7 ms·
Save money on wifi using user agent switching
- davidchua 15y agoIsn't this fraud and an open admission of guilty?
- Luyt 15y agoHow is changing your UserAgent string fraud?
- luca-giovanni 15y agoIt isn't!
- rmc 15y agoYou are implying you are something you are not.
- icebraining 15y agoIf that was enough for fraud, our whole society would have to be jailed.
- Gravityloss 15y ago"You are"? It's just a browser "identification". It's widely known to be approximate, random and unreliable. It's common to try different agents because the web is full of bad pages which try to use it for something inappropriate. That's why user agent switching is a feature in all these browsers in the first place. It's like disabling CSS. Is it fraud to use a battery charger or electrical plug with an adapter? After all, the particular plug is a way of "identification", even when easily circumvented. How about using aftermarket parts for your car or camera. They are implying by their similarly spaced and shaped connections that they are genuine parts after all... What about console cartridge identification chips? These are somewhat interesting questions, if the HN crowd could have other opinions between "fraud" and "not fraud".
- TylerE 15y agoA restaurant offers a 25% discount to seniors (65+), but you're only 60. You copy your friend's AARP card, changing the name, and present the cloned card to receive the discount. Is this fraud?
- Gravityloss 15y agoProbably. It's interesting to think when a hack becomes a fraud or stealing.
- mindslight 15y agoWhen they get your identifying information and feel like hassling you. The only immoral thing here is the wifi provider increasing the complexity of the transaction to extract as much money as possible. Should one be required to tell the supermarket their net worth so they can be charged "appropriately" for their food? Anonymity is the basis for a shared existence. Two parties whose sole interaction consists of sending signals back and forth certainly don't need the outside law to mediate between them - if one party finds the relationship unfavorable, simply stop talking. It's a shame that people have been so brainwashed into thinking it's their responsibility to enforce someone else's desired business rules.
- TylerE 15y agoI find it a bit amusing that someone on this site, where so much of the content is about optimization and business models, is acting so morally offended by the concept of price differentiation.
- mindslight 15y agoSo many of the articles are about business model optimization because it's not the primary nature of hackers - they need to be reminded. The major difference is that the businesses here are new and the market and product are uncertain (inherently complex); Internet access, by definition, is a solved commodity.
- luca-giovanni 15y agoIs it legal to charge people different rates for the same service on different devices? I would argue it certainly isn't moral. Switching user agent is perfectly legal.
- mooism2 15y agoIt's legal to price discriminate based on age (discounted cinema tickets for children and pensioners), gender (free entry to certain nightclubs for women), occupation (teachers get educational discounts on some software, even when they only use it at home), not to mention the tricks aeroplane/train companies pull. So why not legal to price discriminate net access based on the device you're accessing it with?
- luca-giovanni 15y agoI guess it probably isn't but in any case it isn't a robust discrimination method as this guy has shown ;-)
- pbhjpbhj 15y ago>occupation (teachers get educational discounts on some software, even when they only use it at home) // Suppose they say "teachers" and you have a teaching license but aren't currently teaching. You present your teaching license and say "is this acceptable" and they say yes, you only need a teaching license to get the discount. That seems pretty analogous to the current situation. You possess the token they request and that they subsequently use to give you a lower price. You've not committed fraud because you're legally allowed to use that UA string. It's up to the provider to decide if their requirement is "passes us this UA string" or "declares ownership of this device" (I don't consider those things identical by a long stretch). Now if they say when you pass a particular UA string "do you confirm you're owner of $deviceType" or "this service is only for users of $deviceType" then I think things switch around in the direction of [rather minor] fraud.
- gmac 15y agoActually, not all of these are legal everywhere. In the UK, price discrimination by gender (e.g. by nightclubs) is illegal: see http://www.equalityhumanrights.com/advice-and-guidance/your-rights/gender/sex-discrimination-as-a-consumer/sex-discrimination-as-a-consumer-your-rights/ http://www.equalityhumanrights.com/advice-and-guidance/your-...
- MattBearman 15y agoThe wifi network never asked him what device type he was using, it just made an assumption based on something as unreliable as a user agent string. How is it fraud?
- Fizzer 15y agoHe knowingly manipulated their device detection system. Yes, it's true their device detection system is trivial to manipulate, but that doesn't change the legality. If a bank forgets to lock their vault, you still wouldn't want to clean them out and admit to it on your blog.
- luca-giovanni 15y agoWhat if you just choose to change your user agent to something different because you prefer the experience? If you then get different offers as a result you can't be held liable.
- ugh 15y agoIt's plausible deniability, nothing more. Illegal stays illegal.
- ktizo 15y agoIf there were an expensive nightclub which had a cheaper bar round the corner that only admitted people with the first name of "Dan", who then get full access to the nightclub and cheaper drinks all night, would it be criminal fraud to lie about your name to the doorstaff?
- no-downloads 15y agoAs someone named Dan I feel compelled to point out that such policies are really good and absolutely fair :-)
- function_seven 15y ago
- wladimir 15y agoThere is no law that you have to send any user agent at all, or indeed a valid one that matches your device/browser. It is just a hint for the server. Edit: and IMO, it's toxic to the hacker spirit to be too quick in condemning ideas as illegal or immoral
- deleted 15y ago[deleted]
- A1kmm 15y agoDisclaimer: IANAL, this is not legal advice. The article mentions it is in the UK. Relevant fraud statute appears to be this: http://www.legislation.gov.uk/ukpga/2006/35/section/2 http://www.legislation.gov.uk/ukpga/2006/35/section/2 It looks like all the criteria for it to be fraud are met. However, it also looks like legislation in the UK disallows (and renders void) concerted practices which may affect trade within the United Kingdom, and have as their effect the distortion of competition within the United Kingdom, applying, in particular to practices which apply dissimilar conditions to equivalent transactions with other trading parties, thereby placing them at a competitive disadvantage. See http://www.legislation.gov.uk/ukpga/1998/41/section/2 http://www.legislation.gov.uk/ukpga/1998/41/section/2 A concerted practice of charging the owners of well-known brands of smartphones less than the owners of less-known brands for an equivalent transaction would have the effect of lessening competition, because people might eschew a lesser known smartphone (increasing the barriers of entry to the smartphone market in the UK). So there appears to be a good defence that price discrimination practices like this are illegal and void, and therefore circumventing it is not fraudulent. Of course, out of an abundance of caution, I don't think it would be wise to volunteer to be a test case for this.
- Jach 15y agoIf anything this just seems like a violation of Terms of Service, the harshest punishment that should be allowed is them denying him internet.
- patio11 15y agoWord to the wise: "circumventing the access restriction was easy to do, Your Honor, so I assumed it was OK" is not something you ever want to have to say. There exist wifi systems where setting a cookie "paid=1" will save you $15. You might think there are no legal consequences for "writing a text file on your own computer." I strongly suggest not testing that.
- wladimir 15y agoI don't think those cases are even comparable. Lying that you paid (through whatever means) is different from using a different user agent, which has no (direct, expected) relation to money. But if you think changing the user agent is somehow wrong, you could also go all the way of emulating the iPad browser on your laptop, and use that to sign in for the service.
- bryanlarsen 15y agoYou'd still have trouble explaining that to a judge. The hotel has a reasonable expectation that if the traffic says it is coming from an iPad, it's actually coming from an iPad, and you don't have any non-infringing excuses to be using an iPad browser on your laptop.
- joelhaasnoot 15y agoiPad simulator as an iOS/Web developer?
- Joeri 15y agoIf they advertised the plan as an ipad plan, there would be a point. But if the plan is advertised as all-purpose, but only offered to certain user agents, i don't think there's any legal issue.
- cheald 15y ago"I was testing our company's iPad website last week, and forgot to switch it back to the native user agent."
- 15y ago
- CWIZO 15y agoI'm looking forward to the day when I stay in a 100$/night hotel and I don't have to pay for my fricking internet. Every motel/hostel has it for free as it should. To me charging for internet (in hotels/resturatns) in 2012 is the same as charging for using the shower or lights.
- rmc 15y agoIt's always interesting how the really cheap accomodation (hostels etc.) have free internet, but the expensive accomodation have expensive internet. It's a great example of price being based on what the market can bear. People who stay in cheap hostels will just go without internet, or stay at another hostel that has free internet. People who stay in fancy hotels don't care about €15 (or the company is paying)
- luca-giovanni 15y agoSadly you are so right! Internet nowadays is a utility though so I do think it is rude making people pay for it.
- sanswork 15y agoEvery motel/hostel that I've been to with free internet has ended up with internet so slow that its unusable. I'm happy to pay for it to be able to access at faster than dialup speeds. As for why they charge it's because they can. Their target markets are already paying a premium for a room so a small extra charge for internet isn't that much of a deal. People looking for the savings of a hostel are just as likely to go to Starbucks/McDonalds for free internet.
- Tichy 15y agowouldn't it be cheaper to get a mobile router and a mobile flatrate for the country? Where I live 15€ would buy 1gb for a month. I have wondered about easily obtaining prepaid cards for travel, might be a business opportunity if there is no good solution yet?
- mvip 15y agoThere are a few international sim-card providers, but I don't think any of them are really good. It is a business opportunity for sure, but it's also somewhat complex. I usually try to get my hands on a local card when I travel, but the rates (and availability) varies significantly between countries.
- cstross 15y agoIf you know of any source of such SIM cards, please post it here! I've seen plenty of international-travel SIM cards that give cheap[er] texts and voice calls, but none that include any data. And trying to set up a pre-pay data SIM from a foreign ISP in a language you don't speak/read is a nightmare ...
- rwmj 15y agoI found this wiki(a) site useful: http://prepaidwithdata.wikia.com/wiki/Prepaid_SIM_with_data http://prepaidwithdata.wikia.com/wiki/Prepaid_SIM_with_data
- asmithmd1 15y agoI have used this guy for pre-paid SIM cards: http://mrsimcard.com/ http://mrsimcard.com/ He is basically a one man shop owner but is very knowledgable and reliable.
- dfc 15y agoUgh, a bit.ly link? Can someone change the URL to point to the actual address of the page? http://viktorpetersson.com/2011/09/25/how-to-get-50-discount-on-swisscoms-hotspot-and-possibly-also-others/ http://viktorpetersson.com/2011/09/25/how-to-get-50-discount... I love that people get up in arms about the change to google's privacy policy but have no trouble funneling traffic through bit.ly and other link shorteners...
- luca-giovanni 15y agoI guess it gives the original sharer some feedback on the link otherwise they would never really know what interest it got? Looking at traffic I think the link was picked up off Twitter originally hence the URL shortener too.
- dfc 15y agoThe original sharer is not sigma cloud (the bitly link creator).[1] Ostensibly the OP actually visited the site before posting it on HN so its not like the OP was only aware of the shortened link. What's more important a consistent approach to privacy or "knowing how much interest someone's HN link received"? [1] Conspiracy theory: jcloud is an astro-turfing account for sigma cloud. The jcloud account was created 377 days ago the same day a sigma cloud story was posted. Jcloud's first post was on the sigmacloud story and was complimentary of sigma cloud: "Just discovered these guys. Nice interface actually. Investigating a bit more but so far so good." Of the three stories jcloud posted two were shortened with sg.cd and the third was a sigma cloud press release.
- luca-giovanni 15y agoMy point was that the first hit on the article is on Twitter and was from CloudSigma. So I'm guessing the URL was copy pasted from there. Looking at jclouds account, submissions do generally come from CloudSigma tweets but it seems to relate generally to wider things not that company. The residual value of a URL shortening isn't clear to do to the lengths you suggest. Your post gives more advertising than the submissions thus far ;-) The three submissions made by jclouds-fan seem to be of a high quality. The first relating to the same blog as this latest one so looks like a user with a narrow interest base!
- drostie 15y agoI was staying with my brothers at a hotel in Amsterdam and I had brought my laptop; the hotel offered free unencrypted WiFi for guests. Since it's in a big city, as you might imagine, you don't want the neighbors stealing all of your bandwidth, so even though it was free for us, there was a sign-in page -- you had to go downstairs and request that the desk official give you a token, then use that token to register with the system. So I thought that, since I had permission to access this network anyway, I would break in -- just to see if I could. And I'd tell them about my results the next morning as we turned in our keys and headed off. Actually since there wasn't any encryption there isn't much to say after that -- it was obvious that their system wasn't too sophisticated, so I just guessed "they check MAC addresses, don't they?" Using the airotools-ng package for Ubuntu, I set my wireless card into "monitor mode", which (I'm not an expert) I guess is a fancy way of saying "it stopped ignoring everything it saw flying through the air in my hotel room." Normally your computer treats all of these other signals as noise relative to its own goal of connecting to the Internet -- but it's absolutely trivial to start listening to it. With the tool airodump-ng, I was able to see all of the routers at my hotel and MAC addresses of real users connecting to those routers. So I put one of those into my "Connect to the Internet" dialog box under "Cloned MAC address," and hey look, I just saved the desk clerk some time. I mentioned that I'd done it the next day to the desk clerk as I checked out -- that any competent neighbor could steal their wireless access. I'll never forget his response: "yes, but they're all incompetent." A similar experience: when I first came to live at my present household, I knew that we had shared WiFi but I didn't know the password -- and the guy who did know had just stepped into the shower. But it was using "WEP", a very old encryption policy which is vulnerable whenever you are transmitting data. So I fired up these same tools, found out that I was lucky -- he'd left a download running when he stepped into the shower or so -- and I captured a couple thousand data transactions. I didn't have to wait for him to finish showering before I had broken into my own Internet. I'm always surprised by this sort of thing. The other day I had accidentally clobbered my sudo permission when reconfiguring Wireshark (something which can also listen to Internet traffic) to be more secure, and suddenly had no more root permissions. In about half an hour I had downloaded a live CD and burned it and broken into my own box with chroot magic to usurp root permissions to re-add myself to that group. (I have an encrypted disk, and I couldn't have done this without being able to decrypt it. However, most people that I know don't use disk encryption, so the point still stands.) The lesson to take away: If some half-geek amateur like me can do these things, the professional inbreakers must have absolutely terrifying skills.
- donall 15y agoI had a similar experience on a US Airways flight last December. The Kindle Fire browser allows the user to choose whether to optimise for mobile or desktop, and this resulted in two different prices. In relation to the legal questions raised elsewhere on this thread, I'm guessing that it's a non-issue when it's a built-in feature of the device. I think the argument could be logically extended to using plug-ins that switch user agent strings?
- eli 15y agoI wonder if that was segmenting potential customers or if it was an A/B test
- pornel 15y agoI'd suggest using Opera with Turbo proxy instead — it'll compress all textual content and re-encodes images as WebP. That's likely to give you bigger savings than just a UA switch. And if you can't trust Norwegian folk with your data, then you can roll your own "Turbo" with Ziproxy or at least SOCKS proxy over gzipped connection.
- rb2k_ 15y agoWhen I feel particularly nerdy, I try to go the DNS2TCP[0] or iodine[1] route. DNS is pretty much always open in those networks. [0] http://hsc.fr/ressources/outils/dns2tcp/index.html.en http://hsc.fr/ressources/outils/dns2tcp/index.html.en [1] http://code.kryo.se/iodine/ http://code.kryo.se/iodine/
- Drbble 15y agoHow does that work, when DNS always resolves to the paywall IP?
- icebraining 15y agoNot always. The three captive portals I've tried resolved DNS just fine, but then redirected any HTTP requests to their web server instead.
- rb2k_ 15y agoI've never encountered one that didn't have working DNS resolution
- wazoox 15y agoI'm using regularly the same trick to use free tethering with my phone. As I didn't buy some incredibly expensive option that explicitly allows it, simply declaring my firefox as a mobile browser allow to bypass the artificial limitation. I certainly don't abuse it; simply from time to time you need some internet access (to check an email, to download some piece of software, to google for a technical problem) and I wouldn't pay 39 euros/month for a 3G "key" that I'd use maybe once a month, no thanks.
- apaprocki 15y agoAirlines which offer wi-fi connections usually offer a cheaper rate when signing in with a phone-based browser user-agent as well.
- jiggy2011 15y agoI'm surprised there's still much money in selling wifi internet access. People who want to use their internet on the move are very likely to have a smartphone or at least a dongle and 3G is usually fast enough. Here in the UK the train services used to provide free wifi to travelers but recently they decided to charge for it and give the option of a free trial. On my last journey I tried the free trial and found that it was just as slow as it had always been but was now £5 an hour. I would have been seriously disappointed if I had paid for that service. Luckily I could just use my mobile phone tethering and get nice fast access. Surely a better model would be to provide access for free but use some DNS redirection of the popular ad services to redirect the ads to ones of your choice and reap the benefits of those clicks. I also let a lady in the carriage use my connection for a few minutes to check her emails so it's not like you necessarily need your own connection either.