5 ms·
> Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this. Sad if true. If a service is providing public DNS access without a
by QualityReboot 7y ago
> Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this.
Sad if true. If a service is providing public DNS access without any service agreement, I don't see how making DNS queries with it could be illegal, especially on a public radio channel.
You might be right, but how?
It's certainly within their right to ban you by filtering out certain queries though.
- AdamJacobMuller 7y agoIt's theft of service. Remember as abstract as the law can be, the legal system is not going to be amused by contrivances like "they were offering DNS service free and clear, so tunneling youtube over DNS is fine" The legal system is going to understand that you were trying to circumvent paying for services and treat it appropriately.
- QualityReboot 7y agoHow can it be theft of service when they can deny you service at any time automatically by identifying abnormally heavy users and removing them? This isn't like bypassing the electrical grid by running your own line from somebody else's service. This is like saying it's theft of service to read a chapter in the bookstore. If you hang out there all day, you might get kicked out, but that's not a crime. The courts might agree with you, but only because "computers are hard". There's a world of difference between tunneling over DNS and compromising servers. Or at least, there should be.
- blackflame 7y ago"by identifying abnormally heavy users and removing them" - That costs money, ergo, theft. It's like if someone had to hire a security guard for a vending machine.
- QualityReboot 7y agoOr even just let those users alone. Users aren't stealing service if it's not even the same service. It's much slower than buying wifi from the captive portal. DNS tunnelling is not fast or convenient. Places deploying captive portals have probably looked at the risk to their business from it and have decided not to worry about it. I can't believe that using a slow DNS connection, intentionally made public, to tunnel traffic would be considered theft or criminal. How many free samples do I have to eat before I'm a theif? I don't believe I'm a thief until the offer for free samples is rescinded.
- blackflame 7y agoI would imagine at the very least you would degrade DNS resolution times for legitimate users since there would be a lot more requests than usual
- why-oh-why 7y agoThat’s exactly like bypassing the electrical grid. It’s like having a “free” street light and, instead of just enjoying the light, you pull its cables and plug your AC in. The free service is just for the light.
- QualityReboot 7y agoCan I use my solar powered calculator under a street light? Or is that theft of service too?
- danw1979 7y agoThe light is free. The electricity isn't.
- QualityReboot 7y agoI suppose adblock is theft too?
- dspillett 7y agoOpinion differs, but many ad-supported sites would say yes. I'm not sure if it has every been tested in court. "Fare dodging" might be a better concept to compare this to.
- ohazi 7y agoIirc, tunneling with iodine is somewhat slow, so > tunneling youtube over DNS is fine probably wasn't going to work very well anyway. (Happy to be corrected if I'm wrong, though!)
- wongarsu 7y agoApart from the theft angle it's also knowingly and maliciously circumventing access control systems. That's usually covered under anti-hacking laws
- QualityReboot 7y agoI'm floored that this is apparently how people are reasoning about the world now. Especially on HN. There is no circumventing of any access control here. If a service is giving a public access point, on public spectrum, and they let you connect, and they allow you to use DNS, you should be able to use DNS however their access control systems allow you to use it. Now if you find an exploit in their captive portal that allows you access to their service, then sure, that's illegal, because you're breaking into something. You can't circumvent access controls if the access control list is wide open.
- 1996 7y agoIndeed, sometime I'm also floored about the lack of openness here. As I often say, self-proclaimed nerds who can't imagine life without a big brother taking care of things love to complain and complain and complain. The ages of relying on oneself and technology seems gone. Cover-your-ass for 'nerds' I'll be happy to sell these self proclaimed 'nerds' lessons about how to secure a captive portal with iptables, so that no DNS or HTTP/S or ICMP can go through until the login is entered and the TOS validated.
- otoburb 7y ago>>Indeed, sometime I'm also floored about the lack of openness here. Quite the opposite -- there is complete openness in this thread about the technical aspects of the circumvention or use of the technique, plus open and timely reminders regarding the potential legal ramifications of executing this technique in certain jurisdictions.
- nkrisc 7y agoThe intent is that you have to pay to use the WiFi. Even if you find a clever technical way to circumvent that that, the judge will see what you were trying to do: avoid paying for the service is offered. The court is not a computer and a judge will use their human brain to make a judgement of your intent.