Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
When is using an open wifi network a crime?
EH-Net
May 25, 2013, 05:59:09 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
When is using an open wifi network a crime?
Pages:
1
[
2
]
3
4
Go Down
« previous
next »
Print
Author
Topic: When is using an open wifi network a crime? (Read 12131 times)
0 Members and 1 Guest are viewing this topic.
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #15 on:
December 08, 2011, 10:59:41 AM »
Quote from: ziggy_567 on December 08, 2011, 10:44:12 AM
Its not apples and oranges.
As with a house with an open door, an open wifi network is not an invitation to come on in and suck up bandwidth. There must be some other invitation other than the mere existence of the wifi network. Whether it be a hotel clerk telling you to connect to hhonors, a sign on the door of the Starbucks, or a landing page with a Terms of Use, there must be some sort of invitation to use the network.
As with any legal question, if you are unsure of legality its best to not do it until you are sure. As ether3al has pointed out, ignorance of the law is no excuse.
I guess it comes down to whether there should be an indication it is public, or an indication it is private. I believe it should be the AP owner's responsibility to notify it is private. They don't have to be an expert in security, they just have to read the manual. Simple MAC filtering would be enough of an indication that it is private. I'd even count having it open and naming the AP something like DoNOTconnect or PrivateNetwork; similar to a no trespassing sign.
Logged
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #16 on:
December 08, 2011, 11:01:31 AM »
Quote from: eth3real on December 08, 2011, 10:53:42 AM
Quote from: Eleven on December 08, 2011, 10:44:03 AM
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
Now we're starting to get on the same page.
The only difference I have, is that I think the law is not the one that's at fault here. I think the hardware manufacturers, or maybe the 802.11 standard, should require you to protect the access point during setup, and make you jump through hoops if you are absolutely sure you want your AP to be open and unprotected. This would force the lazy or non-security-aware people to at least have some sort of protection, and if they actually went through the trouble of making it open, then they knew what they were doing.
I agree 100%. You're right, ultimately the hardware manufacturers are responsible for creating this mess. That we can agree on.
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #17 on:
December 09, 2011, 06:24:11 AM »
Quote from: Eleven on December 08, 2011, 10:44:03 AM
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
So instead of trying to "steal" or borrow in your case, their network why don't you knock on there door and try to educate them. Yes I know people can read the manual but there are "baby boomers" and "Gen X" people that these manuals make no sense to. With knowledge comes responsibility, so instead of doing something malicious help these people out.
Logged
CCENT, A+, Network+, Security+
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #18 on:
December 09, 2011, 07:58:09 AM »
Quote from: El33tsamurai on December 09, 2011, 06:24:11 AM
So instead of trying to "steal" or borrow in your case, their network why don't you knock on there door and try to educate them.
I actually did that once. The guy freaked out and turned off his wifi permanently.
Logged
Put that in your pipe and grep it!
ziggy_567
Sr. Member
Offline
Posts: 361
Re: When is using an open wifi network a crime?
«
Reply #19 on:
December 09, 2011, 08:02:42 AM »
Quote
I actually did that once. The guy freaked out and turned off his wifi permanently.
That is an alternative solution.....
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #20 on:
December 09, 2011, 08:26:41 AM »
Better you told him, then "someone else" comes by and steals vital information from him. Note the name of the site "The Ethical Hacker Network", we are here because we want to do good not because we want to steal someones wireless or do malicious things.
Logged
CCENT, A+, Network+, Security+
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #21 on:
December 09, 2011, 08:38:02 AM »
Quote from: El33tsamurai on December 09, 2011, 06:24:11 AM
Quote from: Eleven on December 08, 2011, 10:44:03 AM
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
So instead of trying to "steal" or borrow in your case, their network why don't you knock on there door and try to educate them.
I don't view it as stealing or malicious because they are offering a service. And it's not borrowing because they aren't getting it back (they probably wouldn't even notice it missing). It's simply using a service they offered. If someone chooses not to shred their trash and they leave it in a public place like on their curb, it's their own fault if someone takes their trash and goes through it. If someone uses the trash for illegal purposes, or by passes security such as even the most insecure lock in the world to get to the trash or ignores a no trespassing sign, THEN that's a crime. If someone is broadcasting use of their open wifi to the world, it should be their own fault for not enabling any security and ignoring warnings that it's not secure.
Like I've said, there is also the analogy of someone creating a private web page on a website and choosing not to protect it at all and ignoring warnings. Then the person who sees it advertised (indexed) in google, who has no malicious intentions, and clicks the link and that person should go to jail? Nope. It's the sites owner's fault for negligence. Even though Apache defaults to making the web page public just like an AP might, even though the site owner has no idea what they're doing, it's still the owner's fault for not making any effort to limit access.
I never used an open access point. I've never even owned a smartphone. I'm about to get a wifi card for my desktop though to test my own wifi security and was hoping to also use it for open wifi networks. Kind of bummed the last part is considered illegal.
Quote
Yes I know people can read the manual but there are "baby boomers" and "Gen X" people that these manuals make no sense to. With knowledge comes responsibility, so instead of doing something malicious help these people out.
That's the thing though, it's not a matter of tech savvy people taking advantage of those who aren't. There are way more people who don't understand technology than geeks, so I'm sure there are more computer illiterate people breaking this law than geeks breaking it. But yes I have thought about yesterday and today of notifying people who may of accidentally have setup open wifi...
Logged
yatz
Full Member
Offline
Posts: 222
Re: When is using an open wifi network a crime?
«
Reply #22 on:
December 09, 2011, 08:39:05 AM »
Quote from: Eleven on December 08, 2011, 11:01:31 AM
ultimately the hardware manufacturers are responsible for creating this mess. That we can agree on.
I don't know about this. The past few routers I've configured do a very good job of making
strong suggestions
to the user that secure is better, namely in these routers I would have had to jump through hoops and multiple warning messages in order to turn OFF security. With WPA2, all you need is a PSK. It's another password, not even with the complexity requirements. I don't even care if the password is written on the router itself. The problem is not manufacturers, the problem is always and will continue to be the human element.
That said, open wifi is not an invitation. Legally even the police can't come into your house without a warrant, even if the door is open. No explicit consent = no consent = illegal.
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #23 on:
December 09, 2011, 08:46:10 AM »
That's good to know. I've seen way too many routers that you can take out of the box, plug it in, and it's already
up and running
with a typical wifi name (like Linksys or Netgear), absolutely no protection, and utilize a default username and password for the admin console. Many people will see this, "it's working!", and never look at it again. While driving through my neighborhood with a laptop running airodump-ng or kismet, I can still find dozens of networks like this.
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #24 on:
December 09, 2011, 08:57:07 AM »
Quote from: yatz on December 09, 2011, 08:39:05 AM
That said, open wifi is not an invitation. Legally even the police can't come into your house without a warrant, even if the door is open. No explicit consent = no consent = illegal.
It's not just that the door is open (no security) it's that the AP was configured to offer its services. I don't have to have explicit authorization to take someones trash, or view a webpage that has no access control. Even though the owner may of considered them private, they are assumed to be public. Entering and searching a house is a lot more sensitive than using internet. If someone is monitoring communication of an open wifi, yes, that should be a crime.
«
Last Edit: December 09, 2011, 08:59:06 AM by Eleven
»
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #25 on:
December 09, 2011, 09:07:31 AM »
Quote from: Eleven on December 09, 2011, 08:38:02 AM
Quote from: El33tsamurai on December 09, 2011, 06:24:11 AM
Quote from: Eleven on December 08, 2011, 10:44:03 AM
I understand the law, I just don't agree with it.
Personally, I view the combination of absolutely no security on the AP, and the AP offering its services as being authorized. Similar to being authorized to come in my house if I have the door wide open (no security) and invite you in when you walk by (SSID broadcasts).
I know the difference is technical and not everyone is going to understand how to configure an AP, but that's why they should read the manual, or listen to warnings they get when configuring or connecting to their AP.
So instead of trying to "steal" or borrow in your case, their network why don't you knock on there door and try to educate them.
I don't view it as stealing or malicious because they are offering a service. And it's not borrowing because they aren't getting it back (they probably wouldn't even notice it missing). It's simply using a service they offered. If someone chooses not to shred their trash and they leave it in a public place like on their curb, it's their own fault if someone takes their trash and goes through it. If someone uses the trash for illegal purposes, or by passes security such as even the most insecure lock in the world to get to the trash or ignores a no trespassing sign, THEN that's a crime. If someone is broadcasting use of their open wifi to the world, it should be their own fault for not enabling any security and ignoring warnings that it's not secure.
Offering a service? A service has to be advertised as a service which was post before. So no its not a service.
"And it's not borrowing because they aren't getting it back (they probably wouldn't even notice it missing)." Jelly beans at the candy store are small and the owner would not miss if 10 or 15 were missing, so it makes it right to take 10 to 15 because he would not notice? See this thing called "morals" tells me its wrong.
" If someone chooses not to shred their trash and they leave it in a public place like on their curb, it's their own fault if someone takes their trash and goes through it. If someone uses the trash for illegal purposes, or by passes security such as even the most insecure lock in the world to get to the trash or ignores a no trespassing sign, THEN that's a crime." And if you check with the ISP they will tell you the same thing about using another persons internet
.
"If someone is broadcasting use of their open wifi to the world, it should be their own fault for not enabling any security and ignoring warnings that it's not secure." Like I stated before they might not understand and it takes "ethical people" to help them out.
Quote from: Eleven on December 08, 2011, 10:44:03 AM
Like I've said, there is also the analogy of someone creating a private web page on a website and choosing not to protect it at all and ignoring warnings. Then the person who sees it advertised (indexed) in google, who has no malicious intentions, and clicks the link and that person should go to jail? Nope. It's the sites owner's fault for negligence. Even though Apache defaults to making the web page public just like an AP might, even though the site owner has no idea what they're doing, it's still the owner's fault for not making any effort to limit access.
I never used an open access point. I've never even owned a smartphone. I'm about to get a wifi card for my desktop though to test my own wifi security and was hoping to also use it for open wifi networks. Kind of bummed the last part is considered illegal.
Quote
Yes I know people can read the manual but there are "baby boomers" and "Gen X" people that these manuals make no sense to. With knowledge comes responsibility, so instead of doing something malicious help these people out.
That's the thing though, it's not a matter of tech savvy people taking advantage of those who aren't. There are way more people who don't understand technology than geeks, so I'm sure there are more computer illiterate people breaking this law than geeks breaking it. But yes I have thought about yesterday and today of notifying people who may of accidentally have setup open wifi...
You should do more then think about it, you should do it.
Logged
CCENT, A+, Network+, Security+
yatz
Full Member
Offline
Posts: 222
Re: When is using an open wifi network a crime?
«
Reply #26 on:
December 09, 2011, 09:19:58 AM »
Quote from: Eleven on December 09, 2011, 08:57:07 AM
It's not just that the door is open (no security) it's that the AP was configured to offer its services.
This is the source of confusion. It's not only the AP services that are being accessed, it's the internet service that is being paid for by the owner that are being accessed. Let's consider them separately.
1. Access to internal network from open wifi
This is my point from earlier. An open door does not imply consent. The services the AP is offering provide entry into a personal network. Just because the network is digital instead of physical, that doesn't make it any less personal property. The owner purchased the equipment, configured it for personal use, and it is serving the owner as such. In the case where this serving is capable of supporting more than just the owner, it is still the owner's property and requires the owner's consent. Unfortunately, there isn't a very good way for an owner to grant that consent to a general audience, but this does not give blanket authority. The consent is still required for access. Getting a DHCP address on a network for possible access is equivalent to accessing a license, so yes, even connecting to an open wifi without explicit consent is not permitted.
2. Access across subscription-based internet link to external network from open wifi
This takes the same concept one step further. Now the use is not limited to personal property use but also could violate the usage agreement between the owner and the service provider.
Who is at fault if the owner enables this by disabling security? Well, who is at fault if a car door is left unlocked in a mall parking lot and your CDs get stolen? The owner may be at fault, but theft is still theft. In the case of open wifi, the theft is just harder to classify.
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #27 on:
December 09, 2011, 09:53:54 AM »
Quote from: yatz on December 09, 2011, 09:19:58 AM
This is the source of confusion. It's not only the AP services that are being accessed, it's the internet service that is being paid for by the owner that are being accessed. Let's consider them separately.
1. Access to internal network from open wifi
This is my point from earlier. An open door does not imply consent. The services the AP is offering provide entry into a personal network. Just because the network is digital instead of physical, that doesn't make it any less personal property. The owner purchased the equipment, configured it for personal use, and it is serving the owner as such. In the case where this serving is capable of supporting more than just the owner, it is still the owner's property and requires the owner's consent. Unfortunately, there isn't a very good way for an owner to grant that consent to a general audience, but this does not give blanket authority. The consent is still required for access. Getting a DHCP address on a network for possible access is equivalent to accessing a license, so yes, even connecting to an open wifi without explicit consent is not permitted.
2. Access across subscription-based internet link to external network from open wifi
This takes the same concept one step further. Now the use is not limited to personal property use but also could violate the usage agreement between the owner and the service provider.
Okay, but how is that any different than someone who isn't technical, spending money setting up a website they want to be private and not enabling any security what so ever to make it private. If someone clicks a link to it, they haven't been explicitly authorized to use the network and server resources that they didn't pay for, but they can because it was configured to be open and therefore assumed to be public. I just think open wifi networks should be considered the same way.
Quote
Who is at fault if the owner enables this by disabling security? Well, who is at fault if a car door is left unlocked in a mall parking lot and your CDs get stolen? The owner may be at fault, but theft is still theft. In the case of open wifi, the theft is just harder to classify.
If the owner of the AP, configures their AP to offer its services without any restrictions, that should count as authorization for the same reason as when someone setups a web server to offer its services without any restrictions, it is implied authorization.
Logged
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #28 on:
December 09, 2011, 10:02:36 AM »
Quote from: El33tsamurai on December 09, 2011, 09:07:31 AM
"And it's not borrowing because they aren't getting it back (they probably wouldn't even notice it missing)." Jelly beans at the candy store are small and the owner would not miss if 10 or 15 were missing, so it makes it right to take 10 to 15 because he would not notice? See this thing called "morals" tells me its wrong.
Again, I say the AP is offering its resources just like a website with no access control, so it's more similar to being offered the jelly beans so no it wouldn't be immoral.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #29 on:
December 09, 2011, 11:42:31 AM »
Eleven, why are you trying to defend this so much?
We've already covered the basics, having an open access point DOES NOT imply authorization, and the law EXPLICITLY says "unauthorized access" is a violation. What more is there to discuss?
If you want to change the laws, send a letter to your congressmen. You asked why it was illegal, and we answered. The rest is an ethics question, and you already know where we stand. We can talk this in circles all you want, but now you know the law, it doesn't matter if you feel like it
should
be okay or not.
Logged
Put that in your pipe and grep it!
Pages:
1
[
2
]
3
4
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.