Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
When is using an open wifi network a crime?
EH-Net
May 22, 2013, 12:30:12 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
When is using an open wifi network a crime?
Pages: [
1
]
2
3
4
Go Down
« previous
next »
Print
Author
Topic: When is using an open wifi network a crime? (Read 12083 times)
0 Members and 1 Guest are viewing this topic.
Eleven
Full Member
Offline
Posts: 120
When is using an open wifi network a crime?
«
on:
December 08, 2011, 08:56:38 AM »
I read this
SANS paper
and was surprised that they say using an open wifi network is illegal. It was from 2003, so have things changed?
As long as someone doesn't bypass any security, or monitor communication, shouldn't it be legal to use resources from an
open
network? I don't have to get explicit authorization to go to some website that was configured to be open, so why would I have to with a completely open wireless network?
If someone uses an open web proxy without explicit authorization, is that a crime?
If company X accidently makes sensitive documents available publicly on their website, you don't have to get explicit authorization to download them do you?
This whole can't use resources of completely unprotected, publicly available resources seems kind of ridiculous.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #1 on:
December 08, 2011, 09:27:08 AM »
It's illegal to use any network that you don't have permission to use.
Legal: using wifi at a coffee shop that advertises free wifi.
Illegal: using your neighbors wifi just because it has no password.
I know there is a law for that in the state that I live in, but you'd have to check the laws for your area for the specific details.
Logged
Put that in your pipe and grep it!
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #2 on:
December 08, 2011, 09:46:33 AM »
I know what you're saying, though. If it's open, shouldn't it be okay? Websites are open, and there aren't any laws about using open websites, but it's a little different. If I put up a website, and it's open to the internet, I probably had to take some steps to deliberately open that to the public. There would usually have to be a firewall rule specifically allowing that type of traffic to that specific webserver. If there is to be a domain, a domain would have to be purchased and DNS entries setup. These are things that specifically open the site to the internet, it doesn't usually happen by accident.
With wireless networks, it's different. The average user without any idea of security essentials would bring their new router home, plug it in, and say "it works!" and never change any settings, not knowing that they've created an open network. They're still not giving you permission to access their network, they just don't know any better. That being said, they probably would never know that someone connected, and wouldn't know that an illegal activity is taking place, but that still doesn't make it right for people to take advantage of it.
FL Statute 815.06
states:
Quote
Whoever willfully, knowingly, and without authorization accesses or causes to be accessed any computer, computer system, or computer network, commits an offense against computer users.
I gave a presentation on WEP cracking recently, and had to know the rules before giving the presentation.
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #3 on:
December 08, 2011, 09:47:25 AM »
It's not just not having a password, it's not having any security at all. If someone boots their laptop and an AP offers its resources, you can go to jail for using its resources? What the heck? If I setup a website and have a webpage I don't want someone to connect to, it's my responsibility to make some effort to limit access. If I don't do anything at all to limit access, and someone accesses it...
without bypassing ANY security measure
,
without malicious intent
,
without any notification or indication it was intended to be private
,
using the services it offered
, there is no way they should be guilty of a crime.
Aren't people often warned when they connect to an open AP that it is insecure? It's their responsibility to make some effort, even a small one to secure it.
«
Last Edit: December 08, 2011, 09:54:46 AM by Eleven
»
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #4 on:
December 08, 2011, 09:53:45 AM »
The law doesn't state that there are different rules whether or not you have security measures in place, the law is there to protect people who don't know any better. Not everybody who buys a router is going to have to knowledge to setup security. Does that mean that person is not responsible for their own security measures? Not at all. Everyone is accountable for their own network security, that's why there is a security field to begin with.
Like I said in my previous post, would that person even know that a crime was committed? Probably not. Does that make it okay? Absolutely not.
Logged
Put that in your pipe and grep it!
ziggy_567
Sr. Member
Offline
Posts: 361
Re: When is using an open wifi network a crime?
«
Reply #5 on:
December 08, 2011, 09:56:58 AM »
Let me ask you a question, Eleven. If you were walking along in your neighborhood and you found that one of your neighbors had left their front door unlocked and windows open, would you go on in to the house and start using their water, electricity, cable, etc.?
This is essentially what you'd be doing by using someone else's open wifi. Sure, its not as bad as going in to their house and cleaning out their fine crystal, jewelry, and electronics, but stealing is stealing.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: When is using an open wifi network a crime?
«
Reply #6 on:
December 08, 2011, 09:59:26 AM »
Most networks for free use make advertisements that this service is available. Typically a physical sign (a la coffee shop) or an acceptance agreement via the default page of the wireless service's site.
Logged
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #7 on:
December 08, 2011, 10:03:33 AM »
Quote from: eth3real on December 08, 2011, 09:53:45 AM
The law doesn't state that there are different rules whether or not you have security measures in place,
the law is there to protect people who don't know any better.
Not everybody who buys a router is going to have to knowledge to setup security. Does that mean that person is not responsible for their own security measures? Not at all. Everyone is accountable for their own network security, that's why there is a security field to begin with.
Like I said in my previous post, would that person even know that a crime was committed? Probably not. Does that make it okay? Absolutely not.
I don't know about that... The same kind of people who are computer illiterate and don't know how to make any effort to secure their AP are most often going to be the same kind of people who themselves are going to be convicted of using someone's open wifi. Heck, I'm a geek and I didn't even know it was a crime.
Logged
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #8 on:
December 08, 2011, 10:06:23 AM »
Quote from: ziggy_567 on December 08, 2011, 09:56:58 AM
Let me ask you a question, Eleven. If you were walking along in your neighborhood and you found that one of your neighbors had left their front door unlocked and windows open, would you go on in to the house and start using their water, electricity, cable, etc.?
This is essentially what you'd be doing by using someone else's open wifi. Sure, its not as bad as going in to their house and cleaning out their fine crystal, jewelry, and electronics, but stealing is stealing.
Apples and oranges... Open wifi networks are everywhere and an intentionally open wifi network is indistinguishable from an unintentionally open wifi network. Also, an AP offers its resources... if someone has an open door with a sign inviting you in, that shouldn't be a crime for going in.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #9 on:
December 08, 2011, 10:10:26 AM »
Hate to tell you this, but not knowing the law doesn't make it legal. You can defend this as much as you want, but I didn't write the laws. You still need to check what it says for your area.
Quote from: Eleven on December 08, 2011, 10:06:23 AM
if someone has an open door with a sign inviting you in, that shouldn't be a crime for going in.
This is what we're talking about. A sign implies advertising that it is an open service. If I have an unsecured house, it is not open to the public. If I have an unsecured wireless connection, it is not open to the public. If I have a sign stating that either of these are free, then by all means, go for it.
Also, you can't honestly say that you don't know the difference between the wifi offered for free at a coffee shop, and an open wifi network in your neighborhood.
«
Last Edit: December 08, 2011, 10:12:45 AM by eth3real
»
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #10 on:
December 08, 2011, 10:20:29 AM »
Quote from: eth3real on December 08, 2011, 10:10:26 AM
Hate to tell you this, but not knowing the law doesn't make it legal. You can defend this as much as you want, but I didn't write the laws. You still need to check what it says for your area.
Yeah, I know, but my point was you said the laws are to protect people who don't know any better, I was just saying it's going to convict those same people who don't know any better.
Quote from: eth3real on December 08, 2011, 10:10:26 AM
This is what we're talking about. A sign implies advertising that it is an open service. If I have an unsecured house, it is not open to the public. If I have an unsecured wireless connection, it is not open to the public. If I have a sign stating that either of these are free, then by all means, go for it.
Also, you can't honestly say that you don't know the difference between the wifi offered for free at a coffee shop, and an open wifi network in your neighborhood.
I see where you're coming from. But rather than putting the responsibility on everyone else to go hunting for a sign, they should put the responsibility on the few people who own the AP to make an effort to secure it. Because at some point negligence becomes a factor, for example today I heard some places make it a crime to have an open AP. Those jurisdictions seem to have my point of view of putting the responsibility on the owner of the AP.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #11 on:
December 08, 2011, 10:27:35 AM »
I agree that anyone setting up an access point is responsible for protecting their network, from a security standpoint. If you don't want your stuff to get stolen, don't leave it out in the open. Obviously a malicious hacker is ignoring the law when attempting to gain access and steal information.
However, my point is this: the law does not make any discrimination between an access point that is protected and an access point that is not protected. In my area, it's very clear: "unauthorized access" is a crime. Being unprotected does not grant authorization.
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #12 on:
December 08, 2011, 10:44:03 AM »
Quote from: eth3real on December 08, 2011, 10:27:35 AM
I agree that anyone setting up an access point is responsible for protecting their network, from a security standpoint. If you don't want your stuff to get stolen, don't leave it out in the open. Obviously a malicious hacker is ignoring the law when attempting to gain access and steal information.
However, my point is this: the law does not make any discrimination between an access point that is protected and an access point that is not protected. In my area, it's very clear: "unauthorized access" is a crime. Being unprotected does not grant authorization.
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
«
Last Edit: December 08, 2011, 10:46:01 AM by Eleven
»
Logged
ziggy_567
Sr. Member
Offline
Posts: 361
Re: When is using an open wifi network a crime?
«
Reply #13 on:
December 08, 2011, 10:44:12 AM »
Its not apples and oranges.
As with a house with an open door, an open wifi network is not an invitation to come on in and suck up bandwidth. There must be some other invitation other than the mere existence of the wifi network. Whether it be a hotel clerk telling you to connect to hhonors, a sign on the door of the Starbucks, or a landing page with a Terms of Use, there must be some sort of invitation to use the network.
As with any legal question, if you are unsure of legality its best to not do it until you are sure. As ether3al has pointed out, ignorance of the law is no excuse.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #14 on:
December 08, 2011, 10:53:42 AM »
Quote from: Eleven on December 08, 2011, 10:44:03 AM
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
Now we're starting to get on the same page.
The only difference I have, is that I think the law is not the one that's at fault here. I think the hardware manufacturers, or maybe the 802.11 standard, should require you to protect the access point during setup, and make you jump through hoops if you are absolutely sure you want your AP to be open and unprotected. This would force the lazy or non-security-aware people to at least have some sort of protection, and if they actually went through the trouble of making it open, then they knew what they were doing.
Logged
Put that in your pipe and grep it!
Pages: [
1
]
2
3
4
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(14) by
3xban
Network Pen Testing
: Ruby on Rails Vulnerabilities/Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.