Live data from Hacker News

Stunnel and Airline Wi-Fi

potatofrom.space

81–90 of 239 posts

Re: Stunnel and Airline Wi-Fi

#81
post #42
post #41

Earlier quoted context omitted.

He was accessing the router by sending packets through it. Authorisation to do this was only granted in return for payment, and he hadn't paid.

From your link: > the term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter; The information they were accessing didn't come from the computer. And this doesn't say anything about using a computer service in an unauthorized way, which is what it sounds like you're desc…

The output buffer on the Internet side of the router is information in the computer. It was modified without authorization when packets were sent through it.

Re: Stunnel and Airline Wi-Fi

#82
post #69

Earlier quoted context omitted.

> It's illegal to come into my house and take my stuff even if I forget to lock my back door. For some reason, on HN when I've made this argument before, the resulting comments have been that the internet is somehow different, and that real-world analogies don't exist. Using equipment that you don't own in a way the owners don't intend is apparently well-accepted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

> Probably because this is a victimless crime...

How is this a victimless crime?

Re: Stunnel and Airline Wi-Fi

#83

Nice post and well written. I’ll have to try something similar with stunner for my office connection (heavily filtered and firewalled), to allow me to reach my raspberry back home.

Just note that doing that is probably a fireable offense.

Definitely agree! Irrespective of motive it would raise questions about integrity! You don’t want to be going there!!

Re: Stunnel and Airline Wi-Fi

#84

Earlier quoted context omitted.

It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.

It's not illegal to use 500GB of fibre bandwidth in a month when you only pay for 250GB though (say due to a bug in their method of counting usage).

It is if you intentionally structure your communications to evade their accounting.

Re: Stunnel and Airline Wi-Fi

#85

The comment about the 24Mbps is pretty impressive. My experience every month on the JAL flights SF to Tokyo and Tokyo to $SomeOtherAsianCity is pretty crappy. I wonder if doing this it also bypasses some QoS filters? For example on a flight I tried to open the XM app on my iPad and could not stream a thing (it's pretty low but rate). Slack connects and disconnects all time. Email works but is slow. Webpages take minu…

That’s because you’re traveling in airspace covered by different Satellite than the one that covers The American continent. Top speed should actually be ~74MBps. I was one of the people who helped build the system (not at Viasat)

It's almost a 1Gbps over sat link, are you correct?

Re: Stunnel and Airline Wi-Fi

#86
post #25

In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…

How does this not apply to stuff like trackers bypassing anti-fingerprinting browser protections?

You could say the same about adblock then, so lets not open that can of worms

Re: Stunnel and Airline Wi-Fi

#87

While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?

A good point. To be fair, though, even Lifehacker has posted a similar writeup [1] (linked in the article) and I don't think they've been threatened. Getting caught in the air - now, that's a different story ;) [1]: https://lifehacker.com/get-free-unlimited-wi-fi-on-flights-a...

Getting caught in the air seems nigh impossible, since by using this trick you aren't giving them any way to identify you.

Re: Stunnel and Airline Wi-Fi

#88

While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?

My guess would be that getting caught doing this could get you federal terrorism charges. I don't even think it's a safe assumption that the network is isolated or properly insulated from pilot instrumentation.

If that assumption isn't safe, then neither is the plane.

Having ANY access AT ALL whether via "hidden" backdoor or authorized login to plane instrumentation from the WiFi would be an insane setup. Just because they're both invisible to you doesn't mean they're connected in some way. Could you imagine the attack surface? We'd be hearing about terrorist attacks leveraging that design flaw.

Re: Stunnel and Airline Wi-Fi

#89

Earlier quoted context omitted.

See the discussion on the CFAA act elsewhere. At the very least it would be theft of services, although this is typically a state thing, so I'm not sure how jurisdiction would work up in the air.

> theft of services If you have a contract, is this really a crime in the US? That's a civil matter!

But that's the point, you partook of some service without entering into any agreement that you were allowed to do so.

Re: Stunnel and Airline Wi-Fi

#90
post #69

Earlier quoted context omitted.

Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.

> Probably because this is a victimless crime... How is this a victimless crime?

It's not victimless, the loser is the service provider whose bandwidth is consumed. The line many draw is that corporations aren't people and can't be the victim, this is a false analogy.

Thus: let's switch who is penalized: everyone else on the flight. Bandwidth isn't unlimited, without payment it's hard to justify increasing bandwidth if it isn't profitable.

What should the author do? Report it. If he didn't, maybe you can submit it to the company. If they have a bug bounty, you may get paid (if this happens: would you give the money to the original author?)

If you run a company: you should determine how to insensitivise reporting, it's possible in this case: not fixing it spreads awareness, most people can't/don't exploit it.

Post reply on HN