Jump to content

Recommended Posts

Posted

The thing that made me laugh is that, Paul their knowitall super hacker, kept referring to a wireless router as an "internet server". The mark is not running a web server you muppet!!!.

 

Anyway the program does show a genuine problem. Can your average teacher really setup WPA-PSK let alone a RADIUS box. All remote access solutions should be based on SSL or IPSec.

Posted

Radius Authentication at work is on my to-do list too... i have just set my WiFi up as WEP at work cause its the lowest common denominator for clients since not all my WiFi clients support WPA.. most do but not all!!!

 

though at home i use WEP128 cause my cisco 340AP only does WEP :-( ..at a super fast 11Mbps as well... does that mean that some one can hack me in 1 minute........

 

Lol...

Posted
@K-strider - As its Cisco you will find that it will eat and loose packets that they are trying to steal :D Certainly a friend of mines Cisco seems to loose and eat packets at random, so much so we call it Pacman :D
Posted
I have my Access Point open deliberatly. That way, when the BPI comes knocking with the court summons I can say "It wasn't me, it was that guy in the white van outside!".
Posted
I have my Access Point open deliberatly. That way, when the BPI comes knocking with the court summons I can say "It wasn't me, it was that guy in the white van outside!".

 

This wont wash nowadays somthing its now your responsability, its like leaving you keys in your car and saying i do not know why it was robbed.

Posted

Indeed. WEP is less than useful as an actual security measure. A few friends went through 3 years of UNI without paying for broadband :)

 

One enterprising one had 4 hackable networks overlapping his student house and built a linux box from an old pharmacy PC to loadbalance across them.

 

In school I use WPA2, Macrfiltering or a combination of both depending on the area of the school.

Posted
This wont wash nowadays somthing its now your responsability

 

So I'm guilty until proven inoccent am I? I have 5 machines behind my router. Owned by various adult members of my household. I also have an access point anyone outside in the street is free to use. Exactly how is the supposed to prove which machine did it?

Posted
But surely Geoff if it's your equipment, and someone has performed a criminal act through it, the law will hold you partly responsible if you provided the gateway.
Posted
If it was criminal law yes, it would come under 'aiding and abeting', but it's not. Copyright infringment is a civil offence. So I'm not liable, exactly the same way as my ISP isn't. Of course they can request information from me to aid in their prosecution, but as I rotate my log files after a week there wouldn't be anything to provide.
Posted
@Geoff: So what if a criminal act is commited? For instance if your gateway is used to facilitate the theft of funds from somebody's bank account or similar?
Posted
Copyright infringment is a civil offence.
For now. I'm sure the Pigopolists will force our Gov to change that, in the same sort of way they are going after AllofMP3. :x
Posted
So what if a criminal act is commited? For instance if your gateway is used to facilitate the theft of funds from somebody's bank account or similar?

 

Well, again, turning over my logs would probably be a start. But I'd expect to have my equipment seized. Not that that helps, it's all running disk encryption.

Posted
So what if a criminal act is commited? For instance if your gateway is used to facilitate the theft of funds from somebody's bank account or similar?

 

I'd have to turn over my equipment.

 

And if your equipment allowed the access - even if they can't find it to be your computer(s) - are you legally accountable?

 

In a similar vein, if school equipment was used by a 3rd party do perform criminal activity would the school (and RBC since Internet connection is provided by them) be responsible in that instance?

Posted

It is usually classed as 'going equipped' or 'aiding and abbetting', both of which are criminal offences.

 

Ignorance is no defence against the law and with Geoff's job the CPS would have reasonable grounds to presume that he has prior knowledge that the system he has setup would allow it to be abused and allow people to commit criminal offences.

 

It is a dangerous line to walk and if you think that the open network could not only be used for file sharers to download MP3s, but also to allow people to access and pull down child porn, information about committing other serious criminal acts ...

 

People who don't know any better will get sympathy from me ... people who should know better get none ...

Posted
It is a dangerous line to walk and if you think that the open network could not only be used for file sharers to download MP3s, but also to allow people to access and pull down child porn, information about committing other serious criminal acts ...

 

*watches Grumbledook trigger 21st century equivalent of Godwins Law*

 

:)

 

But how is that different from someone doing all of the above with a standard ISP? How is it different from someone going into a coffee shop and using their wireless router to do the same? Like the ISP and coffee shop, Geoff isn't responsible for the content his neighbours download using his free wifi.

 

He _may_ (or may not) be in breach of his ISPs t&cs by sharing their bandwidth publicly, but that's another thing entirely.

Posted

The difference is intent. You've never come across an ISP which tacility encouraged copyright infringement especially on a public forum. Has any such ISP also said it will actively remove evidence of illegal acts to frustrate any likely court action.

 

But this is probably all hypothetical. Geoff's not his real name anyway ;)

Posted

Most people don't realise that Geoff isn't even a real person but a very well programmed AI system used by the Govt to test us all ...

 

And yes ... one of the differences is intent ... another is the T&Cs ... if Geoff was to implement T&Cs with everyone connecting via the 'open' AP then he would be covered to a large extent.

Posted
He _may_ (or may not) be in breach of his ISPs t&cs by sharing their bandwidth publicly, but that's another thing entirely.

 

Just to clarify this point. I only breach the T&C's of my ISP if I charge for the connection.

 

if Geoff was to implement T&Cs with everyone connecting via the 'open' AP then he would be covered to a large extent.

 

Indeed. The wifi AP is running as a captive portal. The only T&C's I inist on are 'Don't be stupid'.

Posted
if Geoff was to implement T&Cs with everyone connecting via the 'open' AP then he would be covered to a large extent.

 

Indeed. The wifi AP is running as a captive portal. The only T&C's I inist on are 'Don't be stupid'.

 

Getting better ... but stll not enough ... you have expert knowledge of what constitutes 'stupid' and you have not shown that this is conveyed to your users ... you still have a responsibility to do so.

 

Some as simple as forcing their home page to be a page listing the stupid things could be enough ... but still skating on thin ice ...

 

Especially when you consider one of those stupid things could be accessing paedophilic materials, information on bomb making and a heap of other things that the govt doesn't track.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...