Open 802.11 networks and ethics

CommuniCat

Active Member
Joined
Feb 9, 2004
Messages
50
Reaction score
0
Location
South Africa.
I've just taken deliver of a shiny new Nokia 9300i phone which I'd like to download email while out of the office.

Now I'm no wardriver - but I did test to see what networks were available whilst driving around today. They are everywhere - and more than most are completely open with no sign of any security at all.

This either means that most people with wireless networks are a friendly bunch who openly invite you to use their net connection to download email while on the road, or, what is more likely, that they are completely technically inept and have no clue about network security.

Now I feel feathers for the law about not connecting over a street or to another business - that crazy law needs a Ghandi and a bag of salt. But I do care about doing something which harms another net user.

I have spare capacity on my ADSL accounts and would be more than happy to share with someone who wants to get their email if they happen to drive past my office. But my network is WEP enabled for other secuirty reasons - not to stop the occasional user using a bit of my surplus bandwidth. I have offered my neighbour some connectivity - and would be happy to activate a wireless card if he wants to.

Of course, that may just be me.

On the other hand, if you are going to be fussy about people using your bandwidth - then at least have half a brain and lock it down.

So what are the ethics here:

1. Sorry for you. Using another person's bandwidth is theft plain and simple. You don't take money from an empty table simply because it's sitting there all alone and unattended do you? And no, just because the money is on the table does not mean that the original owner of the money wants you to take it either.

2. Go ahead. What a rediculous analogy about money on a table! This is a completely different scenario. Those that have open wireless networks know that someone may need a bit of bandwidth. They too are tired of being ripped off by both Telkom and the cellular networks. It's their friendly service to society. You use his network today and he will use yours tomorrow. If the network is open it means that they subscribe to an open bandwidth philosophy of sharing. If they don't want to share the bandwidth they can simply lock it down. No harm done.
 
CommuniCat said:
I've just taken deliver of a shiny new Nokia 9300i phone which I'd like to download email while out of the office.

Now I'm no wardriver - but I did test to see what networks were available whilst driving around today. They are everywhere - and more than most are completely open with no sign of any security at all.

This either means that most people with wireless networks are a friendly bunch who openly invite you to use their net connection to download email while on the road, or, what is more likely, that they are completely technically inept and have no clue about network security.

Now I feel feathers for the law about not connecting over a street or to another business - that crazy law needs a Ghandi and a bag of salt. But I do care about doing something which harms another net user.

I have spare capacity on my ADSL accounts and would be more than happy to share with someone who wants to get their email if they happen to drive past my office. But my network is WEP enabled for other secuirty reasons - not to stop the occasional user using a bit of my surplus bandwidth. I have offered my neighbour some connectivity - and would be happy to activate a wireless card if he wants to.

Of course, that may just be me.

On the other hand, if you are going to be fussy about people using your bandwidth - then at least have half a brain and lock it down.

So what are the ethics here:

1. Sorry for you. Using another person's bandwidth is theft plain and simple. You don't take money from an empty table simply because it's sitting there all alone and unattended do you? And no, just because the money is on the table does not mean that the original owner of the money wants you to take it either.

2. Go ahead. What a rediculous analogy about money on a table! This is a completely different scenario. Those that have open wireless networks know that someone may need a bit of bandwidth. They too are tired of being ripped off by both Telkom and the cellular networks. It's their friendly service to society. You use his network today and he will use yours tomorrow. If the network is open it means that they subscribe to an open bandwidth philosophy of sharing. If they don't want to share the bandwidth they can simply lock it down. No harm done.

Definatly depends on your morals. I mean you could be nailing this persons cap and he uses the internet for his business, then the next minute he could loose all his money due to communication problems. I think that many people who have wireless networks are not aware of security and that people can even get in to their networks. I know that if someone did it to me I would be really pissed off!
 
I've been using three open networks in my area for over six months now. To date none of them have enven tried to secure their wireless networks.
 
Just because I leave my front door open does not mean you can come into my house from the street uninvited and eat my food or sleep in my bed :)

What kind of ridiculous notion is that an unsecured WiFi implies that people want to share their paid connection for free ???.

You are stealing ... it is as simple as that.
 
CommuniCat, I would do more than just wep, maybe mac filtering also ...
wep is easily cracked / hacked ... i do think that users with wifi equipment need training ... but who?
The bloke who sold it to them, or maybe the IntelliGent forum posters can put a generic howto together? and we all promote said howto whereever we go.
 
You are right - also have Mac filtering. In fact it's way easier to connect with my phone to some other poor saps open network down the street than it is to connect to my own! Setting up Mac addresses in AP . . . trying to get the right settings in Nokia phone (what's with the odd "40" bits anyway?).

Eventually I got it right on my own network. But the world's networks are simply left right open!

From an ethical perspective surely it must be stealing, plain and simple. From a legal perspective, however, I'm really not so sure.

Consider the following scenario:

Let's say I know nothing about networks and phones (which isn't too far from the truth heh heh). I'm sitting in my client's office and decide to go and collect my mail. Sure enough my phone goes off and finds a whole lot of available networks. Now I know nothing about GPRS or 3G or any other kind of "network". It's simply all Greek to me.

All I know is that my IT guy told me to use my own wireless network called "Belkin" or "Netgear" at my office. Strange thing is I also find a "Belkin" or a "Netgear" network at my client's office. "This clever technology today" I think. "See, it's even found me at my clients office 25km away."

So on I hop to this network and download all my mail, and maybe a few MP3s for good measure while I work.

The fact that this open "Belkin" or "Netgear" access point actually belongs to someone other than myself or my client never occurs to me. All I'm doing is what I'm told to do - use a "Belkin" or "Netgear" network.

I'll bet this kind of thing happens all the time.
 
Well I just got my wireless card, and walking around my area I am able to pick up about 10 wireless networks - of which about 5/6 have no WEP. Yes I am going to try it out and see if I can get in, but im not going to use up all their bandwidth. It might be a different story if I could actually get signal in my room
 
I went walking around now, found 21 AP's and 13 had no security. I logged in to one and was getting 70kb/s. Found the router and the login was even default.
 
CommuniCat said:
Now I'm no wardriver - but I did test to see what networks were available whilst driving around today. They are everywhere - and more than most are completely open with no sign of any security at all.

This either means that most people with wireless networks are a friendly bunch who openly invite you to use their net connection to download email while on the road, or, what is more likely, that they are completely technically inept and have no clue about network security.

Yes more then half of all wireless APs have not sort of encryption on then. about 2-3% have the defaults still enabled eg. password and SSID

I have asked myself the question. Do these people need to/want to encrypt their networks?

I personally dont care if someone reads my email as it flies past them on the wireless waves. I have nothing to hide. If i did then i would encrypt and start taking all sorts of measure while using the net. The only thing I worry about is when money is involved. the great thing is.. is that when i use the bank's website it is encypted so i have very little to worry about.

but to answer your question. I think very very few people leave their APs open for strangers to collect their email. Personally I would do the same if I had an internet connection to share.

Is it right to steal bandwidth? no! plain and simple.
even if it is to collect your email. but hey I would still use someones AP to do it, but i would not abuse their bandwidth.

at the end of the day it is the morals and ethics of the person taking advantage of the open AP.
 
Heres a better idea.

Get yourself a Boingo.com account
Go crazy at all those Wireless-G AP's all over the place. Its alot cheaper than actually buying time from Wireless-G.
 
Not all those networks are open...

I don't secure my home network with WPA or WEB, for a whole host of reasons... instead all I do is block all mac addresses connecting to my network, other than those on my allow list.

I know my traffic is not encrypted and all that (not conserned). But my point is, my network appears unsecure, but you cannot connect to it and steal my bandwidth.

Also re that other analogy... I think that from a legal / ethical point of view, most people would view that as an honest mistake... kinda like using some else's phone because you mistake it for your own.
 
Spoofing MAC addresses is rather trivial, so this "security through obscurity" approach might not be your best option. Cracking WEP keys is also trivial if the network is rather busy.

The most secure option imho would be to build individual IPSEC tunnels to each wireless device, a bit of an overkill I know, but it will satisfy the truly paranoid. So far WPA/WPA2 has had good results, but only untill it's weaknesses are discovered. IPSEC is tried and tested.
 
Last edited:
twiga said:
Spoofing MAC addresses is rather trivial, so this "security through obscurity" approach might not be your best option. Cracking WEP keys is also trivial if the network is rather busy.

The most secure option imho would be to build individual IPSEC tunnels to each wireless device, a bit of an overkill I know, but it will satisfy the truly paranoid. So far WPA/WPA2 has had good results, but only untill it's weaknesses are discovered. IPSEC is tried and tested.

Yes of course, if you know which MAC's are acceped on the AP... but I was talking about my home network here... Security is really not a big issue... I was actually trying to make the point, that although a network shows up as unsecure, you may not be able to just connect to it.
 
This may be a bit off topic, but just wanted to mention this.

I got a laptop recently, first time I've had wireless network, so decided to drive around my area looking for my wireless networks. So a friend and I drove around my area for almost 30mins, and I did not detect ONE wireless network.

Now I'm pretty sure my laptop is set up right, it's just pretty strange. I drove through rich resedential areas and not even a trace of a wireless network. Is this even possible? Or is it perhaps something wrong on my laptop?

I've never actually used it to connect to a wireless AP before, so not sure if that works, but it should work fine.

Also got another question was reading that overseas wardriving isn't illegal, well obviously unless you take advantage of an "open" wireless network and take bandwidth, since that is stealing. Is it the same here in SA? I assume it is, since I can't see what's illegal about detecting wireless networks.
 
Azgard said:
This may be a bit off topic, but just wanted to mention this.

I got a laptop recently, first time I've had wireless network, so decided to drive around my area looking for my wireless networks. So a friend and I drove around my area for almost 30mins, and I did not detect ONE wireless network.

Now I'm pretty sure my laptop is set up right, it's just pretty strange. I drove through rich resedential areas and not even a trace of a wireless network. Is this even possible? Or is it perhaps something wrong on my laptop?

I've never actually used it to connect to a wireless AP before, so not sure if that works, but it should work fine.

Also got another question was reading that overseas wardriving isn't illegal, well obviously unless you take advantage of an "open" wireless network and take bandwidth, since that is stealing. Is it the same here in SA? I assume it is, since I can't see what's illegal about detecting wireless networks.

Pretty sure your laptop's setup wrong or has a really weak aerial... I always see a number of networks irrelevant of where I am.

I'm not sure about war driving... however the current telecom's act states that it's illegal to broadcast 802.11x over a public domain, especially over a public road.

So connecting to thier network from down the road you're effectively forcing them to break the law :P :eek: :cool:

But nah, I seriously doubt war driving is illegal.
 
Pretty sure your laptop's setup wrong or has a really weak aerial... I always see a number of networks irrelevant of where I am.

Hmm.. basically how would I make sure the wireless is working? I turn the "wireless" switch on the laptop on, make sure it's enabled. Anything else special. Oh I was trying using Net Stumbler. But I have tried refreshing the wireless neworks in Windows but still get nothing.

Hope it's not a weak aerial, since I can't connect an external one.

I'm not sure about war driving... however the current telecom's act states that it's illegal to broadcast 802.11x over a public domain, especially over a public road.

So connecting to thier network from down the road you're effectively forcing them to break the law :P

But nah, I seriously doubt war driving is illegal.

Well that's good to know. Never knew you could force someone to break the law. But suppose then you are breaking the law yourself.
 
Top
Sign up to the MyBroadband newsletter
X