Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 46 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
When is using an open wifi network a crime?
EH-Net
May 21, 2013, 03:38:42 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
When is using an open wifi network a crime?
Pages:
1
2
[
3
]
4
Go Down
« previous
next »
Print
Author
Topic: When is using an open wifi network a crime? (Read 12054 times)
0 Members and 1 Guest are viewing this topic.
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #30 on:
December 09, 2011, 11:44:10 AM »
I feel someone is trying to defend there actions
.
Logged
CCENT, A+, Network+, Security+
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #31 on:
December 09, 2011, 11:56:57 AM »
Quote from: eth3real on December 09, 2011, 11:42:31 AM
Eleven, why are you trying to defend this so much?
We've already covered the basics, having an open access point DOES NOT imply authorization, and the law EXPLICITLY says "unauthorized access" is a violation. What more is there to discuss?
If you want to change the laws, send a letter to your congressmen. You asked why it was illegal, and we answered. The rest is an ethics question, and you already know where we stand. We can talk this in circles all you want, but now you know the law, it doesn't matter if you feel like it
should
be okay or not.
I'm defending my position as much as you guys are. I understand the law that you have described. I'm just saying the logic seems to be inconsistent. You can make a single click of the mouse, have no malicious intentions, bypass no security at all, access a resource that was either intentionally or unknowingly configured to be open, a resource you do not own or pay for, a resource that has no indications it was intended to be private, and when talking about a wifi it's illegal, but websites it is legal. Does not compute.
And no, as I said, I never connected to an open AP, My wifi card is on the way though, but now I'm just going to use for my own network; which is the main reason I bought it. This isn't even about me, I haven't broken this law, but there are a TON of people who have. I don't see them as criminals.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #32 on:
December 09, 2011, 12:01:57 PM »
Now that you know the law, you can assume that every open wifi network is unauthorized until you see a sign saying it's okay, or ask permission.
The moral of the story is that we didn't write the laws, the laws don't always make sense, but it is still unethical to break the laws regardless of your viewpoint. Just because you think it should be okay doesn't make it okay.
You say you're defending your position as much as we are, but we're not defending our position; we're telling you what the law says. In the end, none of use can change the laws, we're just telling you the facts.
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #33 on:
December 09, 2011, 12:11:54 PM »
Quote from: eth3real on December 09, 2011, 12:01:57 PM
Now that you know the law, you can assume that every open wifi network is unauthorized until you see a sign saying it's okay, or ask permission.
The moral of the story is that we didn't write the laws, the laws don't always make sense, but it is still unethical to break the laws regardless of your viewpoint. Just because you think it should be okay doesn't make it okay.
You say you're defending your position as much as we are, but we're not defending our position; we're telling you what the law says. In the end, none of use can change the laws, we're just telling you the facts.
Well it seemed to me like you guys agreed with the logic of the law and were defending it. If you guys agree the law's application of explicit authorization is inconsistent, but you should still follow it, you're probably right. But really the laws should be consistent. When the average person has violated this one law and is a criminal, that's a problem.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #34 on:
December 09, 2011, 12:43:35 PM »
I agree that unknowing end-users of wireless routers should be protected from just not knowing any better. I don't believe that this law is efficient in protecting those people, as most people don't know the law exists, nor would the owners of the network even realize that such an event took place.
I think these people
should
have protected networks, because I don't think it's right that they're just open to anybody use their networks like we're discussing. I definitely don't agree with people legitimizing it "because it was open." I don't believe that the owners of open wireless networks are at fault for this. It is simply easier (in most cases) to leave it alone once it's working, as most people who are not technical would be afraid of messing it up if they change anything. That's not their fault; it should be easier to make it secure than easier to leave it open.
Hardware manufacturer's are not required to make the interface easy for people to use, or make the interface enforce any kind of security standards. Maybe that's what needs to change, but I believe the current laws are fine where they are.
You keep saying that the laws are inconsistent, but comparing it to a website is not a fair comparison. Wifi has a finite range, and it is easier to make it open than secure. If you made an open website on the internet, you had to go through the trouble of making it open on the internet, which can be accessed by the entire world. Not a fair comparison by a longshot.
This is one of those laws that has good intentions, but very little effect in practice. Now that you know you're "not allowed" to connect to open access points, doesn't mean that there is anyone enforcing that law. If you go 5 mph over the speed limit, you are still breaking the law. Is anyone going to give you a citation for it? Probably not. Did you still knowingly break that law? Yes.
My entire point of this, is that we
need
some kind of protection against attacks like this. If someone accesses my network that I did not authorize, I want to file charges. These wireless APs don't come with a big disclaimer on the box saying "this may open your network to unauthorized access, potentially sharing your internet connection and network services to others in range." Do you really think the end users are at fault for this?
Logged
Put that in your pipe and grep it!
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #35 on:
December 09, 2011, 01:56:06 PM »
Quote from: eth3real on December 09, 2011, 12:43:35 PM
I agree that unknowing end-users of wireless routers should be protected from just not knowing any better. I don't believe that this law is efficient in protecting those people, as most people don't know the law exists, nor would the owners of the network even realize that such an event took place.
I think these people
should
have protected networks, because I don't think it's right that they're just open to anybody use their networks like we're discussing. I definitely don't agree with people legitimizing it "because it was open." I don't believe that the owners of open wireless networks are at fault for this. It is simply easier (in most cases) to leave it alone once it's working, as most people who are not technical would be afraid of messing it up if they change anything. That's not their fault; it should be easier to make it secure than easier to leave it open.
Hardware manufacturer's are not required to make the interface easy for people to use, or make the interface enforce any kind of security standards. Maybe that's what needs to change, but I believe the current laws are fine where they are.
You keep saying that the laws are inconsistent, but comparing it to a website is not a fair comparison. Wifi has a finite range, and it is easier to make it open than secure. If you made an open website on the internet, you had to go through the trouble of making it open on the internet, which can be accessed by the entire world. Not a fair comparison by a longshot.
This is one of those laws that has good intentions, but very little effect in practice. Now that you know you're "not allowed" to connect to open access points, doesn't mean that there is anyone enforcing that law. If you go 5 mph over the speed limit, you are still breaking the law. Is anyone going to give you a citation for it? Probably not. Did you still knowingly break that law? Yes.
It is their fault for not knowing any better. This isn't someone tech savvy tricking a user like with hacking; the users are notified their network is open. I don't know anything about cars, but if I choose to ignore an engine light, like someone does when configuring their AP or connecting to it, and say "well my car is working so I'm not worried about it" that's my fault when something goes wrong. They configured the AP, they see the notification it's not secure, it should be assumed it was intended to be public like other open APs, and websites.
As for a website being an unfair comparison, it isn't. The wifi range has nothing to do with it. Also, websites, just like APs, and anything else, are easier to keep open than restricted. As I've said, you could create a website you want public and have a page you don't want public. Regardless of the reason, if you do nothing to limit access to the page, it's you own fault. People aren't criminals for clicking the link.
I don't want anyone connecting to my AP either. That's why I took measures to restrict access. Something anyone can do. If they can't, there is the manual, google, message boards, free tech support, they could have a friend do it, or pay someone to do it. Lots of options and no excuses for no security.
Quote
My entire point of this, is that we
need
some kind of protection against attacks like this. If someone accesses my network that I did not authorize, I want to file charges. These wireless APs don't come with a big disclaimer on the box saying "this may open your network to unauthorized access, potentially sharing your internet connection and network services to others in range." Do you really think the end users are at fault for this?
I definitely want anyone who attacks a computer to go to jail, but at the same time I don't consider grandmas across the country making one click as blackhats who need to be jailed for violating the Computer Fraud and Abuse Act...
«
Last Edit: December 09, 2011, 02:34:59 PM by Eleven
»
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #36 on:
December 09, 2011, 02:51:08 PM »
How about this:
You didn't know that it was illegal to access an unauthorized network.
The people running open wireless networks don't know that wireless security is something to consider.
By your logic, you would be at fault for not knowing the law. You could have read up on the local laws and known better because that information is open to the public. You could have found it online, gone to a local library, etc..
If people don't know it's a problem, how are they going to fix it? Are you going to be the one to inform the public that their access points need to be secure? Are
really
saying that leaving your access point unprotected that you're giving people an
invitation
to access it?
Let me ask you this, if you disagree with the law, what would you do to change it?
If you think everyone should know better with their access points, how would you go about educating them?
People obviously aren't reading the instruction manuals that come with their products, and people obviously aren't reading the laws for their area. What can you do about it?
Logged
Put that in your pipe and grep it!
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #37 on:
December 09, 2011, 02:54:44 PM »
You keep complaining about it like you're offended, but you're not offering any solutions? Try to help us out here. You have such a strong opinion about it, yet you're making no effort to improve the situation.
Logged
Put that in your pipe and grep it!
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #38 on:
December 09, 2011, 02:57:25 PM »
This is still going?
Logged
CCENT, A+, Network+, Security+
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #39 on:
December 09, 2011, 03:15:07 PM »
Eleven, just for clarification:
Yes, the law implies that connecting to someone else's open wireless network is a violation. But, the reality is, who could ever enforce this law? With so many open wireless networks, and so many laptops, smartphones, etc. utilizing wireless networks, how could anyone police this? "Grandmas across the country" are not going to jail for this. Seriously.
You came here to ask:
When is using an open wifi network a crime?
The answer, written in law, is:
Whenever you don't have permission.
End of story.
Logged
Put that in your pipe and grep it!
El33tsamurai
Full Member
Offline
Posts: 192
Re: When is using an open wifi network a crime?
«
Reply #40 on:
December 09, 2011, 03:20:56 PM »
Claps hands for eth3real
Logged
CCENT, A+, Network+, Security+
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #41 on:
December 09, 2011, 03:24:42 PM »
Quote from: eth3real on December 09, 2011, 02:51:08 PM
How about this:
You didn't know that it was illegal to access an unauthorized network.
The people running open wireless networks don't know that wireless security is something to consider.
By your logic, you would be at fault for not knowing the law. You could have read up on the local laws and known better because that information is open to the public. You could have found it online, gone to a local library, etc..
If people don't know it's a problem, how are they going to fix it? Are you going to be the one to inform the public that their access points need to be secure? Are
really
saying that leaving your access point unprotected that you're giving people an
invitation
to access it?
Let me ask you this, if you disagree with the law, what would you do to change it?
If you think everyone should know better with their access points, how would you go about educating them?
People obviously aren't reading the instruction manuals that come with their products, and people obviously aren't reading the laws for their area. What can you do about it?
It's not okay to be ignorant of the law, but it is okay to be ignorant and negligent when it comes to security? Not many people get legal notice that accessing an open wifi network is illegal without explicit authorization, yet the people who have open wifi ARE notified it's open and not secure. I understand it is illegal, I'm saying the law is also illogical.
The computer illiterate owners of open APs are not just "victims." Their negligence should also make them liable for crime when their wifi service is abused. There is a big difference between due care and diligence and absolutely no security. The latter is definitely negligent.
Criminalizing the clients for using an open AP without malice, but not the AP owners for being negligent, doesn't make much sense. If one is a crime, the other probably should be too. Which is worse? Using an open AP to surf the web, or having your open AP be used to anonymously manage a 100,000 node botnet? I'm sure if the police were aware of both situations, the guy who surfed the web would go to jail, yet the grandpa who configured the open AP being used to manage Zeus would get off scott free.
Logged
Eleven
Full Member
Offline
Posts: 120
Re: When is using an open wifi network a crime?
«
Reply #42 on:
December 09, 2011, 03:29:43 PM »
Quote from: eth3real on December 09, 2011, 03:15:07 PM
Eleven, just for clarification:
Yes, the law implies that connecting to someone else's open wireless network is a violation. But, the reality is, who could ever enforce this law? With so many open wireless networks, and so many laptops, smartphones, etc. utilizing wireless networks, how could anyone police this? "Grandmas across the country" are not going to jail for this. Seriously.
You came here to ask:
When is using an open wifi network a crime?
The answer, written in law, is:
Whenever you don't have permission.
End of story.
I guess you're right, my question was answered... thanks!
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: When is using an open wifi network a crime?
«
Reply #43 on:
December 09, 2011, 03:31:59 PM »
If we criminalized people for being negligent, we wouldn't have jobs in IT/security.
Logged
Put that in your pipe and grep it!
3xban
Hero Member
Offline
Posts: 605
Re: When is using an open wifi network a crime?
«
Reply #44 on:
December 09, 2011, 07:56:41 PM »
Part of me said to leave this thread to die. But here is one other factor one should take into account before putting on their gray hat and using someone else's WiFi....
Lets say you are using it to do some "other" security research and you don't bother to anonymize yourself. Well now your neighbor's IP gets logged while you are "testing" a website or downloading some malware "samples." Lets say that site was actually a government site and maybe not our government. they intern start launching attacks on your neighbor and their system is compromised. Next thing you know they are calling all their credit card companies and banks to file identity theft reports. Or one more, someone uses their computer to hide child porn and some local law enforcement or fed track it down. Lots of bad things happen because you felt that their "open" WiFi was an invitation for free internet.
As ethical hackers, we have to look past the open doors and windows and take it upon ourselves to tell the owners to close them when we find them. Regardless if there is a law to protect them or not. I am sure a savvy lawyer could get such a case thrown out in court by stating "Well they didn't say NOT to use the open WiFi" and state that such signage wasn't present.
Anyway just another way to think aside from the laws.
Logged
Certs: GCWN
(@)Dewser
Pages:
1
2
[
3
]
4
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.