Earlier quoted context omitted.
He was accessing the router by sending packets through it. Authorisation to do this was only granted in return for payment, and he hadn't paid.
From your link: > the term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter; The information they were accessing didn't come from the computer. And this doesn't say anything about using a computer service in an unauthorized way, which is what it sounds like you're desc…
Stunnel and Airline Wi-Fi
81–90 of 239 posts
Re: Stunnel and Airline Wi-Fi
#82Earlier quoted context omitted.
> It's illegal to come into my house and take my stuff even if I forget to lock my back door. For some reason, on HN when I've made this argument before, the resulting comments have been that the internet is somehow different, and that real-world analogies don't exist. Using equipment that you don't own in a way the owners don't intend is apparently well-accepted.
Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.
How is this a victimless crime?
Re: Stunnel and Airline Wi-Fi
#83Nice post and well written. I’ll have to try something similar with stunner for my office connection (heavily filtered and firewalled), to allow me to reach my raspberry back home.
Just note that doing that is probably a fireable offense.
Re: Stunnel and Airline Wi-Fi
#84Earlier quoted context omitted.
It's not nuts when compared to non-tech laws. It's illegal to come into my house and take my stuff even if I forget to lock my back door. If we want to protect security professionals, we should write laws that do so.
It's not illegal to use 500GB of fibre bandwidth in a month when you only pay for 250GB though (say due to a bug in their method of counting usage).
Re: Stunnel and Airline Wi-Fi
#85The comment about the 24Mbps is pretty impressive. My experience every month on the JAL flights SF to Tokyo and Tokyo to $SomeOtherAsianCity is pretty crappy. I wonder if doing this it also bypasses some QoS filters? For example on a flight I tried to open the XM app on my iPad and could not stream a thing (it's pretty low but rate). Slack connects and disconnects all time. Email works but is slow. Webpages take minu…
That’s because you’re traveling in airspace covered by different Satellite than the one that covers The American continent. Top speed should actually be ~74MBps. I was one of the people who helped build the system (not at Viasat)
Re: Stunnel and Airline Wi-Fi
#86In the USA this would be a violation of the CFAA https://www.law.cornell.edu/uscode/text/18/1030 . Specifically, the router is a "protected computer" and the procedure described here is "exceeding authorised access" because it routes packets around a mechanism that was designed to stop them. Maximum penalty 5 years. (Some might argue that it was authorised because the computer let him do it. However the CFAA simply d…
How does this not apply to stuff like trackers bypassing anti-fingerprinting browser protections?
Re: Stunnel and Airline Wi-Fi
#87While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?
A good point. To be fair, though, even Lifehacker has posted a similar writeup [1] (linked in the article) and I don't think they've been threatened. Getting caught in the air - now, that's a different story ;) [1]: https://lifehacker.com/get-free-unlimited-wi-fi-on-flights-a...
Re: Stunnel and Airline Wi-Fi
#88While interesting, I would have an uneasy feeling messing with the WIFI AP on an airplane. Perhaps there is a U.S. law this type of conduct would fall under specific to being on an airplane?
My guess would be that getting caught doing this could get you federal terrorism charges. I don't even think it's a safe assumption that the network is isolated or properly insulated from pilot instrumentation.
Having ANY access AT ALL whether via "hidden" backdoor or authorized login to plane instrumentation from the WiFi would be an insane setup. Just because they're both invisible to you doesn't mean they're connected in some way. Could you imagine the attack surface? We'd be hearing about terrorist attacks leveraging that design flaw.
Re: Stunnel and Airline Wi-Fi
#89Earlier quoted context omitted.
See the discussion on the CFAA act elsewhere. At the very least it would be theft of services, although this is typically a state thing, so I'm not sure how jurisdiction would work up in the air.
> theft of services If you have a contract, is this really a crime in the US? That's a civil matter!
Re: Stunnel and Airline Wi-Fi
#90Earlier quoted context omitted.
Probably because this is a victimless crime... What he did would be more akin to someone entering your property, having their lunch in your garden and cleaning up before leaving.
> Probably because this is a victimless crime... How is this a victimless crime?
Thus: let's switch who is penalized: everyone else on the flight. Bandwidth isn't unlimited, without payment it's hard to justify increasing bandwidth if it isn't profitable.
What should the author do? Report it. If he didn't, maybe you can submit it to the company. If they have a bug bounty, you may get paid (if this happens: would you give the money to the original author?)
If you run a company: you should determine how to insensitivise reporting, it's possible in this case: not fixing it spreads awareness, most people can't/don't exploit it.