51 ms·
Hotel Wi-Fi blocking: Marriott is bad
- lylebarrere 12y agoI wish the FCC could subpoena financial records and to see the price consumers pay for Wi-Fi and the total revenue Wi-Fi sales made for Marriott. I would be willing to bet those numbers would make it harder for Marriott to argue this is anything other than an attempt to gouge captive consumers.
- dagw 12y agoI know many hotel chains have outsourced their wifi handling to third parties, who often gouge the hotels at least as badly as the hotels gouge the customers. So while the Marriott no doubt makes a lot of revenue from wifi I wouldn't be surprised if they make basically no profit.
- TeMPOraL 12y agoThen again, those numbers would help in going after those third parties as well.
- ubernostrum 12y agoWorth pointing out, again, that this is not about charges for in-room wifi, but rather for wifi in larger conference spaces in the hotel. Which can easily run into thousands of dollars for a weekend, so if an event wants to do, say, live streaming, they do their best to make it impossible for the event to bring its own hotspot and connection.
- lylebarrere 12y agoDo you have a source for that? I read the actual FCC announcement from FCC.gov and it says: "Marriott employees had used containment features of a Wi-Fi monitoring system at the Gaylord Opryland to prevent individuals from connecting to the Internet via their own personal Wi-Fi networks, while at the same time charging consumers, small businesses and exhibitors as much as $1,000 per device to access Marriott's Wi-Fi network." In your room or in the conference center you should be able to use your own Wi-Fi without interference. Source: http://www.fcc.gov/document/marriott-pay-600k-resolve-wifi-blocking-investigation http://www.fcc.gov/document/marriott-pay-600k-resolve-wifi-b...
- op00to 12y agoMarriott's just kicked off a campaign to give free Wi-Fi access to all Marriott Rewards members. Not sayin' it's not a gouge, but there you go.
- ghaff 12y agoMarriott Rewards Gold status has already been getting free WiFi for a while.
- jzwinck 12y agoIn Asia there are tons of places with free Wi-Fi, even where there the tap water is not potable. At a bus stop in the middle of nowhere in South Korea. At a roadside cafe in Malaysia. At a cheaper-than-cheap hotel in Indonesia. Even some airports! There are no "portals," no "user agreements," just beautiful open Wi-Fi scattered all over the place. It's hard to imagine spending even $5 at any place that wouldn't offer you internet access, much less the $150+ that Marriott charges its "guests." Sooner or later all this unnecessary friction (sorry, "added value") is bound to catch up.
- Mithaldu 12y agoThis works because the free wifi makes the people want to stay there and spend money there, so in effect everybody pays for the wifi. In high-end hotels the relationship is entirely reversed and people stay there because they want to stay there, and the wifi is used to extract more money because people actually need it while staying there. It also needs to be kept in mind that all these asian small places have DIY wifi, while hotels got into the wifi game way too early and locked themselves into expensive, underdelivering and long-term contracts with 3rd party companies that do the wifi for them.
- rb2k_ 12y agoI wonder how much problems companies can get into when providing open wifi in the respective countries. I assume nothing ever happens in a lot of asian countries when somebody torrents their favourite new movie/tv show from one of these connections while I imagine US ISPs send nasty "stop it" letters every now and then. (even if the hotel might not be liable, that probably doesn't stop Comcast from sending them)
- TeMPOraL 12y ago> while hotels got into the wifi game way too early and locked themselves into expensive, underdelivering and long-term contracts with 3rd party companies that do the wifi for them. It's basically one group of scoundrels that got cheated by another group of scoundrels. I wonder though, how hard would it be for hotels to renegotiate those contracts - or drop them and eat the fee - if they actually cared?
- xerophyte12932 12y agoInterestingly enough, my local Marriott has this quote posted on the wall: "Wifi should be like air: Free and Everywhere" And they have a totally open wifi network. I live in Karachi, Pakistan.
- topbanana 12y agoI'm not at all comfortable with the Economist using such facile titles
- scrollaway 12y agoHow is it relevant "how comfortable" you feel with their titles?
- Burritamos 12y agoConsidering this is a comment thread about that article, I would presume that makes it relevant.
- smackfu 12y agoDifferent sections have different styles. This one is just a bit more informal.
- saryant 12y agoThis comes from one of their blogs which have a less formal style than their print publication.
- TorKlingberg 12y agoHow is Marriott blocking WiFi routers, technically? Is it actual radio jamming or something else?
- michaelx386 12y agoFound some details[0] on how they're doing this: > Marriott operates a Wi-Fi monitoring system manufactured by a third party that was installed at the Gaylord Opryland. Among other features, the system includes a containment capability that, when activated, will cause the sending of de-authentication packets to Wi-Fi Internet access points that are not part of Marriott’s Wi-Fi system or authorized by Marriott and that Marriott has classified as “rogue.” [0] https://apps.fcc.gov/edocs_public/attachmatch/DA-14-1444A1.txt https://apps.fcc.gov/edocs_public/attachmatch/DA-14-1444A1.t...
- sargun 12y agoMy guess, and my understanding is that it probably uses the same tech that most enterprise WiFi networks use. They probably send fake deauth packets in order to disconnect stations. A lot of enterprise wireless solutions also do this for the following: (1) Removing security risks: You really don't want people running their own WiFi access point plugged into the corporate network. (2) Removing interference: In order to remove interfering APs / stations from the network, it deauths them in order to disconnect them. You can learn more about the mechanisms used here: https://en.wikipedia.org/wiki/Wireless_intrusion_prevention_system https://en.wikipedia.org/wiki/Wireless_intrusion_prevention_...
- mschuster91 12y agoHeh, with the government using stuff like IMSI catchers, I would not be surprised at all if using a faked AP is a common tool in the box of the 3-letter agencies. I'm fine with Marriott using deauth jamming against rogue APs with their SSID (or a similar impersonating one, e.g. "Mariott Wifi" instead of "Marriott Wifi"), or operating on their specific wifi channel (thus downgrading the experience of the customers), but they absolutely have to leave APs alone which have a different channel/ssid.
- cesarb 12y ago> I'm fine with Marriott using deauth jamming against [...] or operating on their specific wifi channel While they might have a justification that a "Mariott Wifi" ESSID on a Mariott hotel is theirs, how can they say a specific wifi channel is "theirs"? Wifi runs in unlicensed bands, any device which meets certain technical requirements is allowed on any channel in these bands, no matter who the device owner is. The 802.11 protocol is designed to share wireless channels between APs with different owners (while it also assumes that APs with the same ESSID have the same owner). And what would be "their" channel? A well-designed wireless network for a large enough area will use several channels. Unless they have a single AP (unlikely) or their network is not well designed, they are probably using all the non-overlapping channels in the 2.4 GHz band and many channels in the 5 GHz band, including all the non-DFS ones.
- AlyssaRowan 12y agoNo, the real hotel access points, including at Marriott, are part of their attack strategy. They get hacked, sometimes via physical means, and commandeered to launch high-grade targeted malware. The South Korean government has done that quite regularly, for one (known as DarkHotel), and I do believe GCHQ does it over here from time to time. Several others too, I expect. Intelligence agencies just like hotels, I guess, between the visitors of diplomatic, political and economic interest, the public access, potentially lowered guard, and things left unattended in hotel rooms locked by surprisingly forgeable master keys?
- briandear 12y agoAs a platinum member of Marriot and Hyatt, it's clear where I'll be staying on my next trip.
- 72deluxe 12y agoCisco sell a Wireless LAN controller, which can send disconnect packets to "rogue" APs that get set up, rendering them useless. This is particularly important at events where the airspace is severely cramped, such as big arena events, racing, horse racing etc. where the myriad of APs to provide coverage of free wifi to pundits would have to compete with these other APs. In a severely crammed airspace, this would help to encourage the other AP providers to turn their boxes off. And getting a mobile telephone call in such events is even trickier, given that 50,000 people are in one space and the masts to serve them are oversubscribed. If they all suddenly want to place bets or browse the web, that's incredibly difficult to provide on the mast, so providers will set up additional masts for big events (like the big horse-racing events here in the UK). That's why they provide free wifi too, and having other APs set up and attempting to provide wifi over the airspace doesn't really help. I wonder if Marriott hotels have the same approach in order to provide better wifi coverage? I have been in numerous hotels where the wifi coverage was great if you're sat in the bar but abysmal if you're down the other end of the building (where the hotels here in the UK are large old buildings with thick walls, very tricky for wifi). Irritating if you're trying to use your phone to provide wifi to your laptop in order SSH to your own box at home or to get content via your mobile (which might be faster than their Internet access in some cases). I suppose you could just use a Bluetooth PAN instead (and it uses less power!)
- busterarm 12y agoI recently worked for an ISP providing service to some Marriott resorts. This is my opinion and in no way representing either company, but this is exactly what Marriott is trying to do. Marriott is not using any sort of wifi jammer like the author is suggesting; in fact such devices would block their own wifi signal. The most typical problems with wifi in resorts comes down to construction; most of these were built years before wifi was a consideration and are constructed in a way such that even with commercial APs you will get a very poor signal even with the APs in each unit. There's one such property I know of where guests only get wifi in the one room with the AP and out on their balcony and no where else in the hotel besides the pool & lobby. Also they often use authentication pages that mean you can't get on with a device without a browser...but when you have 200 guests sharing a 100Mbps connection, you don't want someone hooking their Xbox or AppleTV anyway.
- matthewmacleod 12y agoObviously this is true, and hotels providing wifi services want to charge for them rather than allowing users to use their own (much cheaper) systems. No question. That aside, what is the solution to rogue access points in a public space? We all know that it's pretty easy to set up camp in a public space, broadcasting a friendly-looking but dangerous wifi network. Let's says you've got someone sitting in the Marriott lobby, creating the "Marriott Free Wifi" network. A bunch of people will connect to it, and some information will leak. Is there any reasonable way to deal with this issue? Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there.
- epochwolf 12y agoYou call the police and they arrest the person. WiFi is short ranged. Not every problem needs a technical solution.
- icebraining 12y agoYou call the police and they arrest the person. WiFi is short ranged. Yes, but it doesn't need constant attention. A small router can be dropped anywhere and route the information to the attacker long after (s)he's gone. That said, finding the AP and disabling it is better than randomly throwing deauth packets.
- nilved 12y agoIt could use a solution that isn't racist or anything tho
- freehunter 12y agoYou can't just arrest someone for having a wifi hotspot. You'd have to prove that they're doing something illegal with it, which is much harder to do.
- macns 12y ago> Obviously we have to assume that public wifi is compromised in any case and require transport-layer security, but I can certainly see there's still a gaping security hole there. Agreed on the security hole on public wifi, though it's probably about less "sensitive" data as HTTPS is becoming more of a standard, especially after the Snowden revelations. Most services/apps speak HTTPS nowdays and a lot more will (hopefully) follow: https://letsencrypt.org/ https://letsencrypt.org/ > Is there any reasonable way to deal with this issue? So, yes with HTTPS
- deleted 12y ago[deleted]
- teh_klev 12y agoSeriously? The term "self entitlement" is often bandied around here with no real justification. But this comment truly exemplifies the phrase. Sure, I too had to click a couple of times to read this free article, but big deal, it could've been hidden behind a paywall. Feeling so outraged as to blame the publisher for a cookie compliance dialogue (in Europe you have no choice; yes the implementation may be sucky, but they're making sure they get the message across) and an invite to subscribe isn't exactly the end of the world, or the justification to post their content on a pastebin.
- leephillips 12y agoCouldn't the "rougue" operator turn the tables and use the same technique to shut down the official WiFi?
- blueskin_ 12y agoYes, although chances are you'd need quite a lot of hardware depending on the scale of their network. Doing so would also be illegal, of course.
- leephillips 12y agoIf the consensus in the comments here is correct, that Marriott's technique is legal because it doesn't create radio interference, then what law is the rogue operator breaking when using the same technique?
- ilitirit 12y agoA guy know wants to block cell phone signals at his business so that customers are forced to use his phones, at a premium. I'm sure there's a law against this though.
- sspiff 12y agoWhat if you just make the walls thick enough to block signals? Or put things that block radio signals in them? I can't imagine this would be illegal. Jamming signals may be hard to do legally, but keeping them out is probably impossible to forbid by law.
- rmc 12y agoKeeping signals out is the definition of jamming.
- logfromblammo 12y agoIncorrect. Jamming is denial of service by increasing the noise. Blocking is denial of service by decreasing the signal. If the hotel puts a grounded Faraday cage around your room, that's blocking. If it transmits 1000 watts of static on the 2.4 GHz band, that's jamming. The former is legal, and the latter is not.
- sspiff 12y agoThanks for making my point a 1000% more clear.
- taddeimania 12y agobecause "making walls thicker" is probably the most expensive way you can implement a blocking mechanism. Also whoever you lease your office building from may frown upon you going around making their walls all thick.