12 ms·
A story about bypassing air Canada's in-flight network restrictions
- 4rt 1y agotldr; the wifi's access restrictions still allowed DNS so they set up a vpn on the dns port
- technothrasher 1y agoI remember doing this about twenty years ago when many hotels blocked the internet behind a paywall but were naive in their approaches. I also remember trying this at a hotel in Tokyo about ten years ago and instantly finding my MAC address blacklisted. Their networking folks were clearly more sophisticated.
- roygbiv2 1y agoIodine has done this for many years. https://github.com/yarrick/iodine https://github.com/yarrick/iodine
- BehindTheMath 1y agoI haven't used iodine, but this seems simpler. Iodine wraps requests with actual DNS requests. In this case that wasn't needed, because port 53 wasn't filtered at all. So all they needed was a simple proxy on port 53.
- krautsauer 1y agoiodine automatically checks several modes a "simple" proxy on port 53 being one of them. If you're trying to sneak traffic through this kind of block, it is really the first tool to try.
- kangs 1y agoDan Kaminski popularized this in 2007-8 or so. Not that it didn't exist here and there, but he made the perhaps first public version of a dns tunnel (ozyman). he inspired iodine and others and was a fairly well known guy. Dan passed away in 2021, rip. if you search for it its hard to find. his blog is down (hea dead...), and many companies and people talked about it on his behalf to drive traffic (hi duo sec..), so you can see the internet forget, rediscover, and rewrite some history even in a few years.
- DaSHacka 1y agoYeah, I was gonna say I've used Iodine to get free Wi-Fi on Delta flights for years at this point.
- roygbiv2 1y agoDoes it work well? I've never actually got it to work consistently. Either it works for a very brief period or just not at all.
- DaSHacka 1y agoIt worked pretty consistently, but was extremely slow, bordering on unusable. I didn't really end up using it and just read a book instead, but in theory it does work.
- huflungdung 1y ago[dead]
- traceroute66 1y ago> We affirm our strict adherence to all relevant regulations and service terms throughout this project. Except if you bypassed payment and used the service in a manner that was not intended, most likely you were by definition not undertaking "strict adherance" to service terms ?
- VladVladikoff 1y agoYeah I am a bit confused about posts like this. It’s bragging about breaking the law. There was a particularly bad one a few months ago where a kid had hacked Monster’s employee training site, and was sharing all this internal media in the post. I don’t understand how they don’t end up getting in some seriously annoying trouble with law enforcement. Well I looked it up just now and the post was deleted, I guess maybe he did get in trouble. https://news.ycombinator.com/item?id=44997145 https://news.ycombinator.com/item?id=44997145
- CaptainOfCoit 1y agoCould also just be lack of knowledge. Weren't we all a bit more risky and playful with other people's websites when we were kids and the internet was still accessed via modems? Remember talking about that with both other kids and adults without getting in trouble, but it was also decades ago. Once I saw others getting in real big trouble (like prison), then I kind of tried to find more beneficial ways of learning programming and computers.
- traceroute66 1y ago> Could also just be lack of knowledge. Huh ? DNS tunneling is not exaclty something you do "by accident". And if the person doing it on the flight "did not know" (which, given the text of the blog, I doubt) , then you can bet your botom dollar that the "roommate" that was summoned for remote assistance knew very well what was going on.
- CaptainOfCoit 1y ago
- andy99 1y ago> The only downside was that although we broke through the network restrictions and could access any website, the plane’s bandwidth was extremely limited, making web browsing quite painful. Unfortunately this is also the downside of paying. Many times I have paid for internet, only to find it unusably bad. To be fair, I just flew a transcontinental flight on Air Canada the other day and the wifi was fine.
- CrossVR 1y agoThis is likely another layer of security that they didn't break through: To prevent chat apps from consuming lots of bandwidth typically your connection is severely bandwidth restricted until you pay. If they didn't then someone could simply stream movies from their chat apps.
- ms7m 1y agoI don't think so, compared to transcontinental, which lately (before Starlink) has been using the cell towers on the ground + satellite backhaul -- even paying would probably still result in a garbage experience.
- armada651 1y agoThe point is that if the connection does have more bandwidth available they wouldn't get that extra bandwidth without paying.
- sheepscreek 1y agoI’ve been the unfortunate one who paid and endured the slow-barely-usable/mostly unusable speeds. However, that was before the Starlink era. So if you’re gonna pay for WiFi, it’s worth checking if the flight is equipped with Starlink.
- mjr00 1y agoYeah, I just flew WestJet from Canada to Honolulu and was amazed; full 1080p YouTube with no hiccups and I was able to play some (non-latency sensitive) online games, all over the Pacific. This was fully intentional; there wasn't any back-of-the-seat iPad for watching movies or anything, they straight up tell you to use your own device and watch Netflix. I did some research after and found a lot of airlines in NA are going to be rolling out satellite internet in the next year or two. For some reason, being fully connected at 50mbps+ on a plane seems more futuristic sci-fi to me than everything AI.
- ogurechny 1y agoLimiting availability of third party services based on local service provider fee can only be done 100% reliably on a service side through an agreement with that provider, i.e. WhatsApp needs to disable certain functions to users coming from certain dedicated links or IP ranges, or even based on live user status metadata. There's an obvious size mismatch, and lack of incentive to implement compartmentalisation only needed for some other company. It also creates enormous shared responsibility and potential circular finger pointing clown shows, all for relatively tiny number of affected paying users. Therefore, it is either done with least amount of work that is “good enough”, and can be done on a cheapest router (rate limit to the absolute minimum, ban connections to ports 80 and 443, maybe cut the traffic to most stable IP ranges of biggest services, and regular person is going to state that “nothing else works”), or trough very extensive commercial DPI with lots of guessing and ad-hoc rules (if this feature is important for the income, and many will try to game the system). So it's either going to be as simple as in this example, or you'll compete with the global army of detection rule authors. Though I do like the wink-wink, nudge-nudge choice of proxy software.
- toast0 1y agoFWIW, WhatsApp does (or did) support special price networking. I used to be the engineering side of that. But the supported offerrings were for special priced everything (text+mms+voip) or just text+mms if real time voice and video was not to be special priced. Text only was not a supported offering while I was there. And you needed to be a mobile carrier to get the information about IP ranges (the IP ranges were public but not directly linked early on, but got limited later). That said, many networks did these sorts of things without communicating with WhatsApp. Even without knowing IP ranges. WA traffic is easy to spot. Chat has a destinctive protocol that's neither http, nor https; mms is https with obvious hostnames in SNI; voip looks like voip. You might be able to trick in-air wifi by looking like WA chat, but I've never been interested enough to check while on a plane. I'd rather use the time to watch awful movies on a tiny screen with terrible audio conditions.
- ajd555 1y agoIf a ping to a specific IP times out, I wouldn't say the IP is blocked. It could be that ICMP specifically is blocked, following some network rules on the firewall. This is pretty common in entreprise networks to not allow endpoint discovery. I could be missing something and happy to be corrected here, but I was surprised to read that.
- VladVladikoff 1y agoYeah, ICMP tunnelling is also a common bypass method for captive networks, so simply blocking all ICMP seems logical.
- EvanAnderson 1y agoEvery time I've had to fight with path MTU discovery not working I've cursed the people who block all ICMP, though. If ICMP echo / echo-reply is the problem just block that. At the very least, allow destination unreachable / fragmentation needed thru (type 3, code 4).
- ogurechny 1y agoYes, you need to test the exact protocol you want to use. This means tcping/curl, TLS with proper certificates and SNI domains, etc. However, just as you make sure that the power supply actually supplies power before dismantling something that refuses to work down to the last washer, repairing network problems should start with the basics. Simple test that does not work, or shows something nonsensical, is a great hint that you forgot something, or should start digging elsewhere.
- dogtorwoof 1y agoAC offers free WhatsApp, iMessage, messenger in most flights. You can ask meta through WhatsApp to effectively browse the net :)
- CaptainOfCoit 1y agoAh "network neutrality", how you won initially yet lost over time...
- cced 1y agoI mean, if everyone was watching 4k YouTube videos they probably couldn’t support it, right?
- axus 1y agoNow imagine the same restrictions on your home Internet
- jeroenhd 1y agoI don't think there are any net neutrality laws that don't exempt things like in-flight Wi-Fi, where the upstream is so heavily restricted that providing balanced services to everyone is basically impossible or leaves the entire connection useless. With Starlink things may be looking a bit better, but I think demanding net neutrality on in-flight satellite internet and plane-to-cell-tower internet is excessive.
- Dylan16807 1y agoYou can still have a very slow free tier, a normal tier, and a quality video tier. Limited bandwidth is not a good reason to abandon net neutrality.
- ogurechny 1y agoMany years ago, some dial-up providers in my city offered free public logins to use their websites (for scratch card activation, account renewal, user guides, and so on). Some companies also paid ISPs to have their sites and services accessible in similar fashion for promotional reasons. At a certain provider, all those free logins used the same firewall configuration to only allow traffic to those free services and ISP site, probably for simplicity, so all of them were accessible with any promotional login. Most of them were not useful (to me), but different agreements with ISP resulted in different call time limit until hang-up, 10-15 minutes instead of 3-5. However, the main treasure was the addition of external page translation service as a feature on some big site. Back then, it was strictly static and server-side, URL in request gave you its HTML source with translated text strings and absolute paths to external resources, so in order for translation to work, users needed to be able to access that third party server, too. Obviously, if you gave it any other URL, the server would also grab it to translate (and choosing least similar language in parameters would leave most of the page text intact). You can imagine that having a browser supporting tabs and switching media off was very handy for loading as many free web pages in text only form as those dial-up sessions allowed. Obviously, WWW-to-email services for people who only paid for mail server access had existed even before that.
- eps 1y ago"All new is something already known, but well forgotten." Escaping locked down networks by tunneling things over DNS is one of these things. We've used it back in 00's to get out of restrictive hotel networks. Not even WiFi, but the actual wired Ethernet ones.
- advisedwang 1y agoThis isn't even tunneling over DNS. It's literally just a proxy on port 53 which is wide open.
- bawolff 1y agoI feel like you have to be brave messing with a plane's network. People tend to get really touchy when airplanes are involved.
- CaptainOfCoit 1y agoImagine if anything essential/of value/useful was exposed on the passengers WiFi, this story could have been a huge scoop. But alas, everything is heavily separated.
- reactordev 1y agoI was going to say this too. I once merely mentioned the words “Heart Attack” on a plane and was kicked off by the flight attendants. No context, they just heard the words and forced me off. There are things that trigger them because of laws and regulations like mentioning “bomb” (even if you’re describing something fantastic). So messing with the gogo flight entertainment is up there with flirting with terrorism charges.
- yabones 1y agoI'm pretty "curious" when it comes to public networks. I'll scan coffee shops, stadiums, hotels, bus hotspots, anything I can connect to. Some networks are set up well, others not so much. I would never in a thousand years run a sweep on an airplane network. That's massively risky, to the point you might never be allowed on a jet again. Anything to do with aviation I am on my absolute best behaviour.
- zavec 1y agoWithout commenting on the appropriateness of what they did, the author doesn't say they did anything like a sweep. It looks like they were manually poking a few things with dig and ping, not firing up nmap.
- reactordev 1y agoCircumventing security on a network, on a plane, is definitely up there regardless if you sweeped or not. IANAL but that could put you in DHS crosshairs.
- ajross 1y agotl;dr: The firewall on the plane allows any traffic to pass on port 53 (to allow for DNS queries) but doesn't do any state inspection or rate limiting so you can do whatever you want on it. > My roommate spent about an hour setting up a proxy server exposing port 53 using xray 1, and sent me the configuration via WeChat: An hour!? As opposed to just spinning up an sshd on that port and coming in using ssh -D to establish a local socks proxy?
- crispair 1y agoThis was a thing back in the days too. You’d use a tool like iodine to tunnel ip through dns queries. Fun!
- MarsIronPI 1y agoMy question is: would proxying over SSH running on port 53 have worked? Seems simpler than using Xray.
- Doohickey-d 1y agoOn some networks, yes: I used to use a prepay mobile network (= buy a fixed quantity of GBs in advance, use them, once you run out, you get a restricted captive portal where you can buy more, just like on this flight). But all traffic on port 53 was allowed, it didn't need to be actual DNS traffic. There's even some commercial VPN providers which offer openVPN on port 53.
- noxvilleza 1y agoIf they had a ssh server on the remote machine they could have also done something like `ssh -g -ND 53 root@localhost` from the remote machine, which would have exposed a remote-accessible SOCKS proxy on port 53.
- appreciatorBus 1y ago> Here we exploited a simple cognitive bias: not all services using port 53 are DNS query requests. Eh, I don’t think this is a result of cognitive bias. I’m sure the people involved in creating whatever hardware or software is running the network know that you can run other stuff on ports. More likely the extra effort involved in inspecting packets was not deemed worth the risk, a decision either made by the manufacturer of the hardware/software, or someone on Air Canada‘s IT team.
- gwbas1c 1y agoTo quote https://news.ycombinator.com/item?id=45537828 https://news.ycombinator.com/item?id=45537828 > This is likely another layer of security that they didn't break through: > To prevent chat apps from consuming lots of bandwidth typically your connection is severely bandwidth restricted until you pay. If they didn't then someone could simply stream movies from their chat apps.
- stackedinserter 1y agoWhy does Air Canada charges $30 for internet, that's brutal. Especially on 12hr flight where it should be provided for free imo.
- huhtenberg 1y agoThat's Air Canada. They are already making you a favor by allowing on board.
- gruez 1y ago>Especially on 12hr flight where it should be provided for free imo. "Should" in the sense that "everyone should get free food, housing, and healthcare" or that other airlines actually provide it for free? I don't know of any airline that provides it for free, the most is some Asian/Gulf airlines providing "free for 1 hour" or similar. Compared to that, "free texting, unlimited" doesn't seem too bad, considering there are also trans-continental flights with no internet access at all.
- apple1417 1y agoOn a recent 12h Air New Zealand flight I went on they offered free wifi for everyone. They say you can: - Browse the web. - Send and receive emails and messages. - Check and post to social media In practice I think they just whitelist a few messenger apps. Everything else was unusable - I couldn't even load this site. Only had my phone so couldn't check if I was actually receiving any bytes from other sites, but it at least wasn't immediately blocked.
- theideaofcoffee 1y ago> - Browse the web. > - Check and post to social media > In practice I think they just whitelist a few messenger apps. Everything else was unusable That was probably intentional, because to the vast majority of the users of these services, 'the web' is just a handful of the same social sites. As long as they can post a few things about their trip, that's the extent of the web access that they need or care to want. Sucks when you're expecting the whole kit and kaboodle, but the airlines seem to know their customers.
- Nzen 1y agoCould y'all point at instructions for how to imitate this limited internet situation ? I ask because, two years ago, I was able to circumvent the Windows-11-requires-internet-and-a-microsoft-account part of the set up for a new laptop computer by doing this on a flight. Apparently, connecting to the airplane wifi (without yet logging in) was enough to satisfy the OS set-up, but limited enough that my laptop didn't require a microsoft account. With windows 10 now end of life, I will probably get a new desktop computer and would like to repeat the feat at home. Thanks
- gruez 1y ago>Apparently, connecting to the airplane wifi (without yet logging in) was enough to satisfy the OS set-up, but limited enough that it didn't require a microsoft account. Set up a wifi network with no internet? If you have a separate router/modem, just unplug your modem from your router. If your mode/router is combined unplug the coax/fiber/phone line.
- jeroenhd 1y agoBoot up a router without any ethernet cables hooked up to it. Or turn on tethering on your phone but disable mobile data. I believe this trick doesn't work on Windows 11 anymore, though. Microsoft will happily wait for you to move some place with internet access to finish the OOBE, especially with upcoming changes where they disable various internal mechanisms to bypass the account restrictions. For about 30 bucks (or a crack) you get more life out of Windows 10 if switching to Linux isn't an option for you. You'll need to log in to an MS account once every three months to keep that going, but you can log out in between. If you live in the EU, you'll get the first year for free if you just sign in to an MS account, which I believe will also work as long as you sign in once every three months to keep the computer registered for updates.
- rubatuga 1y agoI never understood the need to post about this. Just pay the $30 or just keep quiet so others can continue to browse for free.
- dlenski 1y agoGreat writeup. I have done similar things on several long flights. Very often, there is at least one large cloud provider or CDN (e.g. Microsoft/Azure or Amazon/AWS or Google/GCP) that is whitelisted by the in-flight Internet gateway so that it can serve static pages, and I can get access to all the sites hosted by that provider simply by using domain fronting (which the author of this post describes as "disguise domain": https://ramsayleung.github.io/en/post/2025/a_story_about_bypassing_air_canadas_in-flight_network_restrictions/#approach-1-disguise-domain https://ramsayleung.github.io/en/post/2025/a_story_about_byp...)
- BestHackerOnHN 1y ago[dead]
- pehtis 1y agoAnother option would be to setup a wireguard server listening on 53. Wireguard traffic is UDP so it would work even if TCP DNS requests are blocked. And it would also make the client configuration much easier, ie just connect to the wireguard server.
- NoahZuniga 1y agoI'm not following the reasoning here: > Since acwifi.com is accessible but github.com is not, is it possible that the network has imposed restrictions on the DNS server, only resolving domain names within a whitelist (such as instant messaging domains)? > If this is the case, can I modify /etc/hosts to disguise my server as acwifi.com, so that all request traffic passes through my server before reaching the target website (github.com)? But by putting the host in /etc/hosts, you're skipping asking the planes DNS server, so how are you "disguising" an external server? And why go through the effort of proxying through acwifi.com instead of going straight to the example of github.com
- avidiax 1y agoIt could be that they allow any HTTP/HTTPS request that has Host: acwifi.com regardless of whether the IP address destination of the request is valid for acwifi.com. You see these sorts of shenanigans being used to get around country-wide firewalls. Plenty of deep packet inspection is unable to handle edge cases like the "Host:" header being misleading, having it fragmented into two TCP packets, etc. See "domain fronting".
- mixdup 1y agoit's extremely unlikely that the plane wifi would be configured that way. trying to use a host file to make github.com respond on acwifi.com was definitely a red herring. It led to figuring out 53 was open, but was definitely not how the filtering was working
- NoahZuniga 1y agoAlso, this doesn't resolved the non sequitur in the OP. It claims there might be DNS blocking, not deep packet inspection. Also cloudflare has encrypted client hello turned on by default and the only domain that shows up for https connections in this case is cloudflare-ech.com, so if any Cloudflare website is whitelisted it would have to allow this domain, and consequently any other Cloudflare website.
- otterley 1y agoLesson for implementers: block all DNS requests from customers unless they are addressed to a onboard DNS cache (whose IP address is supplied by the DHCP response).
- pumanoir 1y agoWhere can i learn to do this kind of things? Any book(s) that'd teach this kind of stuff?
- mcpherrinm 1y agoI don't know specifically what skills you're interested in, but this is all pretty much networking fundamentals. I think I learned most of what I'd need to do this in 'TCP/IP Illustrated: Volume 1'. There's plenty of "network penetration testing" type books which might also be of interest, though I don't have a specific recommendation here. There's a wider set of books at https://github.com/jacobian/infosec-engineering https://github.com/jacobian/infosec-engineering that's pretty good too, though it's a wider set of things than this.
- pumanoir 1y agoExcellent, thanks! Just took a look at "TCP/IP Illustrated: Volume 1" and was exactly what I was looking for. Any book along those lines that is compressed/water down (just to get started over a weekend)?
- Evidlo 1y agoWhy is there an in-flight internet bypass blog post every year, but they never mention Iodine?
- t1234s 1y agoPlanes that use the Panasonic system allow access to the full *.paypal.com domain to allow the paywall to work. If there is a way to somehow proxy all your traffic though something under paypal.com you could get free wifi on certain flight. Or you can pass the time away reading all the paypal API documentation.
- joshheyse 1y agoI’m guessing the speeds were slow because QOS was limiting the slowed for what was speed to be a chat only connection. What not just spoof the MAC address of “machine” that has paid. I had written a utility that monitors MAC address on the network and tries them each until it finds on that is allowed. Looks like someone released an app to do just that. https://github.com/t-mullen/wififox https://github.com/t-mullen/wififox
- advisedwang 1y agoThey may have been throttled/deprioritized but often the plane just has a really high latency connection. Some in-flight internet is provided via geo-stationary satellites, which has a minimum of 250ms latency. Even when a low-earth orbit satellite is used, I expect they are being back-hauled to the WiFi vendors datacenter before going out to the internet. When your latency gets in the hundreds of ms, no amount of bandwidth is going to make your internet connection feel snappy. And buffer bloat means even a workload that could theoretically saturate a high latency connection may actually get trashed.
- barbs 1y agoCan someone please explain what project X/Xray is? Judging from the context I imagine it's some sort of proxying software but I can't seem to find out more. The website and github seem to be littered with vague jargon or is in Chinese and Googling brings up something called XTLS?
- ogurechny 1y agoIt's a system for steganographic traffic proxying plugins that evade advanced detection systems. https://github.com/XTLS/Xray-examples https://github.com/XTLS/Xray-examples Chinese, Russian and Persian links could've given you a hint. Though after recent developments in Britain, I'm sure English docs will also appear.
- tempestn 1y agoI wonder if they heavily throttle traffic on port 53, so DNS works, but this kind of exploit isn't particularly useful.