UK and Europe · Public discussion

OT: Wireless networking and security.

Started by Jon Senior · · Last activity · 37 posts · 1,255 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
UK and Europe
Published
30 January 2005
Last activity
2 February 2005
Original author
Jon Senior
Posts
37
Discussion status
Public discussion
Total views
1,255
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–20 of 37
Posts remain in their original chronological order.

Text size
  1. I have internet access again! In advance of my move to the flat next to
    a friend and our corresponding wireless shared internet connection, I
    set up one of the wireless bridges today. Once configured, I scanned the
    local airwaves and found two wireless networks within reach, one
    implements the WEP encryption, the other appears to be a wireless router
    with all its default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have access
    to the net.

    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter, but
    I feel I should get in touch with the owner and at the least, offer to
    subsidise his connection for a month and lock down the security a little
    better.

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities.

    Jon (The possibly immoral!)

  2. Jon Senior said:

    I have internet access again! In advance of my move to the flat next to
    a friend and our corresponding wireless shared internet connection, I
    set up one of the wireless bridges today. Once configured, I scanned the
    local airwaves and found two wireless networks within reach, one
    implements the WEP encryption, the other appears to be a wireless router
    with all its default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have access
    to the net.

    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter, but
    I feel I should get in touch with the owner and at the least, offer to
    subsidise his connection for a month and lock down the security a little
    better.

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities.

    Jon (The possibly immoral!)

    You raise some interesting points Jon. I assume you think its morally
    wrong since you bring it up. Bandwidth theft. Since you are about to
    move out anyway why bother doing anything. Just ignore you find and
    you'll be breaking no moral codes or continuing exploiting this persons
    gift. I'd do the former because its the right thing to do. I know of no
    way with ordinary equipment of finding out where the access point is
    location and hence the owner. Can you get onto the console ? You'll have
    to try to guess the password. Maybe then you can make a change to alert
    the owner that his network is wide open.

    Or you could learn some war chalking marks and inform the rest of the
    community.

  3. Jon Senior said:

    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter,

    That is a very dodgy justification. The phrases 'she was asking for it
    wearing clothes like that.", "it was your own fault for not being in a
    car", and so on.. Victim blaming is still indefensible no matter how you
    look at it. (That doesn't stop a victim being naive or being able to
    avoid being a victim).

    ...d

  4. "Jon Senior" <jon_AT_restlesslemon_DOT_co_DOT_uk> wrote in message
    news:[email hidden]...

    Quoted message said:

    I have internet access again! In advance of my move to the flat next to a
    friend and our corresponding wireless shared internet connection, I set up
    one of the wireless bridges today. Once configured, I scanned the local
    airwaves and found two wireless networks within reach, one implements the
    WEP encryption, the other appears to be a wireless router with all its
    default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have access to
    the net.

    So; morally or legally, what is the stance on this one.

    Its illegal, you could be imprisoned.

    --
    Tumbleweed

    email replies not necessary but to contact use;
    tumbleweednews at hotmail dot com

  5. Jon Senior said:

    So; morally or legally, what is the stance on this one.

    So long as you don't hog the bandwidth, I don't see why you should worry
    about it. I presume it is technically against some law on authorised use
    of computer equipment, but we found our neighbour's generosity similarly
    useful when setting up our own wireless network :-)

    James
    --
    If I have seen further than others, it is
    by treading on the toes of giants.
    http://www.ne.jp/asahi/julesandjames/home/

  6. In message <[email hidden]>, MSeries
    <[email hidden]> writes

    Quoted message said:
    Jon Senior said:

    I have internet access again! In advance of my move to the flat next
    to a friend and our corresponding wireless shared internet
    connection, I set up one of the wireless bridges today. Once
    configured, I scanned the local airwaves and found two wireless
    networks within reach, one implements the WEP encryption, the other
    appears to be a wireless router with all its default settings (SSID = default).
    I pointed my wireless bridge at this router and presto... I have
    access to the net.
    So; morally or legally, what is the stance on this one.

    Quoted message said:

    Can you get onto the console ? You'll have to try to guess the
    password. Maybe then you can make a change to alert the owner that his
    network is wide open.

    Well, it probably is illegal, though I know of no case, and if no 'harm'
    was done I think you'd find it hard to interest your local bobbies very
    much.

    I think someone round here got a new wireless AP at xmas, as after that
    I sometimes got it come up as an available network.

    It appeared to be on the default settings, I was able to use the
    connection with no problem, and it wasn't hard to workout the default
    password to access the admin for the device (though I guess goggle would
    help here)

    I did wonder at changing the password to alert them, but never got round
    to it. and it doesn't seem to appear any more.
    --
    Chris French, Leeds

  7. Jon Senior said:


    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities

    Try the Consume website http://www.consume.net
    (it is down at the moment)

    Not sure how Consume is doing at the moment, but this is a community
    wireless network, with a map of open access points which
    people have made available.
    Of course, there is life outside London and I would imagine Consume
    has links on the site to other community wireless projects.

  8. Jon Senior said:

    I have internet access again! In advance of my move to the flat next to
    a friend and our corresponding wireless shared internet connection, I
    set up one of the wireless bridges today. Once configured, I scanned the
    local airwaves and found two wireless networks within reach, one
    implements the WEP encryption, the other appears to be a wireless router
    with all its default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have access
    to the net.

    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter, but
    I feel I should get in touch with the owner and at the least, offer to
    subsidise his connection for a month and lock down the security a little
    better.

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities.

    Jon (The possibly immoral!)

    Legally you are on dodgy ground. Under the Misuse of Computers Act 1990
    it is an offence unless you are either the owner of the connection or
    have been specifically authorised by the owner of the connection.

    Morally in these days where many people are on PAYG and capped
    connections your usage could well be costing them money. Yes they left
    the front door open but that doesn't make it right to take the money off
    their sideboard. Either locate them and make an arrangement (although
    that is probably contrary to their ISP's T&C's) or get your own connection.

    If you own a connection enable the access security, restrict access to
    defined MAC addresses and you should be safe.

    Tony

  9. Jon Senior wrote:
    <snip tale of insecure wi-fi>

    Quoted message said:


    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range
    of 300m, there are a large number of possibilities.


    perhaps the simplest method, but one that drops you further into a moral
    quagmire, is to use a packet sniffer on the traffic until you find their
    email address, then drop them a line. However, the fact you've been
    (potentially) reading their email may mean you get a thump on the nose
    rather than their their gratitude for offering to fix their security
    faux-pas!

    Colin

  10. Tony Raven said:

    Legally you are on dodgy ground. Under the Misuse of Computers Act 1990
    it is an offence unless you are either the owner of the connection or
    have been specifically authorised by the owner of the connection.

    Morally in these days where many people are on PAYG and capped
    connections your usage could well be costing them money. Yes they left
    the front door open but that doesn't make it right to take the money off
    their sideboard. Either locate them and make an arrangement (although
    that is probably contrary to their ISP's T&C's) or get your own connection.

    That's actually what I'd like to do. The flat that I'll be moving to is
    just up the road from here, so once we have both ends of the link
    up-and-running, I'll probably be able to access that connection instead.

    The owner does appear to have changed the default passwords so I can't
    think of anyway of informing them and I've yet to see another computer
    appear on the WLAN.

    Quoted message said:

    If you own a connection enable the access security, restrict access to
    defined MAC addresses and you should be safe.

    Believe me, I intend to.

    Jon

  11. Jon Senior said:


    The owner does appear to have changed the default passwords so I can't
    think of anyway of informing them and I've yet to see another computer
    appear on the WLAN.

    First they are likely to be within 100ft of you which limits the search.
    Second get a programme like Netstumbler that gives you a signals
    strength indicator. Wander around with your laptop and with a bit of
    turning and walking you should be able to pinpoint pretty well in which
    direction the wireless router is located. If you can do it from two
    directions so much the better and you can triangulate the owner.
    Netstumbler is worth having anyway if you set up your own wireless
    network as you can use it to optimise the aerial position and
    orientation for your room layout.

    Finally you could try either pinging other IP addresses round that of
    the gateway and try setting up a link with any other computers you find
    Or you could go to http://www.grc.com and it will most likely give you
    an IP address. Put that into http://www.geektools.com/whois.php and it
    should give you the details of the ISP. Simply e-mail the contact
    asking them to contact the owner and alert them. They will be able to
    trace your e-mail back to the account owner and its then up to them.

    Beware of the suggestion of sniffing and reading the owners traffic.
    That really does take you into legal territory you do not want to be in.

    Tony

  12. Jon Senior said:

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network?

    Worth trying email to [email hidden]

    Given a potential range of

    Quoted message said:

    300m, there are a large number of possibilities.

    I'd be sceptical about that range. My own wireless equipment doesn't
    work at 100, let alone 300m once you have real-life objects like houses.
    It may be possible, but it's likely to be much nearer. Does your wlan
    card indicate what signal strength it's got?

    --
    Nick Kew

  13. in message <[email hidden]>, Jon Senior

    jon_AT_restlesslemon_DOT_co_DOT_uk ('') said:

    I have internet access again! In advance of my move to the flat next
    to a friend and our corresponding wireless shared internet connection,
    I set up one of the wireless bridges today. Once configured, I scanned
    the local airwaves and found two wireless networks within reach, one
    implements the WEP encryption, the other appears to be a wireless
    router with all its default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have
    access to the net.

    I run an 802.11b network in the house; it's actually inside our
    firewall. Originally I was very paranoid about security on it, but as
    this made life exceedingly difficult when visitors wanted to use their
    computers I've now greatly relaxed the security.

    Quoted message said:

    So; morally or legally, what is the stance on this one.

    H'mmm... I'd not be nearly so bothered about people stealing some
    bandwidth as people being able to see the network from inside the
    defences. If I logged anyone we hadn't authorised using the network my
    probable response would be to switch the 802.11b transceiver to outside
    the firewall. I don't think I'd tighten the security of the WiFi itself
    - it would be just too much hassle.

    Quoted message said:

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities.

    The range isn't anything like that in practice. We have a booster
    aerial, but even so the reception is pretty poor in the wings of the
    house and disappears entirely 20 yards down the garden.

    --
    [email hidden] (Simon Brooke) http://www.jasmine.org.uk/~simon/

    ;; ... exposing the violence incoherent in the system...

  14. in message <[email hidden]>, David Martin

    (') said:
    Jon Senior said:

    So; morally or legally, what is the stance on this one. The cynic in
    me would have it that a door left wide open is an invitation to
    enter,

    That is a very dodgy justification. The phrases 'she was asking for it
    wearing clothes like that.", "it was your own fault for not being in a
    car", and so on.. Victim blaming is still indefensible no matter how
    you look at it. (That doesn't stop a victim being naive or being able
    to avoid being a victim).

    I'd go beyond that. I live in a place where doors (of houses or cars)
    are rarely locked outside the tourist season. I really appreciate that.
    The fact that my house is unlocked (as it usually is) is _not_ an
    invitation to come in.

    There isn't something naive about leaving your door unlocked: there's
    something decidedly sick about a community in which dishonesty is so
    widespread that locks are necessary.

    --
    [email hidden] (Simon Brooke) http://www.jasmine.org.uk/~simon/

    ;; When all else fails, read the distractions.

  15. If the owner of this internet connection is on some kind of "pay as you go"
    deal with their ISP, then you might be costing them real money as well as
    the inconvenience of pinching bandwidth.

    Neil

    "James Annan" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:
    Jon Senior said:

    So; morally or legally, what is the stance on this one.

    So long as you don't hog the bandwidth, I don't see why you should worry
    about it. I presume it is technically against some law on authorised use
    of computer equipment, but we found our neighbour's generosity similarly
    useful when setting up our own wireless network :-)

    James
    --
    If I have seen further than others, it is
    by treading on the toes of giants.
    http://www.ne.jp/asahi/julesandjames/home/

  16. Jon Senior said:

    I have internet access again! In advance of my move to the flat next to
    a friend and our corresponding wireless shared internet connection, I
    set up one of the wireless bridges today. Once configured, I scanned the
    local airwaves and found two wireless networks within reach, one
    implements the WEP encryption, the other appears to be a wireless router
    with all its default settings (SSID = default).

    I pointed my wireless bridge at this router and presto... I have access
    to the net.

    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter, but
    I feel I should get in touch with the owner and at the least, offer to
    subsidise his connection for a month and lock down the security a little
    better.

    Without recourse to expensive uni-directional aerials, how exactly do
    you locate the owner of a wireless network? Given a potential range of
    300m, there are a large number of possibilities.

    Jon (The possibly immoral!)


    Assuming you are still located where you were in August when I visited
    why not put a note near your front door with the information you have
    shared here. Chances are the open network belongs to someone in the same
    building.

  17. In article said:


    So; morally or legally, what is the stance on this one. The cynic in me
    would have it that a door left wide open is an invitation to enter

    I think it's morally equivalent to unlocked rather than wide open.
    Face it, if you _really_ thought it was an invitation to a do-it-yourself
    community network, you wouldn't be asking the question here.
    If he's paying for metered bandwidth, I think using it would be morally
    theft. If not, it might be merely rude.
    http://www.hmso.gov.uk/acts/acts1990/Ukpga_19900018_en_2.htm#mdiv1
    defines "Unauthorised access to computer material". I think at least
    some uses of at least some wireless routers might count.

    Quoted message said:

    Without recourse to expensive uni-directional aerials

    You could narrow it down with a very cheap cardboard and tinfoil
    directional aerial (like this section of Pringles tube shaped into a
    parabola: http://www.freeantennas.com/images/llpr4.jpg).
    Just seeing which directions holding a metal baking tray or similar
    blocks the signal could be a start.

  18. Tony Raven <[email hidden]> wrote:

    : Beware of the suggestion of sniffing and reading the owners traffic.
    : That really does take you into legal territory you do not want to be in.

    I do this stuff as a day job. Do not sniff the traffic. That's an offence.
    It may or may not be an offence under the Computer Misuse act to use
    an unsecured AP (since you could try arguing that it was "obviously"
    intended for public use). I wouldn't fancy being the test case myself.

    And just in case those who think it does no harm have their own AP
    left open for all to use, consider what happens when the National
    High Tech crime unit brake your door down at 5am because someone's
    been downloading stuff they shouldn't...

    For tracking it down, any program that gives signal strength will
    work (as Tony suggests), though in practice it can be harder than it
    might seem in theory since the signals bounce around buildings in
    unexpected ways.

    Arthur

    --
    Arthur Clune PGP/GPG Key: http://www.clune.org/pubkey.txt
    It is better to light a candle than to curse the darkness

  19. Arthur Clune said:


    I do this stuff as a day job. Do not sniff the traffic. That's an offence.
    It may or may not be an offence under the Computer Misuse act to use
    an unsecured AP (since you could try arguing that it was "obviously"
    intended for public use). I wouldn't fancy being the test case myself.

    There has been a test case and the arguement was rejected. Not being
    forbidden is not the same as being authorised and under the Act you have
    to be explicitly authorised:

    "the subsection lays down two cumulative requirements of lack of
    authority. The first is the requirement that the relevant person be not
    the person entitled to control the relevant kind of access. The word
    "control" in this context clearly means authorise and forbid. If the
    relevant person is so entitled, then it would be unrealistic to treat
    his access as being unauthorised. The second is that the relevant person
    does not have the consent to secure the relevant kind of access from a
    person entitled to control, i.e. authorise, that access."

    Lord Hobhouse of Woodborough in the judgement of the House of Lord in
    Regina v Bow Street Magistrates Court and Allison 1999 under the Misuse
    of Computers Act 1990.

    Tony

  20. Simon Brooke said:

    H'mmm... I'd not be nearly so bothered about people stealing some
    bandwidth as people being able to see the network from inside the
    defences. If I logged anyone we hadn't authorised using the network my
    probable response would be to switch the 802.11b transceiver to outside
    the firewall. I don't think I'd tighten the security of the WiFi itself
    - it would be just too much hassle.

    Bandwidth theft may be an issue if (As others have suggested) the owner
    of the AP has a capped bandwidth. I like the idea of firewalling on the
    other side of the WiFi link. A damn sight easier to secure than the link
    itself.

    Quoted message said:

    The range isn't anything like that in practice. We have a booster
    aerial, but even so the reception is pretty poor in the wings of the
    house and disappears entirely 20 yards down the garden.

    I live in a tenement flat with reasonably thick walls and yet even the
    more minimal estimates cover a wide range of properties. I'll try
    sticking a notice in the stairwell as suggested and I'll see if the
    other unit can also receive it from 25 houses up the road.

    Jon

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.