Skip to content

Comment on Hotel Wi-Fi blocking: Marriott is bad

Comments

Cisco sell a Wireless LAN controller, which can send disconnect packets to "rogue" APs that get set up, rendering them useless. This is particularly important at events where the airspace is severely cramped, such as big arena events, racing, horse racing etc. where the myriad of APs to provide coverage of free wifi to pundits would have to compete with these other APs. In a severely crammed airspace, this would help to encourage the other AP providers to turn their boxes off.

And getting a mobile telephone call in such events is even trickier, given that 50,000 people are in one space and the masts to serve them are oversubscribed. If they all suddenly want to place bets or browse the web, that's incredibly difficult to provide on the mast, so providers will set up additional masts for big events (like the big horse-racing events here in the UK). That's why they provide free wifi too, and having other APs set up and attempting to provide wifi over the airspace doesn't really help.

I wonder if Marriott hotels have the same approach in order to provide better wifi coverage? I have been in numerous hotels where the wifi coverage was great if you're sat in the bar but abysmal if you're down the other end of the building (where the hotels here in the UK are large old buildings with thick walls, very tricky for wifi).

Irritating if you're trying to use your phone to provide wifi to your laptop in order SSH to your own box at home or to get content via your mobile (which might be faster than their Internet access in some cases). I suppose you could just use a Bluetooth PAN instead (and it uses less power!)

  Cisco sell a Wireless LAN controller, which can 
  send disconnect packets to "rogue" APs [...] 
  this would help to encourage the other AP 
  providers to turn their boxes off.
Perhaps I should make a product that detects controllers sending fake deauth packets, and does the same thing in return.

This would help "encourage" people who buy the Cisco product to turn that feature off :)

Not defending Marriott, but the primary use case for rogue AP mitigation is not fueled by corporate greed. I recommend it to clients to keep employees from standing up insecure AP's on their internal network, which is a serious security concern. I encourage you to write the tool, though!

[deleted]

[deleted]

Many consumer routers have a clone MAC feature to address exactly this issue. A person puts their computer behind the new wifi router and clones the MAC address so it can get on the network.

Cisco makes the product that does the detection, too. So does Aruba, Motorola, and probably Meru.

The first main use case for the deauth packets is when someone is broadcasting your SSID but they're not actually part of your network. The second use case is when a client that you actually own (corporate laptop) connects to an access point it's not supposed to. And nobody will really mind if you do those.

This anti-competitive use case is another matter.

I mind. You can't own an SSID and they are not uniquely set. Just because you have the same SSID as me what gives you the right to deauth my router?

What is the use case for using an SSID that is already taken? Especially in a business or corporate environment.

The use-case doesn't really matter; it's against the regulations for that radio band to interfere with other people's usage. Even if you think they're attempting to commit fraud.

Right about radio but the thread was talking about Cisco sending deauth packets to rouge APs.

... as was I! Just because you consider an AP to be rogue doesn't mean it's legal for you do something about it.

Right! because who decides if it is a rogue AP. In this cause Marriott has decided that all AP's that don't belong to them are rogue.

And I would argue that as it is their building they can decide what is legal and what is not, no?

I recently worked for an ISP providing service to some Marriott resorts. This is my opinion and in no way representing either company, but this is exactly what Marriott is trying to do. Marriott is not using any sort of wifi jammer like the author is suggesting; in fact such devices would block their own wifi signal.

The most typical problems with wifi in resorts comes down to construction; most of these were built years before wifi was a consideration and are constructed in a way such that even with commercial APs you will get a very poor signal even with the APs in each unit. There's one such property I know of where guests only get wifi in the one room with the AP and out on their balcony and no where else in the hotel besides the pool & lobby.

Also they often use authentication pages that mean you can't get on with a device without a browser...but when you have 200 guests sharing a 100Mbps connection, you don't want someone hooking their Xbox or AppleTV anyway.

Actually, 200 guests on a 100MBit connection is probably not a problem. At a nearby university they have a 100MBit connection for 1000 students plus teachers, and it holds up reasonably well. (Of course, unless the hotel bought an overbooked connection with only a theoretical max speed of 100mbit)

Even though we're a major vacation destination, people seem to want to stay in and watch movies or play online games on their expensive vacations. There's basically always a minority of users ruining the connection for everyone else.

Watching movies and playing games away from home does sound like a nice vacation to me.

Ruining is subjective - many hotel wifi networks were provisioned for 2002 style access of web and email, not 2012 where one's mom streams gigs of video. This is why I appreciate the move to free basic wifi and paid premium wifi at some hotels.

If they all started watching HD YouTube videos all night long, would the link be saturated?

I suppose you could just use a Bluetooth PAN instead (and it uses less power!)

On that note, it's worth pointing out that many Android (and other) phones allow USB-based tethering as well, which eliminates the need to use the airspace entirely.

I think the solution to this is for the industry to add a set of licensed frequencies to the 802.11 spec. They could set it up so that base station operators would rent the alternate frequencies for their events (either baked into the cost of the AP, or on a time/geographic limitation basis), and consumer client-side devices would of course need to be updated to implement this additional spectrum when talking to a licensed AP.

Of course this doesn't do any good for existing consumer devices, it would have to be baked into the next 802.11x spec.

Is that LAN controller illegal? According to the article:

"Federal law prohibits the operation, marketing, or sale of any type of jamming equipment, including devices that interfere with cellular and Personal Communication Services (PCS), police radar, Global Positioning Systems (GPS), and wireless networking services (Wi-Fi)."

If that disconnect is disabling wifi aps then technically it is "intefering" with wifi services and thus illegal?

I imagine "jamming" has a pretty specific definition by the FCC. For example, if I DOS a WAP with reset packets, then that's just network traffic as far at the FCC is concerned. If I setup some kind of overpowered RF device that demolishes everything in the 2.4ghz spectrum, then I'm guilty of jamming.

If you DDOS my website, which is for some reason attached to the internet via wireless, you're not jamming anyone. You're doing a DDOS. The regulatory body or laws surrounding that are going to be different than a proper old fashioned RF jam.

Actually it's not - the FCC definition is extremely broad, it simply states:

"No person shall willfully or maliciously interfere with or cause interference to any radio communications of any station licensed or authorized by or under this Act[.]" [1]

And in fact their explanation specifically states that jammers "prevent targeted devices from establishing or maintaining a connection". [2]

To put the same actions in a different context - if two radio amateurs are trying to communicate over a digital mode and I broadcast "disconnect" packets to shut them down, I am clearly jamming their communications. The fact that this jamming occurs on the 2.4GHz band instead of the 20-meter band is irrelevant.

What it comes down to - your laptop wifi is a device licensed by the FCC for radio operation, two parties (you and the router) are communicating, and a smart jammer interferes with these communications.

As for your DDOS example - jamming is usually used in the context of the low-level layers of the OSI model, not the application layer. However, there are analogous actions that would be actionable in amateur radio. If you get a dozen of your buddies to deliberately pile-up on someone's CQ/QRZ without actually trying to communicate, you can bet the FCC's gonna look at that as de facto jamming too.

You can get away with a lot as long as you do it on private wires - but when you get public airwaves involved then an additional set of much stricter rules apply.

[1] http://www.fcc.gov/document/fcc-proposes-29k-fine-employer-j...

[2] http://www.fcc.gov/document/consumer-alert-using-or-importin...

Has your interpretation ever panned out in reality? Do DDOS kiddies ever get FCC jamming charges applied? I've never seen that. I can't imagine case law fitting in with your interpretation.

Sure. K1MAN made communications that would probably have been legal if they didn't cause willful interference:

In support of its motion for summary judgment on the monetary forfeiture, the Government presented FCC transcripts of recordings made on November 27, 2004, December 8, 2004, and March 31, 2005 that it alleges show K1MAN beginning to transmit on top of existing communications by other users. [...] The Government also provided the declarations of several FCC personnel who monitored and observed interference between K1MAN and other amateur operators. [...] [1]

Chief US District Judge John A. Woodcock Jr, in writing for the Court, agreed with the FCC on the first two counts -- willful or repeated failure to respond to FCC requests for information, and willful or malicious interference -- and granted summary judgments to the FCC in the amount of $3000 and $7000, respectively. [2]

As for more targeted attacks, see the Notices of Apparently Liability for KZ8O [3] and K3VR [4].

Once public airwaves are involved (as opposed to wires) you're on the FCC's turf, and the FCC takes radio communications VERY seriously.

[1] http://www.arrl.org/files/media/News/Baxter_Summary_Judgment...

[2] http://www.arrl.org/news/us-district-court-for-maine-issues-...

[3] http://transition.fcc.gov/Daily_Releases/Daily_Business/2014...

[4] http://transition.fcc.gov/Daily_Releases/Daily_Business/2014...

Technically it's not really jamming. It's not shutting down the frequency, it's just resetting every connection. It's a denial of service attack.

You're pretty much describing a "smart"/active jammer there.

The difference between this and jamming is signal jamming typically uses noise on the same frequency to make it impossible for the receiver to understand the signal. Basically, jamming blocks ALL communication on that frequency. This just shuts down the specific AP by deauth'ing the clients.

Dumb jamming, yes. Smart jamming tries to interdict the enemy's communications. Look into the the more advanced ECM/anti-radar stuff.

Everyone jammer is a DoS attack in one form or other. Either way you're flooding clients with junk disabling the connectivity.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.