Hotel Wi-Fi blocking: Marriott is bad
economist.com
economist.com
And getting a mobile telephone call in such events is even trickier, given that 50,000 people are in one space and the masts to serve them are oversubscribed. If they all suddenly want to place bets or browse the web, that's incredibly difficult to provide on the mast, so providers will set up additional masts for big events (like the big horse-racing events here in the UK). That's why they provide free wifi too, and having other APs set up and attempting to provide wifi over the airspace doesn't really help.
I wonder if Marriott hotels have the same approach in order to provide better wifi coverage? I have been in numerous hotels where the wifi coverage was great if you're sat in the bar but abysmal if you're down the other end of the building (where the hotels here in the UK are large old buildings with thick walls, very tricky for wifi).
Irritating if you're trying to use your phone to provide wifi to your laptop in order SSH to your own box at home or to get content via your mobile (which might be faster than their Internet access in some cases). I suppose you could just use a Bluetooth PAN instead (and it uses less power!)
The most typical problems with wifi in resorts comes down to construction; most of these were built years before wifi was a consideration and are constructed in a way such that even with commercial APs you will get a very poor signal even with the APs in each unit. There's one such property I know of where guests only get wifi in the one room with the AP and out on their balcony and no where else in the hotel besides the pool & lobby.
Also they often use authentication pages that mean you can't get on with a device without a browser...but when you have 200 guests sharing a 100Mbps connection, you don't want someone hooking their Xbox or AppleTV anyway.
Ruining is subjective - many hotel wifi networks were provisioned for 2002 style access of web and email, not 2012 where one's mom streams gigs of video. This is why I appreciate the move to free basic wifi and paid premium wifi at some hotels.
Cisco sell a Wireless LAN controller, which can
send disconnect packets to "rogue" APs [...]
this would help to encourage the other AP
providers to turn their boxes off.
Perhaps I should make a product that detects controllers sending fake deauth packets, and does the same thing in return.This would help "encourage" people who buy the Cisco product to turn that feature off :)
The first main use case for the deauth packets is when someone is broadcasting your SSID but they're not actually part of your network. The second use case is when a client that you actually own (corporate laptop) connects to an access point it's not supposed to. And nobody will really mind if you do those.
This anti-competitive use case is another matter.
"Federal law prohibits the operation, marketing, or sale of any type of jamming equipment, including devices that interfere with cellular and Personal Communication Services (PCS), police radar, Global Positioning Systems (GPS), and wireless networking services (Wi-Fi)."
If that disconnect is disabling wifi aps then technically it is "intefering" with wifi services and thus illegal?
If you DDOS my website, which is for some reason attached to the internet via wireless, you're not jamming anyone. You're doing a DDOS. The regulatory body or laws surrounding that are going to be different than a proper old fashioned RF jam.
"No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this Act[.]" [1]
And in fact their explanation specifically states that jammers "prevent targeted devices from establishing or maintaining a connection". [2]
To put the same actions in a different context - if two radio amateurs are trying to communicate over a digital mode and I broadcast "disconnect" packets to shut them down, I am clearly jamming their communications. The fact that this jamming occurs on the 2.4GHz band instead of the 20-meter band is irrelevant.
What it comes down to - your laptop wifi is a device licensed by the FCC for radio operation, two parties (you and the router) are communicating, and a smart jammer interferes with these communications.
As for your DDOS example - jamming is usually used in the context of the low-level layers of the OSI model, not the application layer. However, there are analogous actions that would be actionable in amateur radio. If you get a dozen of your buddies to deliberately pile-up on someone's CQ/QRZ without actually trying to communicate, you can bet the FCC's gonna look at that as de facto jamming too.
You can get away with a lot as long as you do it on private wires - but when you get public airwaves involved then an additional set of much stricter rules apply.
[1] http://www.fcc.gov/document/fcc-proposes-29k-fine-employer-j...
[2] http://www.fcc.gov/document/consumer-alert-using-or-importin...
In support of its motion for summary judgment on the monetary forfeiture, the Government presented FCC transcripts of recordings made on November 27, 2004, December 8, 2004, and March 31, 2005 that it alleges show K1MAN beginning to transmit on top of existing communications by other users. [...] The Government also provided the declarations of several FCC personnel who monitored and observed interference between K1MAN and other amateur operators. [...] [1]
Chief US District Judge John A. Woodcock Jr, in writing for the Court, agreed with the FCC on the first two counts -- willful or repeated failure to respond to FCC requests for information, and willful or malicious interference -- and granted summary judgments to the FCC in the amount of $3000 and $7000, respectively. [2]
As for more targeted attacks, see the Notices of Apparently Liability for KZ8O [3] and K3VR [4].
Once public airwaves are involved (as opposed to wires) you're on the FCC's turf, and the FCC takes radio communications VERY seriously.
[1] http://www.arrl.org/files/media/News/Baxter_Summary_Judgment...
[2] http://www.arrl.org/news/us-district-court-for-maine-issues-...
[3] http://transition.fcc.gov/Daily_Releases/Daily_Business/2014...
[4] http://transition.fcc.gov/Daily_Releases/Daily_Business/2014...
On that note, it's worth pointing out that many Android (and other) phones allow USB-based tethering as well, which eliminates the need to use the airspace entirely.
Of course this doesn't do any good for existing consumer devices, it would have to be baked into the next 802.11x spec.
"Wifi should be like air: Free and Everywhere"
And they have a totally open wifi network. I live in Karachi, Pakistan.
There are no "portals," no "user agreements," just beautiful open Wi-Fi scattered all over the place. It's hard to imagine spending even $5 at any place that wouldn't offer you internet access, much less the $150+ that Marriott charges its "guests."
Sooner or later all this unnecessary friction (sorry, "added value") is bound to catch up.
It also needs to be kept in mind that all these asian small places have DIY wifi, while hotels got into the wifi game way too early and locked themselves into expensive, underdelivering and long-term contracts with 3rd party companies that do the wifi for them.
I assume nothing ever happens in a lot of asian countries when somebody torrents their favourite new movie/tv show from one of these connections while I imagine US ISPs send nasty "stop it" letters every now and then. (even if the hotel might not be liable, that probably doesn't stop Comcast from sending them)
It's basically one group of scoundrels that got cheated by another group of scoundrels. I wonder though, how hard would it be for hotels to renegotiate those contracts - or drop them and eat the fee - if they actually cared?
It usually means the customer needs to bend over and grease up, because somebody's getting screwed ...
"For your convenience, we are increasing our fee from $1.95 to $9.95 ..."
"For your convenience, the complimentary continental breakfast is now available upon payment of a $14.95 convenience fee ..."
Now and then I look at how badly customer-facing businesses are misusing the word "convenience". Unfortunately, I am rarely disappointed.
I can stream HD YT to my laptop (via tethered 4G) and it works most of the time (although sometimes drops me out of HD).
I'm fine with Marriott using deauth jamming against rogue APs with their SSID (or a similar impersonating one, e.g. "Mariott Wifi" instead of "Marriott Wifi"), or operating on their specific wifi channel (thus downgrading the experience of the customers), but they absolutely have to leave APs alone which have a different channel/ssid.
While they might have a justification that a "Mariott Wifi" ESSID on a Mariott hotel is theirs, how can they say a specific wifi channel is "theirs"? Wifi runs in unlicensed bands, any device which meets certain technical requirements is allowed on any channel in these bands, no matter who the device owner is. The 802.11 protocol is designed to share wireless channels between APs with different owners (while it also assumes that APs with the same ESSID have the same owner).
And what would be "their" channel? A well-designed wireless network for a large enough area will use several channels. Unless they have a single AP (unlikely) or their network is not well designed, they are probably using all the non-overlapping channels in the 2.4 GHz band and many channels in the 5 GHz band, including all the non-DFS ones.
The South Korean government has done that quite regularly, for one (known as DarkHotel), and I do believe GCHQ does it over here from time to time. Several others too, I expect. Intelligence agencies just like hotels, I guess, between the visitors of diplomatic, political and economic interest, the public access, potentially lowered guard, and things left unattended in hotel rooms locked by surprisingly forgeable master keys?
Which can easily run into thousands of dollars for a weekend, so if an event wants to do, say, live streaming, they do their best to make it impossible for the event to bring its own hotspot and connection.
"Marriott employees had used containment features of a Wi-Fi monitoring system at the Gaylord Opryland to prevent individuals from connecting to the Internet via their own personal Wi-Fi networks, while at the same time charging consumers, small businesses and exhibitors as much as $1,000 per device to access Marriott's Wi-Fi network."
In your room or in the conference center you should be able to use your own Wi-Fi without interference.
Source: http://www.fcc.gov/document/marriott-pay-600k-resolve-wifi-b...
That aside, what is the solution to rogue access points in a public space? We all know that it's pretty easy to set up camp in a public space, broadcasting a friendly-looking but dangerous wifi network. Let's says you've got someone sitting in the Marriott lobby, creating the "Marriott Free Wifi" network. A bunch of people will connect to it, and some information will leak.
Is there any reasonable way to deal with this issue? Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there.
Yes, but it doesn't need constant attention. A small router can be dropped anywhere and route the information to the attacker long after (s)he's gone.
That said, finding the AP and disabling it is better than randomly throwing deauth packets.
Agreed on the security hole on public wifi, though it's probably about less "sensitive" data as HTTPS is becoming more of a standard, especially after the Snowden revelations.
Most services/apps speak HTTPS nowdays and a lot more will (hopefully) follow: https://letsencrypt.org/
> Is there any reasonable way to deal with this issue?
So, yes with HTTPS
On the other hand, you're also saying that people shouldn't care as much about security if they are on the proper wifi network, which is a little ludicrous. Just hope on a vpn either way, and you're safe.
I'm sure there's a law against this though.
I can't imagine this would be illegal. Jamming signals may be hard to do legally, but keeping them out is probably impossible to forbid by law.
If the hotel puts a grounded Faraday cage around your room, that's blocking. If it transmits 1000 watts of static on the 2.4 GHz band, that's jamming. The former is legal, and the latter is not.
> Marriott operates a Wi-Fi monitoring system manufactured by a third party that was installed at the Gaylord Opryland. Among other features, the system includes a containment capability that, when activated, will cause the sending of de-authentication packets to Wi-Fi Internet access points that are not part of Marriott’s Wi-Fi system or authorized by Marriott and that Marriott has classified as “rogue.”
[0] https://apps.fcc.gov/edocs_public/attachmatch/DA-14-1444A1.t...
(1) Removing security risks: You really don't want people running their own WiFi access point plugged into the corporate network.
(2) Removing interference: In order to remove interfering APs / stations from the network, it deauths them in order to disconnect them.
You can learn more about the mechanisms used here: https://en.wikipedia.org/wiki/Wireless_intrusion_prevention_...
They also have a pretty good back and forth on the issues about it. One can probably find it in the show notes if you want to find out which casts have covered it already.