Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

71–80 of 239 posts

Re: Stunnel and Airline Wi-Fi

#72
post #69

Earlier quoted context omitted.

> It's illegal to come into my house and take my stuff even if I forget to lock my back door. For some reason, on HN when I've made this argument before, the resulting comments have been that the internet is somehow different, and that real-world analogies don't exist. Using equipment that you don't own in a way the owners don't intend is apparently well-accepted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

Granted that's still a crime. You probably won't use the video recording of that guy to file a police report (unless you suspect he did something else on your property, which would be like the author also running aggressive nmap scans) just as viasat is probably not going to file a lawsuit.

Re: Stunnel and Airline Wi-Fi

#73
post #69

Earlier quoted context omitted.

> It's illegal to come into my house and take my stuff even if I forget to lock my back door. For some reason, on HN when I've made this argument before, the resulting comments have been that the internet is somehow different, and that real-world analogies don't exist. Using equipment that you don't own in a way the owners don't intend is apparently well-accepted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

What a dumbass analogy. They stole bandwidth. And bandwidth on an airplane is extremely limited.

Re: Stunnel and Airline Wi-Fi

#74

While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?

While in general bypassing Wi-Fi restrictions is indeed dubious from legal standpoint, it’s most likely as safe on an airplane as anywhere else. If in-flight Wi-Fi provider’s AP was in any way part of aircraft control system network, I would be surprised if overseeing such a design flaw weren’t a crime.

Re: Stunnel and Airline Wi-Fi

#75
post #10

This seems quite unethical to me.

It is theft of services. Ironical in this website since ycombinator companies are mostly about selling services via the Internet.

Well, the flip side is that Y Combinator has no qualms about funding companies whose business model relies on ignoring laws that are inconvenient.

Here are two different YC startups that relied on tourists smuggling goods to avoid import duties:

https://techcrunch.com/2014/08/13/backpack-connects-you-with...

https://news.ycombinator.com/item?id=10998377

Re: Stunnel and Airline Wi-Fi

#76
post #66

Earlier quoted context omitted.

If someone charges for tours of part of their house, has two prices of tour, and you change the colour of your badge to let you access the part you haven't paid for, is that a crime?

Sounds like some form of fraud to me. What's the difference between that and simply forging a ticket to an event instead of buying one? Or forging a currency note?

OK, the better example from further down. You realise your badge lets you into areas of the premium tour, it opens all doors, not just the ones you paid for it to open.

And even if it is fraud of some kind, the bar for charging someone with fraud (instead of just suing for damages) is fairly high...

Re: Stunnel and Airline Wi-Fi

#77
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

How does this not apply to stuff like trackers bypassing anti-fingerprinting browser protections?

Re: Stunnel and Airline Wi-Fi

#78

While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?

It's also, you know, wrong. Old fashioned wrong. Stealing.

Re: Stunnel and Airline Wi-Fi

#79
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

How does this not apply to stuff like trackers bypassing anti-fingerprinting browser protections?

Because a prosecutor hasn't tried to use it in that way.

Re: Stunnel and Airline Wi-Fi

#80
Wow, this was an amusing read. I actually helped architect part of the system that was bypassed at LiveTV (now Thales). We had some serious hackers on the team and discussed how much probing & prodding it would take to find vulnerabilities like this, but made the conclusion anyone doing this should be worried about more serious consequences. I for one, wouldn’t attempt this myself on the aircraft. The hacker side of me finds this Amusing, but I hope the author doesn’t face more serious consequences, primarily for having made this public knowledge. I have a sense the defense company that now owns the system being bypassed/broken will not find it amusing in the least bit.

Disclaimer: opinions above are my own. I do not speak for or on behalf of any party in the article.

Post reply on HN