How I hacked Gogo inflight wireless Internet with Chrome
blog.andrewboni.com
blog.andrewboni.com
Seriously, kids: this is an astoundingly bad idea.
It seems equivalent to saying "red computers get charged half price", and then objecting when someone snaps a red shell on their laptop.
There is no affirmative defense "But it was really easy for me to exceed my authorized privileges because their security sucked" provided for in the law.
(i) Did the defendant knowingly access a system used by the federal government, a financial institution, or a system used in interstate commerce without authorization?
(ii) Did they have an intent to defraud? (This is the key issue and the point I believe you were making)
(iii) Did the actual computer access materially advance their fraudulent scheme? (You can't drag computers into any given fraud case to make it federal)
(iv) Did they obtain anything of value?
So far so bad: the answers to all four questions are "yes".
But: when the object of the fraud is access to the computer system itself --- that is, when the "thing of value" is "use of the computer system in question", there's a fifth test:
(v) Was the total value of the computer usage greater than $5000?
Nope.
Very important to note here though: regardless of the fact that it is vanishingly unlikely that a CFAA case would be brought here, and even less likely that the prosecution would prevail, if by committing this particular little fraud and then bragging about it on the Internet this blog post cost the operators of the service a huge amount of money to strengthen defenses or investigate system usage, the blogger has opened themselves up to a very painful civil case.
The answer to that one is "no". He had authorization to both pages. Unless we're going to interpret that authorization was given to each device and not the person.
Good luck with that argument.
Further playing devil's advocate: it seems that the system is not so much that the provider cared about whether it was a phone or computer (I bet a galaxy tablet would get the mobile price... and I can use just as much data on that as on a laptop without trying very hard at all), but whether they were using a browser with a mobile user-agent string. They offered a discount for having the right user-agent string, and being willing to browse the mobile version of Gogo's landing page.
Questions this raises: what if my phone browser was not on their list of mobile browser agent strings? Say it was just a custom webkit thing I built? Or a firefox compiled for a tablet? Would I be defrauding by making my user-agent work for my mobile device? What if I had been working with a mobile browser compiled for my laptop, as I was just browsing with it, but not using my phone, so I could get a feel for various quirks it would introduce over a non-mobile browser, in an easy to side-by-side way on my nice big laptop monitor?
By analogy, a few years ago, many mobile banking sites worked just fine with firefox, but those users were denied access because it was an "IE only" site. Does changing the user agent to IE to gain access to the bank site then also constitute fraud? Web/interne banking is something of value.
edit: Accidentally said mobile instead of web.
Then what are we arguing about? The way they enforce that restriction is relevant only to the extent that someone could accidentally violate it. You can't accidentally commit fraud.
As I said, a laptop is arguably a mobile device. Further, there is nothing there that states it is for a mobile device, just that it is the mobile page. It doesn't say "for phone users only".
As for my analogous situation: My bank said I could only sign in through IE to access my web banking. Does this mean I committed fraud to access via a Firefox with changed agent string? I used that log in to transfer money to my debit card account and get some cash. Definitely a deceit with value. (Note, the account was in fact mine).
On the other hand, when you see $7.99 for phone service and $25.99 for computer service, it's clear to a reasonable person what the intent of that price difference is: the company wants to charge more to computer users.
As for the clearness or not-clearness of the message: there's a lot of reasons why I think this case isn't going to the Supreme Court. If you want to suggest that the clarity of the pricing message is one of those reasons, I'm not going to disagree too strongly --- though I do disagree.
Second, what is the real line between say a macbook air or other keyboarded computer and an ipad or galaxy table or kindle fire or... they all run operating systems that let me use more or less the same software and access the same network resources.
The combination is really the difficult part for me, given I can do the same things - look at the same sites, get the same utility, and otherwise use the same bandwidth in both cases, particularly when usb tethering is a real option giving me the same deal but now without the act you are calling fraud, how is it even reasonable to think that the "mobile" case is other than a discount for some magic words?
<devil's advocate> Well, in this case: No. The plan seen on the phone is simply labeled as "GoGo Mobile Pass". The plan seen on the laptop is labeled "GoGo Flight Pass". They do not clearly list any examples of what devices they think should be "mobile". It is not unreasonable to make the assertion that a laptop is a mobile device. Not recognizing the laptop as a mobile device sounds like a bug. This guy was able to find a work around for that bug. </devil's advocate>
It's a public facing website. He has authorization to access it. I don't see any other viable interpretation.
Whether or not Gogo should price discriminate like that, it seems clear that they want more money in exchange for authorizing use from a laptop.
(i) Did the defendant knowingly access a system used by the federal government, a financial institution, or a system used in interstate commerce without authorization?
My beef is with GoGo's price difference in the first place.
(a) Knowingly? The blog post (and the changing and then changing-back of the UA) makes this clear. (Though if he had happened to inadvertently had his UA set to mobile before hand, maybe to test something the day before, and never even saw the other screen... but once he saw it, and consciously decided to get around the higher price, it hits the "knowingly" requirement.)
(b) "Access a system used by the federal government, a financial institution, or a system used in interstate commerce"? The Gogo system seems pretty clearly an interstate commerce system to me, what with the whole used-across-the-country thing and the charging-for-access part.
(c) Without authorization? He specifically notes that he saw they charged different prices for different devices and purchased the option for a device that was not the type he was using. So he did not purchase authorization to use it from a laptop.
As to (c) I was reading "system" as the two signup pages, not the overall wifi system. Still, unless there's a difference between the mobile and laptop services, they're the same product regardless of type of device used to access the system, and you're paying for the service.
It would be like an all you can eat restaurant charging extra if you were over certain weight/height thresholds.
I think the majority of my vitriol comes because it's an asinine way to split up service based on what we're assuming is bandwidth concerns. If they want a tiered service, then put in a tiered rate structure. The "laptop" rate gets you 300kbps, the "mobile" gets you 100kbps. Simple.
That's about as far as I'd like to go with this particular branch of the discussion, if that's OK with you.
Now excuse me while I go listen to some Judas Priest... \m/
In other words: the law sees it as a bad thing that ISPs should have to bulletproof their offerings so that when they make a service available to phones, it isn't easy to trick those systems into providing service to computers. The law says, "it is silly that the market should have to bear the cost of that engineering, because it's undertaken solely to prevent dishonest people from obtaining undue benefit".
The only question you really have to ask here is, "am I tricking a business into offering me something with a dollar value without paying for it?" Yes? That's fraud. It's the definition of fraud.
People probably do violate all sorts of stupid laws all the time. But that's a very different point than "people commit all sorts of frauds all the time". They do not. Fraud is invariably wrong.
What services did he steal? He paid for wifi services for the duration of the flight. The device by which he enjoys that service should be of no consequence.
I still don't see fraud here.
If GoGo can't tell the difference between a laptop and a mobile phone, that's their problem. And no, the UA string doesn't guarantee that and there is no law that I've heard of that prevents users from altering their UA string (or anything for that matter). They showed him a price for a service on his device, and he bought that service.
I'd urge you to learn a little more about the law if you think that a UA string specific law is needed, or even a computer-specific law. Intent and personal gain are more an enough.
He did pay. The question now is, is this something roughly akin to switching price stickers on merchandise in a store. Since there's no specific requirement that a browser return an "accurate" UA string (whatever "accurate" even means for a UA string), this is closer to a company putting out a bucket with a sign saying "Honor System: suggested donation: $7.95 for phones, $15.95 for computers" and having somebody throw in $7.95 while using a computer. Not noble, but hardly something they should be punished for.
To the extent that the insignificance of this fraud will preclude it from becoming a federal case, I agree.
In general: don't lie to people to win deals for yourself. At all.
I find GoGo's double pricing to be the most morally objectionable thing about this whole situation.
Edit: Let's say they were price discriminating by looking at the size of your browser window, assuming anything < 600x400 is mobile and charging less. Is it illegal to resize?
[1] http://www.gogoair.com/gogo/cms/term.do [2] http://www.volokh.com/2012/04/10/ninth-circuit-hands-down-en...
No. The browser window size, or user agent string are just proxies for the real question: is the device a laptop or a phone/tablet/etc?
Your laptop remains a laptop whatever size the window is. This guy's laptop remained very much not a phone after altering his user agent.
Edit: It's worth adding that desktop browsers do not use mobile device user agent strings during normal operation, but small windows are perfectly legitimate.
You do need to intend to deceive to commit fraud, which moots your later example.
[1] http://www.useragentstring.com/pages/Internet%20Explorer/
No - there's no financial gain from using IE.
He has manipulated his computer to inform web servers that his device is a mobile device. I'm not aware of any desktop browsers which use mobile device user agent strings during normal operation. Whether it is discretionary or not is irrelevant, the point is that he's deviated significantly from normal behaviour, deliberately, without any legitimate reason (e.g. he wasn't at the time say, testing a mobile site), in fact with only the intent to defraud.
Ultimately, user agent strings are not a brilliant way to create a legally binding contract - it would be much smarter to have the contract amended based on the user-string to include "I confirm that my device is a laptop", and make this click-through.
1) He didn't trespass on a protected computer system or hack anything - he's using a web browser.
2) Users are not required to leave their browser's default settings intact when interacting with websites.
3) Where are the theft of services? He paid for a wifi internet connection for the duration of the flight with a price he was offered. He could have just as easily paid using his phone and then tethered his laptop to it.
A certain airline offers upgrades to first class seating, but only within a certain time period before the flight.
When using their website, I realized that I could pass in the time constraint as a parameter to their webapp. Boom, cheap first class upgrade, at any time!
Is that stealing? Yes. At the very least, theft of service. That first class ticket can sell for thousands of dollars, and instead, this trick would have allowed me to get it for hundreds. Just because their webapp allowed it doesn't make it OK. It's no different than tricking someone at the counter into giving you an item for free, or giving you extra change.
Am I committing fraud? Violating the TOS maybe? Both?
tl;dr: GoGo implements price discrimination in a naive way. Author "hacks" it with equally naive mechanism to save $8US.
We had one company gogo subscription. They connected and shared their internet through ethernet to another laptop. That laptop shared it out through wi-fi. We had 4 people using the Internet. It was awesome but fairly impractical. At least I could tweet from the clouds.
It would have been acceptable if the author was 13 or something but they appear to be an adult who works for google.
What next, spoofing referer to get into porn sites? l33t d00d!
Oh, it's $15? Nevermind.
If there were no 'hack', and I went on that plane knowing full well that I was going to purchase internet access, I would buy the half-off solution and tether to my phone.
As a user, this is a valid set of decisions. Since they're implementing this in a stupid way, it's perfectly valid to exploit their method and pay for the cheaper item.
If you went to the supermarket and found an item at $10, but you had the option of doing 5 jumping jacks to lower the price to $5, what would you do? Is it immoral to do jumping jacks?
Really?
If you went to buy something on Amazon, and found they had a "stupid" vulnerability you could exploit in order to get half off of your order—maybe some Javascript hack that made the part of their system that calculated the price you pay think you actually ordered a smaller version of the product—is that immoral?
Is leaving your house or car unlocked a sufficiently stupid vulnerability to become "perfectly valid to exploit"?
If Amazon charged $20 for a book if I were to buy it on my laptop, but $10 for that same book if I buy it with my phone, why in the hell would I buy it on my laptop? How is that immoral? I'm presented with two options: $10 or $20 for the same item. The company has offered me a contract of payment and I am to choose one, or I can take my patronage elsewhere. This is not a matter of breaking into a server and SQLi'ing until you can make an item free; this is the company offering me something for cheaper, depending on how I buy it.
This is preying on the notion that you "should" have to pay more for a laptop vs a phone access because that's what people have been conditioned to accept from their wireless carrier.
Oh, and what a seriously lame article in almost every respect. Awesome interface etc etc. This was the gentle reminder I needed to push me from these mind-numbing articles. Good luck and good night.