Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Literally every browser out there sends a user agent that is in some way lying. Anyone trying to authenticate based on a user agent is a victim only of their own stupidity, not any sort of crime by their guests.


Good thing you're not a lawyer, because it's certainly illegal in the UK...

http://www.legislation.gov.uk/ukpga/1990/18


Good thing there are other countries in the world apart from UK and US.


It looks to me like that only clearly applies to unauthorized access to programs and data stored on a computer. Unauthorized routing of packets through a computer is not obviously covered by that law.


The very, very first clause:

    > he causes a computer to perform any function with intent 
    > to secure access to any program or data held in ***any*** 
    > computer


No. That's not sufficient to classify the action as illegal. If you're accessing a public website, but through a wireless router that the owner doesn't want you using without paying for, then the data you're accessing is still data you're authorized to access (it being a public website, after all).

To get charged under this law, you would have to be accused of the unauthorized access of something on the router itself, since that is the only relevant computer you aren't authorized to use. The charges against you would have to be based on the theory that sending packets with a spoofed MAC address or user agent is accessing the routing program and tables on the router in an unauthorized manner. That argument delves much deeper into the law than just the first clause.


You're talking about computer misuse law - there are existing cases in UK and probably US that cover this.

Here's one BBC article that talks about it: http://news.bbc.co.uk/1/hi/magazine/6960304.stm

> The Communications Act 2003 says a "person who (a) dishonestly obtains an electronic communications service, and (b) does so with intent to avoid payment of a charge applicable to the provision of that service, is guilty of an offence".

Seems pretty clear. A person is paying for hotel access; notices their Apple-device using colleague is not paying; spoofs the user agent; - these seem to cover all the points of dishonesty with the intent to avoid paying for a service.

Even if the hotel is in a country that doesn't have that particular law there is probably some fraud law that covers the actions. (I realise now that I should have mentioned the fraud because that's the more serious offence and it seems some people missed my point).


That's an entirely different law from the one that peteretep cited. His assertion that it's illegal may in fact be correct, but his justification was complete bullshit. The fact that you've found a law that is relevant doesn't make him any less wrong.


Yes, people who are relying on user agents are stupid.

That doesn't make it any less illegal to use the useragent to deceive someone about what equipment you're using purely to avoid paying a charge.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: