Live data from Hacker News

A story about bypassing air Canada's in-flight network restrictions

ramsayleung.github.io

91–100 of 169 posts

Re: A story about bypassing air Canada's in-flight network restrictions

#91
Great writeup.

I have done similar things on several long flights.

Very often, there is at least one large cloud provider or CDN (e.g. Microsoft/Azure or Amazon/AWS or Google/GCP) that is whitelisted by the in-flight Internet gateway so that it can serve static pages, and I can get access to all the sites hosted by that provider simply by using domain fronting (which the author of this post describes as "disguise domain": https://ramsayleung.github.io/en/post/2025/a_story_about_byp...)

Re: A story about bypassing air Canada's in-flight network restrictions

#92
post #10

If a ping to a specific IP times out, I wouldn't say the IP is blocked. It could be that ICMP specifically is blocked, following some network rules on the firewall. This is pretty common in entreprise networks to not allow endpoint discovery. I could be missing something and happy to be corrected here, but I was surprised to read that.

Yeah, ICMP tunnelling is also a common bypass method for captive networks, so simply blocking all ICMP seems logical.

Every time I've had to fight with path MTU discovery not working I've cursed the people who block all ICMP, though. If ICMP echo / echo-reply is the problem just block that. At the very least, allow destination unreachable / fragmentation needed thru (type 3, code 4).

Re: A story about bypassing air Canada's in-flight network restrictions

#93
post #32

Earlier quoted context omitted.

I was going to say this too. I once merely mentioned the words “Heart Attack” on a plane and was kicked off by the flight attendants. No context, they just heard the words and forced me off. There are things that trigger them because of laws and regulations like mentioning “bomb” (even if you’re describing something fantastic). So messing with the gogo flight entertainment is up there with flirting with terrorism cha…

I'm pretty "curious" when it comes to public networks. I'll scan coffee shops, stadiums, hotels, bus hotspots, anything I can connect to. Some networks are set up well, others not so much. I would never in a thousand years run a sweep on an airplane network. That's massively risky, to the point you might never be allowed on a jet again. Anything to do with aviation I am on my absolute best behaviour.

The router is 100% separated from the rest of the plane, and has a fuse on the power. You can't really mess anything up and the only chance of you getting caught is if you somehow manage to ddos the network.

The fun thing to do on the plane is clone the wifi and add an option to log in with google or meta or apple credentials....

Re: A story about bypassing air Canada's in-flight network restrictions

#94
post #68

Earlier quoted context omitted.

Most countries will have laws covering cases of unauthorized access, theft of services, and computer misuse. The user agreement helps define the service as a paid service with defined access cases. Going around those would put the user in violation of some laws. An analogy would be showing up to a paid event venue and noticing a back door was left open. Going into the building without paying is not okay, even though…

If the user routed all traffic through a WeChat or other messaging service, they would just be using messaging.

Intent matters. In US legal jurisdictions that could potentially be prosecuted as a CFAA violation, although I'm not aware of any cases like that yet.

https://www.justice.gov/jm/jm-9-48000-computer-fraud

Re: A story about bypassing air Canada's in-flight network restrictions

#95

> We affirm our strict adherence to all relevant regulations and service terms throughout this project. Except if you bypassed payment and used the service in a manner that was not intended, most likely you were by definition not undertaking "strict adherance" to service terms ?

Yeah I am a bit confused about posts like this. It’s bragging about breaking the law. There was a particularly bad one a few months ago where a kid had hacked Monster’s employee training site, and was sharing all this internal media in the post. I don’t understand how they don’t end up getting in some seriously annoying trouble with law enforcement. Well I looked it up just now and the post was deleted, I guess maybe…

I was about to correct you and say that bobdahacker hacked McDonald's, but I guess he did both, and bragged about both.

Re: A story about bypassing air Canada's in-flight network restrictions

#96

Earlier quoted context omitted.

Oh, that's nasty. How long did it take you to troubleshoot that?

Relatively speaking, it wasn't that bad. It took a few weeks of getting trouble tickets with no root cause, and a bit of googling. But management wasn't okay with fixing the root cause, instead they just increased the timeout/retry window.

Wow. That's a classic. We were quite motivated because we were the ones that got the automated alerts. I still see them in my nightmares: "chopper is down". The machine was called chopper, I'll never forget, it's been close to 30 years. My buddy Jasper and me spent multiple nights trying to track it and when we finally found it we still couldn't believe that that was it. But a simple swap was proof.

Re: A story about bypassing air Canada's in-flight network restrictions

#97
post #23

I feel like you have to be brave messing with a plane's network. People tend to get really touchy when airplanes are involved.

I was going to say this too. I once merely mentioned the words “Heart Attack” on a plane and was kicked off by the flight attendants. No context, they just heard the words and forced me off. There are things that trigger them because of laws and regulations like mentioning “bomb” (even if you’re describing something fantastic). So messing with the gogo flight entertainment is up there with flirting with terrorism cha…

> I once merely mentioned the words “Heart Attack” on a plane and was kicked off by the flight attendants.

Well now you have a chance to tell your side - were you merely sitting and just uttered the words "heart attack" for no externally apparent reason?

Re: A story about bypassing air Canada's in-flight network restrictions

#98
post #76

Earlier quoted context omitted.

Yeah, I just flew WestJet from Canada to Honolulu and was amazed; full 1080p YouTube with no hiccups and I was able to play some (non-latency sensitive) online games, all over the Pacific. This was fully intentional; there wasn't any back-of-the-seat iPad for watching movies or anything, they straight up tell you to use your own device and watch Netflix. I did some research after and found a lot of airlines in NA are…

> This was fully intentional; there wasn't any back-of-the-seat iPad for watching movies or anything, they straight up tell you to use your own device and watch Netflix. Westjet has required you to use your own device for a long time now (10 years?), but they offer an app/website and streaming library that works for anyone who connects to the in-plane wifi, unrelated to actual access to the internet. Interesting that…

Nope, wifi was free. Well, have to sign up for WestJet rewards, so the price is your personal data and such. No WestJet streaming option, the information card in the backseat tells you to use your own Netflix account; yes, literally mentioning Netflix by name.

Re: A story about bypassing air Canada's in-flight network restrictions

#99

Earlier quoted context omitted.

If you move to an empty seat to prevent WiFi signal strength triangulation, and assuming the cabin has no cameras, you didn't auth to the network with identifiable information, actually encrypt your Xray proxy connection (which OP didn't), and you have MAC randomization on, there's next to no way the airliner would be able (or even care) to identify that you did what was described in the article. Sure, they could use…

I highly doubt any airline staff are on your flight (or even remotely) counter-hacking one in a billion passengers messing around with the in-flight WiFi. That $30.75 they're not getting doesn't justify anyone looking into it.

Plus, the free tier is usually set to a very low QoS such that chat is pretty much the only thing you'd bother doing. Short videos will download in a reasonable amount of time but on average, the actual data rate is small. There's only so much bandwidth available and they want to make the $30 somewhat of a value for those needing full Internet access. One person absolutely saturating the limited bandwidth allowed for the free tier is not going to make much of a difference for everyone else but it could be an issue if everyone was doing it (like if a VPN was all that was required to bypass the restrictions).
Post reply on HN