Live data from Hacker News

A story about bypassing air Canada's in-flight network restrictions

ramsayleung.github.io

41–50 of 169 posts

Re: A story about bypassing air Canada's in-flight network restrictions

#41

> We affirm our strict adherence to all relevant regulations and service terms throughout this project. Except if you bypassed payment and used the service in a manner that was not intended, most likely you were by definition not undertaking "strict adherance" to service terms ?

Say you're on a plane from Canada to Hong Kong (random example), which country's laws would be applicable here? The country where the airplane is registered?

It depends on which jurisdiction region wants to enforce the law. If someone wants to enforce a law, and it succeed, then the law of that jurisdiction region applies.

Re: A story about bypassing air Canada's in-flight network restrictions

#42
post #38
post #32

Earlier quoted context omitted.

I'm pretty "curious" when it comes to public networks. I'll scan coffee shops, stadiums, hotels, bus hotspots, anything I can connect to. Some networks are set up well, others not so much. I would never in a thousand years run a sweep on an airplane network. That's massively risky, to the point you might never be allowed on a jet again. Anything to do with aviation I am on my absolute best behaviour.

Without commenting on the appropriateness of what they did, the author doesn't say they did anything like a sweep. It looks like they were manually poking a few things with dig and ping, not firing up nmap.

Circumventing security on a network, on a plane, is definitely up there regardless if you sweeped or not. IANAL but that could put you in DHS crosshairs.

Re: A story about bypassing air Canada's in-flight network restrictions

#43

> Here we exploited a simple cognitive bias: not all services using port 53 are DNS query requests. Eh, I don’t think this is a result of cognitive bias. I’m sure the people involved in creating whatever hardware or software is running the network know that you can run other stuff on ports. More likely the extra effort involved in inspecting packets was not deemed worth the risk, a decision either made by the manufac…

To quote https://news.ycombinator.com/item?id=45537828

> This is likely another layer of security that they didn't break through:

> To prevent chat apps from consuming lots of bandwidth typically your connection is severely bandwidth restricted until you pay. If they didn't then someone could simply stream movies from their chat apps.

Re: A story about bypassing air Canada's in-flight network restrictions

#44
post #10

If a ping to a specific IP times out, I wouldn't say the IP is blocked. It could be that ICMP specifically is blocked, following some network rules on the firewall. This is pretty common in entreprise networks to not allow endpoint discovery. I could be missing something and happy to be corrected here, but I was surprised to read that.

I’ve had to explain this over and over throughout my career. The only way to know if something is accessible is to try the exact endpoint and protocol. Even application-aware firewalls will mess with things at times.

Re: A story about bypassing air Canada's in-flight network restrictions

#45

AC offers free WhatsApp, iMessage, messenger in most flights. You can ask meta through WhatsApp to effectively browse the net :)

Ah "network neutrality", how you won initially yet lost over time...

Now imagine the same restrictions on your home Internet

Re: A story about bypassing air Canada's in-flight network restrictions

#46
post #9
post #7

> The only downside was that although we broke through the network restrictions and could access any website, the plane’s bandwidth was extremely limited, making web browsing quite painful. Unfortunately this is also the downside of paying. Many times I have paid for internet, only to find it unusably bad. To be fair, I just flew a transcontinental flight on Air Canada the other day and the wifi was fine.

This is likely another layer of security that they didn't break through: To prevent chat apps from consuming lots of bandwidth typically your connection is severely bandwidth restricted until you pay. If they didn't then someone could simply stream movies from their chat apps.

I don't think so, compared to transcontinental, which lately (before Starlink) has been using the cell towers on the ground + satellite backhaul -- even paying would probably still result in a garbage experience.

Re: A story about bypassing air Canada's in-flight network restrictions

#47

Earlier quoted context omitted.

Say you're on a plane from Canada to Hong Kong (random example), which country's laws would be applicable here? The country where the airplane is registered?

Same country that would be responsible if you stab your seat neighbor for taking too much space I‘d guess.

> if you stab your seat neighbor for taking too much space

IIRC the way it works is that when you land (destination or forced landing elsewhere) the offender is delivered to the local competent authorities.

They then undertake an initial investigation and decide either to exercise their own jurisdiction or undertake extradition proceedings to send the offender to the country of registration of the aircraft.

In a scenario of (attempted)murder, I suspect that it is highly likely it would be dealt with in the local courts unless there was a specific external push for extradition.

The point of the convention is to ensure there is never no jurisdiction, i.e. the country of registration to the aircraft is always there as the ultimate fallback. The wording doesn't seek to strictly define the jurisdiction, which is why in most cases the delivery country has the option to take jurisdiction.

Re: A story about bypassing air Canada's in-flight network restrictions

#48

> We affirm our strict adherence to all relevant regulations and service terms throughout this project. Except if you bypassed payment and used the service in a manner that was not intended, most likely you were by definition not undertaking "strict adherance" to service terms ?

Yeah I am a bit confused about posts like this. It’s bragging about breaking the law. There was a particularly bad one a few months ago where a kid had hacked Monster’s employee training site, and was sharing all this internal media in the post. I don’t understand how they don’t end up getting in some seriously annoying trouble with law enforcement. Well I looked it up just now and the post was deleted, I guess maybe…

I didn’t see this, but the monster hacker blog post is up on archive. Honestly the person sounds like a kid:

https://web.archive.org/web/20250823174801/https://bobdahack...

Re: A story about bypassing air Canada's in-flight network restrictions

#49

Earlier quoted context omitted.

Yeah I am a bit confused about posts like this. It’s bragging about breaking the law. There was a particularly bad one a few months ago where a kid had hacked Monster’s employee training site, and was sharing all this internal media in the post. I don’t understand how they don’t end up getting in some seriously annoying trouble with law enforcement. Well I looked it up just now and the post was deleted, I guess maybe…

Could also just be lack of knowledge. Weren't we all a bit more risky and playful with other people's websites when we were kids and the internet was still accessed via modems? Remember talking about that with both other kids and adults without getting in trouble, but it was also decades ago. Once I saw others getting in real big trouble (like prison), then I kind of tried to find more beneficial ways of learning pro…

> Remember talking about that with both other kids and adults without getting in trouble.

A few kids doesnt matter. A few adults is only a problem if it's their stuff (If they are teachers, they will care more about unautorized changes of the wallpaper in the computer of the school that anything in a remote computer.) And yuo can even later claim they misunderstood or you were exagerating.

But here is an in written report in front of thousands of persons and about planes that is a sensitive topic.

Re: A story about bypassing air Canada's in-flight network restrictions

#50
post #46
post #9

Earlier quoted context omitted.

This is likely another layer of security that they didn't break through: To prevent chat apps from consuming lots of bandwidth typically your connection is severely bandwidth restricted until you pay. If they didn't then someone could simply stream movies from their chat apps.

I don't think so, compared to transcontinental, which lately (before Starlink) has been using the cell towers on the ground + satellite backhaul -- even paying would probably still result in a garbage experience.

The point is that if the connection does have more bandwidth available they wouldn't get that extra bandwidth without paying.
Post reply on HN