without payment it's hard to justify increasing bandwidth if it isn't profitable. What should the author do? Report it. If he didn't, maybe…

Name the victim, please. Because it looks like it causes a infinitesimal harm to a corporation whereby no person is harmed to any noticeable extent, aka a victimless crime. "Victimless crime" doesn't mean there are no negative effects, it means no _person_ is a victim.

Every user who bears the additional cost of the service because of freeloaders is a victim.

Re: Stunnel and Airline Wi-Fi

#223
post #204

Earlier quoted context omitted.

You can't look at the legality of it from the point of what the adblocker does. Software doesn't commit crimes; people do. The possible crime (if it is one) would be if you know your browser has adblock, you know authorization to use their server is conditional on not using adblock, and you choose to access it anyway.

This is an extremely naïve, baseless argument- if you could even call it an argument at all. So let us turn to the ‘proposed’ argument itself: “Software doesn’t commit crimes; people do” The first thing to notice is that the argument has no stated conclusion. What follows? That there should be no software regulation at all? That there should not be any more software regulation than there already is? That the increase…

You have missed the point of my comment. It isn't about what the law should be. Instead, I was discussing whether it is currently legal to use adblock.

As I interpreted it, someone said adblock may be illegal under existing law because you are accessing a server without authorization. Someone else seems to have argued that this isn't true because adblock doesn't cause anything to happen on the server; therefore, adblock must be legal because adblock only affects the client.

My comment was that this reasoning doesn't hold water. Perhaps the owner states that authorization is only granted to people who don't use adblock. (Maybe there's a splash page that informs the user they aren't authorized to proceed to the next page if they have adblock enabled.) What matters is the choices people make, not that the behavior of the software avoids interacting with the server. Your hands are not clean just because your software doesn't take an action.

Re: Stunnel and Airline Wi-Fi

#224
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

Understood. Also, I bet every sibling comment to this one will be terribly low quality and fail to convince anyone of anything.

Re: Stunnel and Airline Wi-Fi

#225

Earlier quoted context omitted.

I suspect you're still associating hacking with other actions that can be facilitated by hacking. But the very next thing I wrote was "knowingly turning off a hospital ventilator is still murder", so it only makes sense to answer as if you strongly intend the "per se". In isolation, why would finding a hole in someone else's ruleset be immoral? If hacking per se were immoral, then there could be no such thing as a "w…

> I suspect you're still associating hacking with other actions that can be facilitated by hacking. I specifically wrote "per se", so no - I'm not. > If hacking per se were immoral, then there could be no such thing as a "white hat". White hat hacking it typically specifically authorized (e.g. red teams). That is not the case with the example from the article. In the locksport community there is a pretty strong norm…

> White hat hacking [is] typically specifically authorized (e.g. red teams)

That is merely one kind of white hat hacking. Another kind would be figuring out an exploit for software that you have a local copy of, even against the wishes of its developer. If we agree that this is moral, then general finding of holes itself cannot be immoral.

I don't think you mean to imply that in locksport, you only pick models of locks that the manufacturer has given you the go-ahead to attack. Rather you're referring to ownership of the physical lock itself, which is merely one type of authorization. I would also guess that the reason the community repeats this prominently is to head off legal entanglement.

To the extent that a given ruleset only exists on a specific device that one does not own, then it is indeed hard to find holes in it without also affecting that device itself. However, it is still important to draw the distinction between any effects and the logical hacking itself, lest minor effects end up being persecuted inequitably.

In the context of the original article, there are essentially no damages and a little bit of unjust enrichment. Yet this whole thread has blown up about a spectre of harsh punishment under the CFAA, when equity is closer to the amount of the access fee.

Re: Stunnel and Airline Wi-Fi

#227
post #208

Earlier quoted context omitted.

Try this: The lobby is not locked. Neither are any of the doors leading out from it. There is a cashier in the lobby and a sign with ticket prices for the different doors.

In that situation, opening the doors without paying is illegal. It would be treated as trespassing or theft of services. You don't have the right to use other peoples' stuff without permission just because it's easy to do.

And that was my point.

Re: Stunnel and Airline Wi-Fi

#228
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

Wouldn't this be excluded anyway since the only thing "fraudulently obtained" was "use of the computer or system" worth less than $1,000 per year? Even if that language weren't in 18 USC 1030(a)(4), the guidelines sentence assuming no priors would look to be 0-6 months and $250-$5000 fine, assuming you couldn't plea out to something less. I doubt the federal authorities are even going to waste their time looking at $…

It depends on whether someone wants to make something of it. The costs taken into account by the CFAA include the costs of investigating the incident and repairing any damage, and courts in the past have tended to accept pretty much any assertions about these costs. They probably wouldn't blink if the entire cost of fixing the exploit were attributed to the OP.

Re: Stunnel and Airline Wi-Fi

#229

Earlier quoted context omitted.

Name the victim, please. Because it looks like it causes a infinitesimal harm to a corporation whereby no person is harmed to any noticeable extent, aka a victimless crime. "Victimless crime" doesn't mean there are no negative effects, it means no _person_ is a victim.

Every user who bears the additional cost of the service because of freeloaders is a victim.

Your working definition sounds like it's wrong: Could you give an example of what you call a "victimless crime"?

Re: Stunnel and Airline Wi-Fi

#230

Hey guys, thanks for all the comments! I realized that it was not an ethical idea to post, so I decided to take it down. I did not get a cease and desist, but I would appreciate if you could refrain from reposting it. If you are interested in seeing some of my other (more ethical) work, check out Delphus [1], an open research study management platform which I am working on at my new startup ;) [1]: https://delph.us

I'm not sure about this, still. I'd consider it roughly equivalent to posting a POC for an exploit: it could be abused, could be uses for academic learning, or could be used to improve systems. It's not inherently bad.
Post reply on HN