Live data from Hacker News

Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

arstechnica.co.uk

41–50 of 85 posts

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#41

Earlier quoted context omitted.

Large scale public wifi generally doesn't have passwords, that clearly doesn't scale, they have fancy enterprise auth things or captive portals. Shared password only works for small places like coffee shops. Anecdotes: 1: on London Underground, my phone authenticates using the SIM somehow (it still shows a captive portal screen, just with an ad, yay). 2: in the Turkish lounge in Istanbul airport, the shared password…

> But to take your idea just one step further, once you've opened up all wifi for the general publics consumption (what a renaissance for wired networking!) I think this requires clarification - I don't mean no business should ever use wifi. I mean businesses like telephone companies shouldn't be using to augment their networks. Obviously offices and the like need secure wireless networking that normal hardware can c…

So you're speaking of a specific problem in a specific place - this is kind of hard to know when it was phrased as a general principle.

Also, it's hard to discuss the issue when there are no details about the specific issue available.

But two points: First, where I am, 2.4Ghz is perfectly swamped with normal residential access points. It seems unlikely that this telco in your city did much more than move up the point where the spectrum is swamped, rather than causing it directly (also, if their use is affecting everyone else, they themselves are affected, too, rendering their investment pretty pointless, which leads me to wonder just how bad the situation actually is). Second, if you do want to regulate, in a rule-of-law-compatible way, well, it's going to be hard to distinguish a Starbucks access point operated for the benefit of customers of Starbucks from a telco access point operated for the benefit of customers of that telco. (If you want to use spectrum ownership as the metric, consider that many telcos cover both spectrum-owning mobile and commercial and residential broadband (ie wifi-providing) subsidiaries). To further muddy the waters, the telco is very likely to be selling access to their wifi network to non-subscribers.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#42

Earlier quoted context omitted.

If I remember correctly, the problem with open WiFis is that all data is transmitted as plaintext. If you set a password (even if it's just "password") and therefore enable e.g. WPA2-PSK, data is properly encrypted with a per-client session key.

This isn't really true. If you know the PSK and can capture the packets of the client associating with the AP, you are able to decrypt any further communication. http://security.stackexchange.com/questions/8591/are-wpa2-co...

Well, that's almost as terrible. Combined with the "everyone can deassociate everyone" that's been in WLAN forever and the "enterprise" solutions using MSCHAPv2 where passwords can be almost trivially recovered it's pretty much impossible now to do WLAN securely. Companies should really treat any wireless network as basically insecure.

The terrible certificate support in e.g. Android is just icing on the top.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#43

Earlier quoted context omitted.

> But to take your idea just one step further, once you've opened up all wifi for the general publics consumption (what a renaissance for wired networking!) I think this requires clarification - I don't mean no business should ever use wifi. I mean businesses like telephone companies shouldn't be using to augment their networks. Obviously offices and the like need secure wireless networking that normal hardware can c…

So you're speaking of a specific problem in a specific place - this is kind of hard to know when it was phrased as a general principle. Also, it's hard to discuss the issue when there are no details about the specific issue available. But two points: First, where I am, 2.4Ghz is perfectly swamped with normal residential access points. It seems unlikely that this telco in your city did much more than move up the point…

>it's going to be hard to distinguish a Starbucks access point operated for the benefit of customers of Starbucks from a telco access point operated for the benefit of customers of that telco

Not really. Usually there is an actual Starbucks where there is Starbucks WiFi and it doesn't extend much beyond the coffee shop. In this case and the case of Comcast in the US, the company is using other people's property for broadcasting wireless.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#44
post #36

Earlier quoted context omitted.

Public doesn't mean free to everybody, it means available to everybody. A public house (as opposed to a private club), aka a pub, is not a place you can hang out whenever, they have hours (they are not "public" at night) and you're supposed to buy stuff when you're in there. There's nothing about password protected wifi that makes it inherently non-public.

I think he means when certain Telcoms blanket entire cities with Wi-Fi in the unlicensed spectrum which at scale makes everyone else's connection worse. I have no problem with blanketing cities with internet access but I think commercial wireless should have their own frequency -- which would actually be good for them since they would be mostly alone in the space and could get a frequency which is better suited to la…

I live in London which has allot of telco wifi everywhere and I haven't seen any adverse impact on my signal.

Wifi is saturated regardless of it being metro or not, relatively speaking the strongest signals by far will come from your neighbours not the telcos.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#45
post #40

Earlier quoted context omitted.

> Is the legal argument stronger here? EU court directives are applicable for EU member countries. CDU or SPD can't do much. There's also a ruling from the Danish SC on EU directives that applies in Germany on open WiFi. I doubt SPD or CDU could do much. It would potentially just delay the homecoming of such a law.

Danish court rulings binding on Germany? You're either joking or misinformed.

No court rulings are ever binding apart from the specific case discussed. However, judges often (especially in higher courts) state criteria they would use to judge similar cases and make general remarks in this area of law. Other judges then later directly refer to those lines of argumentation. If a Danish judge issued a ruling based solely on EU law with convincing arguments, then a German judge can use that later just as if another German court ruled on that matter.

I don't read verdicts often enough to say how common this is (and certainly often arguments are copied without mentioning the source). However, in literature you regularly see that authors refer to cases from different EU member states. And why should arguments made by Danish judges by worth less in Germany than arguments made by German judges? The whole point of the EU is harmonization of law. If one legal source is consistently interpreted in two different ways in two different countries something definitely went wrong.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#46
post #40

Earlier quoted context omitted.

> Is the legal argument stronger here? EU court directives are applicable for EU member countries. CDU or SPD can't do much. There's also a ruling from the Danish SC on EU directives that applies in Germany on open WiFi. I doubt SPD or CDU could do much. It would potentially just delay the homecoming of such a law.

Danish court rulings binding on Germany? You're either joking or misinformed.

I have explicitly mentioned that is a Danish Supreme Court ruling on EU directives and hence, has bearing (not binding) in Germany. I'd love to prove wrong but here's a link that pretty much mentions the same

> It’s noteworthy, though Germany’s legislators probably don’t realize this yet, that the elimination of the Störerhaftung enables use of the open wireless defense in Germany, according to a ruling from the Danish Supreme Court (which does have bearing in Germany, as that court ruled on EU directives).

https://www.privateinternetaccess.com/blog/2016/05/finally-g...

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#47
post #13

The wording of the proposed law is not published yet and there are good reasons (including statements by the involved ministries) to believe that it does not really have the effect they claim.

Just politically it doesn't make any sense to me to believe the change will have that effect. Why would after such a long time the CDU suddenly drop the pro-Störerhaftung position? It seems much more likely that SPD and CDU have reached a compromise that eliminates the Störerhaftung only partially. I expect the outcome will just create legal uncertainty. So that there won't be any positive effect.

> Why would after such a long time the CDU suddenly drop the pro-Störerhaftung position?

Most of them own tablets and smartphones by now and they don't feel like maxing out their data plan which they have to pay for themselves.

On a serious note, I'd agree that this just creates legal uncertainty. Netzpolitik.org (in German langauge) goes a bit into details [0]

[0] https://netzpolitik.org/2016/abschaffung-der-wlan-stoererhaf...

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#49

Earlier quoted context omitted.

Well, I am glad they are moving over. Technically, it would be very hard to find people responsible for open Wifi in, for example, a hotel. Who would be responsible if Osama Bin Laden browsed something that is illegal? The hotel owner, the staff, the internet provider? And how about if the hotel is owned by a public company? The shareholders? Just bullshit.

That's why the wifi isn't open in German hotels, instead you get a login specific to your room.

And that is why this is bullshit, because, if I want, I switch to mobile roaming for the price of one beer. You cannot stop me with bullshit like that, if I want to do something that they think is illegal.

And not only that, I can buy an anonymous SIM card, if I want. What exactly are you saying, you are defending this stupidity? What else are you defending, if someone uses Facebook or Whatsapp for terrorism, you gonna shut them down.

Please.

Re: Germany plans to remove owner liability for piracy on open Wi-Fi hotspots–report

#50

Earlier quoted context omitted.

No. That's a Germany thing and it resulted in the conplete lack of public wifi hotspots.

More precisely: for example hotels typically have a public wifi for their customers, but you must get an individual login account from the reception. This protects the hotel or its service provider. It is quite silly, of course, and is generally a little hassle with your hotel.

It's more problematic when you're transiting through a German airport, and practically fall off the face of the earth.

Ohhhh, they have a wifi hotspot portal: "Enter your cell phone number to get an SMS with a 30 minute code". You want me to turn on my cell-phone and potentially incur roaming charges now?

I hear things have gotten better in Frankfurt and you only have to provide an email address. How did they skirt this law?

Post reply on HN