12 ms·
How AT&T Recognizes Unauthorized Tethering from Jailbroken iPhones
- pieter 15y agoI'd like to see a proper source of this (other than Android Police / iPhone Download Blog). I have used MyWi without having any special settings for tethering (my provider doesn't supply those), and it worked just fine; it would be a bit silly to go through the trouble of setting up a hotspot and making sure you're actively routing the data to the 'wrong' APN. (Note that iPhone Download Blog is the one calling MyWi by name) Also, if this is the case, wouldn't it be easier for AT&T to just disable the tethering APN for you if you don't have the tethering option? That would seem to be much more effective.
- delinka 15y agoEvery good dealer knows that you don't cut off your customers' supply. You "work with" them, you send someone to break their legs for not paying, but you never cut them off. Seriously, wouldn't it always have been easier just to cut customers off to prevent things like astronomical texting overages? That would interfere with that beautiful revenue stream.
- gcb 15y agoI think everyone here is only worried with the breaking of legs anyway.
- Irfaan 15y agoJust to add another data point - during a recent move, I was temporarily using iPhone + MyWi as my primary internet connection. Nothing particularly egregious - just basic web browsing and SFTP. This lasted for about a week. That was at least 1 billing cycle ago, and I've yet to hear a peep from AT&T. My suspicion is AT&T is (currently) just looking for users with excessive data usage.
- dude_abides 15y agoA couple of years back, federal regulators (thanks to the efforts of EFF) declared that jailbreaking an IPhone is not illegal. Since then, Apple has stopped threatening users with jailbroken IPhones, and also, finding and patching new vulnerabilities that allow jailbreaking has become a moot point. In the same vein, has there ever been a verdict on the legality of unofficial (MyWi-like) tethering?
- eli 15y agoJailbreaking was given a temporary exemption from the DMCA. That doesn't mean it's necessarily legal, nor does it mean that it doesn't violate the terms of the contract with your carrier.
- smackfu 15y agoDoesn't that explicitly mean it's legal? At least for the time of the exemption.
- eli 15y agoNo, it just means that it doesn't violate one part of one law: the anticircumvention provision of the DMCA. And the exemption only applies if "circumvention is accomplished for the sole purpose of enabling interoperability of such [software] applications, when they have been lawfully obtained..." One could argue that skirting carrier rules on tethering is different from enabling interoperability. Further, it has no bearing on any contract you may have with your carrier.
- jhc 15y agoThere's a huge difference between jailbreaking an iPhone, which the EFF established doesn't (necessarily) violate the DMCA, and breaking your contract by using services from AT&T that you're not paying for. The first means using something you bought and paid for in a way the manufacturer doesn't want you to. The second means using a service that the provider charges for, but you're not paying for. The law is never going to protect the second one. To start with, tethering without paying for it is definitely a contract violation, and AT&T could cut off your service, retroactively charge you for it, or do whatever else (within reason) the contract provides for. There is little or no legal ambiguity about this. You are getting a service for free from AT&T that other people are charged for, so you're breaking your deal with them and owe them damages. The (slightly) more interesting legal question might be whether AT&T could ask a prosecutor to bring criminal charges. My uninformed guess is they could, based on something like "theft of services." If I charged $20 a month for you to come fill up a one-gallon bucket any time you wanted from my well, and instead of a bucket you filled up a tanker truck, it would be theft plain and simple, because you'd knowingly be taking something from me without my permission. (Actually I hate physical metaphors for computer stuff, because they usually distract more than help if you're talking with reasonably technical people. So let's not get sidetracked with questions like, "what if I filled up the tanker truck _with the bucket?_" [Unless you happen to enjoy pointless arguments as much as I do, in which case go for it.] The point is that the contract permits you to access AT&T's network in certain ways for a certain price, and you're accessing it in different ways without paying the different price, and the law's not too likely to be on your side for that one.) This is all probably hypothetical, though. AT&T wouldn't bother to bring an expensive lawsuit or risk negative publicity from criminal charges, when they can (perfectly legitimately) charge you extra under the terms of your contract and dare you to fight it. IAAL, in case that changes your assessment of a random person's opinions on the internet.
- Osiris 15y agoDoes anyone know if tethering can be detected on Android phones? I'm curious what other provides do to try to detect tethering on Android phones.
- CWuestefeld 15y agoI have a theory that Verizon, at least, has started installing watchdogs that prevent covert tethering. My Droid X has an odd property such that connecting it via USB (in USB mass storage mode) causes BSoD, so I've been looking for a way to transfer data without a connection. The most promising was to run an FTP server on the phone (through a high port, since the lower ones like 21 are protected). This works for me intermittently, and is super-fast when it does, but more often than not, I'm told that it can't connect. The exact same behavior occurs with several different FTP server apps, as well as an HTTP server. It's not due to DHCP shuffling my IP address, and it may even work briefly for a minute before the connection breaks and can't be re-established. On the other hand, going in the other direction works OK, either through FTP or through an SMB share to my desktop. Unfortunately, this method is painfully slow (I don't know why). My solution, then, is to do any transfer via my notebook computer, to which the phone can connect via USB with no trouble. Anyway, the only explanation I can think of for the mostly-not-working FTP server is that there is a watchdog that's looking for the phone to act as a server, and when it detects a port sitting there, it closes it. That's just my theory, but I can't think of anything else to explain the behavior.
- burgerbrain 15y agoI would first suspect some sort of powersaving feature. Try continuously using the phones interface locally (reloading webpages or something of the sort), and I bet you'll notice that your FTP server is always available from other computers. I say this because I've noticed what seems to be similar behaviour with servers running on my hacked kindle3 (wifi only). They stop responding until you generate traffic from the kindle, which kicks the wifi card up from some sort of lower power level, or something.
- kevko 15y agoI wrote a non-root tethering app, so I might have a bit of tunnel vision. First, any good tethering app should be immune to a simple TTL check. The most likely culprits are instead application traffic patterns. The following immediately come to mind: - Browser user agents - Automatic status checks under both OS X and Windows - Application behavior: * Netflix and Hulu on Android isn't supposed to happen. * Browsers like Chrome are very aggressive and can open dozens of simultaneous TCP connections. DNS prefetching can also generate dozens of requests over UDP in a very short time window.
- conradev 15y agoI heard they checked for varying TTL values?
- kevko 15y agoTTLs should not affect PdaNet if it is written like any of the other non-root tethering apps. Mac and Windows update pings are probably a good indicator, however.
- runjake 15y agoLast week at a conference, I spoke briefly to an engineer from one of the large two US telcos on this issue. He indicated they utilized a variety of methods, including utilized fingerprinting of the IP/TCP headers, and protocol analysis to help identify traffic. Specifically, I heard TTL mentioned, as well. He might be a user here. There are more knowledgeable people than you working on the issue. That said, I haven't gotten an evil text from using PDAnet, yet. Then again, I don't tether that much and when I do it's not a lot of data.
- Niten 15y agoIf you want to be safe, run a VPN on the phone and route all your traffic, tethered or not, through that.
- ajg1977 15y agoNote: TetherMe (native tethering on jailbroken iPhones) sends all tethered data through the same APN as mobile data by default so users won't fall foul of the APN detection method mentioned here. Of course that wouldn't stop AT&T & Co sniffing browser strings of high data users, but that's a more complicated system to implement.
- eli 15y agoOr just assume that high data users are all tethering.
- phonehome 15y agoThey'll find other ways i.e. looking at the UserAgent in any unsecured HTTP request would signal tethering
- xorglorb 15y agoNot really. You could always write a browser app for iOS or Android that uses Firefox or Chrome's user agent to have servers return the full desktop version.
- phonehome 15y agoIf I was AT&T looking for unauthorized tethering folk, I'd focus on the people that are using > 2 GB a month + other various heuristics. Something deff smells funny if someone is using substantial bandwidth and much of the traffic is with a UserAgent like Firefox or Chrome
- RyanKearney 15y agoAh yes because it's impossible to spoof your user agent string be it with a 3rd party web browser on the iPhone or your desktop browser to match the iOS one.
- phonehome 15y agosure but many websites use the useragent to alter the presentation for the device...this would diminish the experience for the lay user when tethering
- gcb 15y agoanyone actually knows what the old unlimited contract says about this?
- amorphid 15y agoI tested my Verizon HTC Thunderbolt 4G's download speeds today. I got over 7 megabits per second down. It also got 4 megabits up!