pen-test
[Top] [All Lists]

Re: Legality of WEP Cracking

Subject: Re: Legality of WEP Cracking
From: Nick Selby <nick.selby@the451group.com>
Date: Mon, 28 May 2007 08:24:27 +0200
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <20070528000923.25223.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Organization: The 451 Group
References: <20070528000923.25223.qmail@securityfocus.com>
Resent-date: Tue, 29 May 2007 19:25:57 -0600 (MDT)
Resent-from: pen-test-return-1078484269@securityfocus.com
Resent-message-id: <20070530012557.3065B143ABB@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.10 (X11/20070403)
Thanks, that's great information! THis has been a really interesting thread - I did agree also with someone else who said, Hey, it's still kind of a cheesy way to do business, and the lawyers I speak with are less convinced than you, but you make great points.

Cheers,
Nick

cwright@bdosyd.com.au wrote:
<snip>Access and authorisation are not the issue. The law is well developed in 
terms of property, license and authorisation. When you claim that it may be difficult 
to prosecute, this is a function of evidence.

In the respect of the law, rules of evidence are also well defined. The issue 
is that of collecting evidence. Being a matter of fact, the nature of the 
evidence is not one that requires a large amount of legal dispute. It does 
however require more than the word of the accuser.

In civil cases, the requirements are lower. In criminal, there is a higher 
hurdle. Either way, there is a duty to collect evidence if you want to persue 
this. The difficultly is that it is not likely that a system running an open 
WEP gateway will have detailed logging and monitoring enabled. You do not need 
to notify the user that they are accessing the system without authority; they 
are not licensed to do so by the nature of the communications.

The law of license is a subset of property and requires a legal technical background 
that I can not extrapolate adequately on this list. </snip>



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>