University Network Policies and Punishment?
A not-so Anonymous Coward asks: "I'm a student in the dorms at the University of Colorado, where every room is wired with Ethernet. I bought an 802.11b access point and card, and have been using them on the network. 2 days ago, I came home to find out that my network access had been shut off. When I called ITS, they said it was because I was running the access point, and this was against policy. I proceeded to look through CU's site, and read the entire AUP and terms of use. Nowhere in these agreements is any ban on using wireless equipment in-room. When I called back to see when I could get my access turned back on, I was told that the one person that could help me was out sick. So far my access has been off for 2 days and counting, and chances are slim that I'll get it back by Monday, leaving me with a total of 5+ days without access, all for a violation I was unaware of, and had no warning about. Do I have any rights to force them to turn my access on earlier, or do I just sit without access until they get around to helping me?" Now assuming the AP was not completely open to public access, what possible reason is there for such a limitation? Most kids now go to college with laptops, and an AP is probably the best way for them to work (ie, not tied to the wall). My recommendation would be to politely talk to the University IT department? If anyone else has been in similar situations, how did you go about dealing with the University to get your account/email address/network access restored?
As per the AUP you mention:
* ResNet services and wiring may not be modified or extended beyond the area of their intended use. This applies to all network, hardware, computer lab and in-room data jacks.
This one is questionable, since it does (or can) extend use outside the room
* ResNet may not be used to provide the University of Colorado computer services or Internet access to anyone outside of the Residence Halls community for any purposes (other than those in direct support of the academic mission of the University).
Aside from the inherent insecurities in WEP, they may not be sure you
are even using WEP, which would (or certainly could) provide access to
others outside of your residence halls
* The University of Colorado specific or commercially obtained network resources may not be retransmitted outside of the University community.
As per the AUP you mention:
* ResNet services and wiring may not be modified or extended beyond the area of their intended use. This applies to all network, hardware, computer lab and in-room data jacks.
This one is questionable, since it does (or can) extend use outside the room
* ResNet may not be used to provide the University of Colorado computer services or Internet access to anyone outside of the Residence Halls community for any purposes (other than those in direct support of the academic mission of the University).
Aside from the inherent insecurities in WEP, they may not be sure you
are even using WEP, which would (or certainly could) provide access to
others outside of your residence halls
* The University of Colorado specific or commercially obtained network resources may not be retransmitted outside of the University community.
And not being sure about the location or range, this could also apply.
So, frankly, don't gripe. Those terms are designed to be loosely interpreted. Point is, while YOU may not feel you violated any rules, THEY do, and THEY control the access. Perhaps you can get approval now, but if not, just accept it and live with it. Life is unfair.
... set up their own wireless network. Access requires registering your laptop's MAC address, and you can reach the network from just about every classroom and dorm on campus. They require the MAC address to block out non-Drexel folk, as the campus is in the middle of Philly.
The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
...last year, I accidentally did some portscanning (I was getting Samba up and running and forgot the WINS server; OIT's web page didn't have that information readily available. So I scanned the entire 128.119.0.0/16 subnet for a WINS server) and got my ethernet card blacklisted (I was still able to log on to the public machines). I met with OIT and explained to/convinced their netops guys that I wasn't evil. I ended up scoring extra points by being very vigilant from then on about reporting hacking attempts from the university subnet (as OIT's detection systems are mainly designed for external attacks).
So my advice is be contrite, say you'll never do it again; if you want to do it again, ask them first (maybe going UNODIR would work, also). And if there's anything they need help with, don't hesitate to give it.
Remember, netops people have a tendency to be just like you. They've just had to deal with far too many morons who do stupid things while breaking the AUP. As a result, any violations are assumed to be the work of a moron. If you can demonstrate that you know what you're doing and can be trusted running a wireless gateway (stay away from WEP... use end-to-end IPSec), they'll be much more likely to let it slide.