Slashdot Mirror


Schneier Says 'Steal this Wi-Fi'

apolloose noted Bruce Schneier's latest entry on Wired where he talks about insecured wifi networks, and suggests that you Steal this WiFi. Basically, since insecure WiFi is everywhere, why not? You're helping make the world a little better for someone else.

32 of 432 comments (clear)

  1. Yeah, but... by Serenissima · · Score: 5, Funny

    If I opened up my network, anyone could start downloading pirated movies and music and use up all of my bandwidth that I want to use for downloading pirated movies and music!

    --
    Give a man a fire and he'll be warm for a day. But light a man on fire and he'll be warm for the rest of his life.
    1. Re:Yeah, but... by computational+super · · Score: 5, Informative

      What he said was, "If I enabled wireless security on my network and someone hacked it, I would have a far harder time proving my innocence", and I often wonder if he's right. Like you, I'm pretty terrified of the accusation, so my network is locked down as tight as I can get it. I use WPA with a strong password, MAC address filtering, I renumbered the subnet from the default, I set a strong administrator password, and disabled DHCP... and if I can think of anything else I can do to lock it down, I'll probably do it, out of fear that somebody will do something nefarious with it.

      On the other hand, if I do get hacked (somehow), all that work will probably hang me. Couple that with the fact that I have an advanced degree in computer science (which to the average slashdot reader seems to mean I now *nothing* about computers, but would surely impress a jury of my "peers" that I'm impervious to being hacked), and if my network is used against me, I'm getting the death penalty.

      --
      Proud neuron in the Slashdot hivemind since 2002.
    2. Re:Yeah, but... by Connie_Lingus · · Score: 4, Insightful

      jeez...security is great and all that but you sound paranoid as hell. does the word overkill mean anything to you?

      --
      never bring a twinkie to a food fight.
    3. Re:Yeah, but... by fictionpuss · · Score: 5, Funny

      Apparently the words 'wired ethernet' mean nothing to him either.

    4. Re:Yeah, but... by matt_king · · Score: 4, Insightful

      That's actually an erroneous legal idea....if in fact you have shown due diligence in trying to secure your network, and someone gets in, you are less likely to be found at fault. If however the courts can show that you knew the risks and consequences to having your network opened, and you had the means to do it, yet did not, you are much more likely to be held accountable.

    5. Re:Yeah, but... by Tony+Hoyle · · Score: 5, Insightful

      The only effective measure there is the WPA. If a hacker gets through that (and that's *hard*) they can break through the others in a matter of seconds just by sniffing packets.

      All he's doing is making life harder for himself.

  2. Anonymity by N3TW4LK3R · · Score: 4, Insightful

    Why not? For one thing because it would pretty much guarantee total anonymity to everyone online.

    If you want to commit a crime online, it's easy enough to drive your car to the next city, open you laptop and connect to a random open AP.

    And if you were too lazy to do that, you can always say "It wasn't me, someone else connected through MY open AP!"

  3. Beware of strangers bearing gifts by Applekid · · Score: 5, Interesting

    Sure, everyone please use my unsecured local Wi-Fi access point. I'm giving back to the community... ... and the community in turn will have all traffic filtered through a box that will sniff passwords, private keys, you name it.

    So please "steal this Wi-Fi" since I need a few more social security and credit card numbers.

    --
    More Twoson than Cupertino
    1. Re:Beware of strangers bearing gifts by garcia · · Score: 4, Funny

      My public facing wireless AP has a SSID that reads, "I_SNIFF_AND_LOG". I generally find that no one is using my network and instead probably chose to use one of the 8 open "linksysfoo" APs around me.

    2. Re:Beware of strangers bearing gifts by Braino420 · · Score: 4, Informative

      An SSL certificate is fairly cheap to purchase, just by one and operate a man-in-the-middle for all SSL connections. A few tech-savvy might notice, but most won't.
      You purchase an SSL cert from a CA for a single host, so you will have to go through the whole process for each site the user tries to connect to. Not only this, but CAs do, admittedly minimaly, verify that you are who you say you are (depending on how much money you give them). Not only this, but you will not be able to get a cert that says you're, for example, Bank of America. You can always self-sign a cert, but this will alert the user in all modern browsers. On top of all that, if the user does get fooled by your MITM attack, you only get the information that they give you: their username and password. Sure, you can now log in to the site, but I know that if you're signing into BoA for the first time from that location, they ask you one of the security questions (which you do not have). Even if they didn't (or you fooled the user into giving you that information too) and you got access to their account, what are you going to do? You can't just transfer that money to your account without someone finding out who you are, and the accounts only show the last 4 digits of each account number. You can't get that 3 digit number on the back of the card for most online purchases, not to mention that online purchases will also point back to you. I will admit this is all much easier than cracking the 128-bit SSL session.

      All of that means you aren't going to do shit; the payoff just isn't worth it and it's not as easy as some /. posters will have you believe.
      --
      They call me the wookie man, I guess that's what I am
    3. Re:Beware of strangers bearing gifts by Tim+Doran · · Score: 5, Funny

      Brilliant! The tech-savvy will know that means and avoid your WiFi.

      The non-tech savvy will find it ambiguously gross and avoid you, your property, your children, your dog...

    4. Re:Beware of strangers bearing gifts by zymurgyboy · · Score: 4, Funny
      Which to your Average Joe Wifi-thief probably translates to:

      "He snorts coke and has a commercial lumber company."

      Or

      "He has cold, and probably a clogged toilet."

      I'm surprised you don't more traffic.

      --
      If you never make mistakes, it's probably because you're not doing anything.
  4. Yeah! But firmware and software changes would help by presidenteloco · · Score: 5, Interesting



    1. Clients (laptops) default installed wifi software (hint: Steve Jobs are you reading???) need a scanning
    mode which does not waste my time telling me about all the password or mac-address locked wifi
    basestations, and only advises me about open ones.

    2. Basestation/routers need a simple-to-configure mode where they will let others into a separate
    subnet that goes straight out to the Internet but does not see my home computers directly.

    3. (Brain software/mindset change.) Americans need to stop reflexively calling sharing 'stealing'.
    You've been trained into this terminology by those who have already stolen everything and don't
    want you to get it back.

    --

    Where are we going and why are we in a handbasket?
  5. Ethics by analogy by crow · · Score: 4, Insightful

    This is an ethics by analogy situation. Everyone arguing over whether it is right to use unsecured wi-fi connections bases their arguments on analogies, and depending on the analogy, reaches a different conclusion.

    As I see it, if someone left their wi-fi open, then either it was intentional, or they're too clueless to notice (or care) that I'm reading my email.

    1. Re:Ethics by analogy by plague3106 · · Score: 4, Insightful

      Fine. Go to said person and tell them "your network is not secured, so I'm using it to read my mail." Tell me if they care or not then. Seriously, just because someone doesn't know their WiFi is not secured doesn't mean they won't care that you're using. They just don't know.

  6. Re:how do i crack a WEP password? by fastest+fascist · · Score: 4, Funny

    Excuse me? He uses an iMac, therefore he must be used to paying through the nose.

  7. Re:Steal Wi-Fi? by Intron · · Score: 5, Insightful

    I think it's more like bookcrossing You've already paid for it, now you're letting someone else use it. With books, publishers might not like it because they sell fewer books. With wifi, ISPs may sell fewer connections. Either way it's not stealing.

    --
    Intron: the portion of DNA which expresses nothing useful.
  8. "Insecured" Wi-Fi by wcrowe · · Score: 4, Funny

    "Insecure?". Yeah, nobody wants a clingy Wi-Fi.

    --
    Proverbs 21:19
  9. The flaw in Schneire's logic. by Vellmont · · Score: 4, Insightful

    Everything Schneire says is true.. for Bruce Schneire. Not everyone is as adept as he is in configuring a computer to be secure. I'm OK, but I'm likely not vigilant enough to keep everything as secure as it should be (and thus I have WPA encryption on in my wireless network). The vast majority of the public is just plain terrible, and has no clue how to configure their computers to be secure in an open network.

    Securing your wireless network with encryption isn't like flipping a switch, but it's a HELL of a lot easier and more accessible than knowing how to secure each and every device accessible on your network. Having ONE point of entry and configuring that properly is a lot easier to maintain than having multiple, different, changing points that take continued vigilance to remain secure. Is it better to keep each device secure on any network? Sure.. but how many people have the time, patience, knowledge, and ability to do that? Not many.

    --
    AccountKiller
  10. Re:how do i crack a WEP password? by roystgnr · · Score: 5, Insightful

    "Can anyone point me to a simple tutorial on cracking a WEP password?"

    1. Ask your neighbors for permission to connect to their WiFi.
    2. If you get permission, use the password they give you.
    3. If you don't get permission, don't be a dick.

    If someone has their WiFi configured to allow public access, I don't see much problem in making limited (e.g. no hogging bandwidth, nothing that might get them in trouble) use of it. The internet is built on the idea that people set up unattended computers to give automatic electronic permission for total strangers to use them; Slashdot would suck if everyone had to call Rob before they felt they were allowed to use his web server. But finding a hole in someone's security isn't permission, it's just intrusion.

    Even when you see an open access point asking permission isn't a bad idea. It shouldn't be a legal requirement, but it's a nice thing to do, despite involving the frightening prospects of going outside and meeting someone in real life.

  11. He's being an idiot. by Anonymous Coward · · Score: 4, Insightful

    That's just inviting trouble.

    If "Something Bad" were to happen from your IP address, there -will- be a knock at your front door in the early morning. Trust me.

    "Something" happened to my personal email server several years ago, and I had federal agents at my front door at 1am. I don't know what the heck happened - they wouldn't give me any details - but they seized my email server, and every computer in my household, even though their search warrant was only for the server. You don't tell them "no" - all that means is that they wait for the search warrant to be signed, and THEN they wreck your place searching. Much better for everyone involved to be cooperative.

    Cost me thousands of dollars in a retainer fee to a lawyer, I had to take a polygraph exam, and it took almost 2 years to get all my "stuff" back. That was 2 years where I was fearful for my job, worried about keeping my family afloat, worried about just about everything. My wife lost ALL of her graduate school work, and had to re-do most of it to turn in her final portfolio. Talk about miserable.

    And I STILL have no idea what that "Something Bad" was. And it didn't even happen at my house - it happened at my hosting ISP where the email server lived. It didn't matter that *I* didn't do it. I still had MY stuff taken from my, *I* still had to go take the polygraph exam, and *I* was still on the hook for 2 years.

    So yeah - keeping an open wireless network is just ASKING for trouble. If you want to deal with federal agents in the middle of the night, well, be my guest. You can talk the talk about how you'd tell them to go away, and how they'd have no proof, etc. etc., but unless you've been there, you have no idea what you're in for.

    Trust me.

    1. Re:He's being an idiot. by Hatta · · Score: 5, Insightful

      You're being an idiot. You consented to the search without having it signed by a judge, and then you let them take things that weren't on the warrant. You don't have to do either of those. And why the hell did you let them give you a polygraph? Those aren't admissible anywhere because they're absolutely useless for anything.

      The only reason you had no recourse is because you consented. If you made them get the warrant signed and they still took items not listed on the warrant you would have had an excellent case against them.

      --
      Give me Classic Slashdot or give me death!
  12. FON and Co by PhillC · · Score: 5, Interesting

    There are already a number of organisations/initiatives around that actively encourage you to purchase their wireless routing products and then open up access to everyone.

    I'm a member of FON, which allows you to allocate a specific amount of bandwidth for sharing if you're using one of their routers - say 1MB of your 8MB ADSL, which neatly overcomes the first poster's issue of not having enough bandwidth for their own nefarious purposes. After being a member of FON for 12 months they actually sent me three free wireless routers at Christmas, which I gave away to friends hoping that they too will join and share bandwidth.

    There's another company I heard about, US based, that does something similar, but I can't think of their name right now.

    However, I wonder about my ISP's stance regarding sharing WiFi for free with others. Does it violate their Ts&Cs? Do I care enough to actually find out? No!

    --
    Brought to you by the author of such childrens' classics as "Some Kittens can Fly!" and "All Dogs go to Hell."
  13. Correct my if I'm wrong by Seakip18 · · Score: 4, Interesting

    But I thought the best way to browse securely was have all traffic sent to your home server, encrypt it, and forward to the laptop. This was because you assume your home network is inherently more secure. With is approach, you are leaving your home network, including your significant others, at risk. Especially those who are not savvy enough to apply updates and maintain anti-virus.

    While I understand the anonymity helps his secure network stand out, all those open networks are just waiting for a guy with a little time and knowhow to start doing many bad things, say, man-in-the-middle. Just because you are blending into the pack does not keep the lions from eating one of you.

    Now then, it IS his network at home, so he can do whatever the heck he feels like. And I do understand his social aspects of looking at WiFi as another resource for the public. But that does not free you from liability regardless of how little or insignificant it may be or stupidly enforced.

    To me, it sounds like he doesn't want to roll up his sleeves and do some dirty work with port-forwarding, SSH-ing, and proxying. With those, you can enjoy quite decent browsing while away AND understand that your weakest point is at home.

    On an unrelated note, where does this guy live?

    --
    import system.cool.Sig;
  14. Re:how do i crack a WEP password? by Anonymous Coward · · Score: 5, Funny

    So then he's just a bastard?

  15. Re:Steal Wi-Fi? by gnick · · Score: 5, Insightful

    That's like saying we should "steal" music files because it's not a physical thing and EVERYONES doing it so it's okay. Besides, it'll be an important lesson to those who didn't secure it in the first place... Did you RTFA? He's not suggesting that everyone should go out and steal Wi-Fi, he's just saying that it's nice to leave your own Wi-Fi unsecured so that others can use it if they want.

    That said, IANAL but the ones that he apparently spoke to seem awfully cavalier about the situation. I would be extremely uncomfortable explaining to a judge that I:
    1) Published an article stating that I knew that my wireless connection could be used by others to commit crimes.
    2) Left my connection unsecured anyway.
    3) Was arrested because of illegal traffic.
    4) Expect to be excused.
    --
    He's getting rather old, but he's a good mouse.
  16. Re:Usually not stealing by zappepcs · · Score: 5, Insightful

    Not only might you want to give away unused bandwidth, but look at the reasons people are telling us we should not give it away:

    - You might be blamed for illegal file sharing or spamming
    - You might be held legally responsible for what other do
    - You might be the victim of malicious users
    - You might.... nevermind, all the reasons are to protect you from people who would sue you. What does that say about the world?

    Lets throw some other analogies out there:

    You shouldn't stop to help a stranded motorist because they might attack you or kill you
    You shouldn't give people advice because they might sue you for using it badly (lawyers & doctors)
    You shouldn't leave objects in your lawn in case someone trips and sues you
    you.... getting the picture?

    You are NO LONGER free to do as you wish with what is yours because other people control what you do, either directly, or indirectly as a consequence of fear of what they MIGHT do. If gun makers are not responsible for what people do with the products they make, you should NOT be responsible for what people do with the bandwidth you gave them to use.

    If we can be held responsible for what happens across our open APs, then the ISP can be held responsible for what goes across its network.

    In the end, common sense and reasonable thought dictate that the person who does the spamming or file sharing is responsible. If you leave a gardening tool in your lawn, and a person trips on it and hurts themselves, who is at fault? If you put a bench in your yard where people can sit and rest and some kid pushes another who then falls and cuts his head on the bench, who is at fault?

    I know those don't fit perfectly, but the point is that just because you helped to create something, you are NOT responsible for the use of it. Leaving your car unlocked is a good analogy: if someone takes it, they are stealing, and just because you did not do all that you could do to prevent them from taking it does not change the fact that they stole it.

    In another thought, holding the AP owner responsible is like trying to treat them as network security experts under the law. Insurance companies, police departments, all sorts of people work to inform you how to stop someone from stealing your property but does anyone do public service announcements to tell you how to stop people from stealing your bandwidth? Can you get insurance to protect you from bandwidth theft? or to compensate you when the **AA are suing you?

    Is a bus driver culpable if he drives the bus that a bank robber used to get to the bank he robbed?

    This goes on and on, but the point of holding you responsible for what others do with something you gave them (without the intent of doing so for malicious or nefarious reasons) has been proven in court already. Gun makers are not responsible for any deaths that happen from use of their products. Game over.

  17. Re:Steal Wi-Fi? by penguin_dance · · Score: 4, Interesting

    No, it's more akin to: I go to the grocery store and buy a 5 lb bag of sugar. Now I don't need to use that much sugar so I let the neighbors have some. That's not stealing because I paid for it. You're essentially doing nothing more than what a Starbucks or other cafe does.

    However, don't be surprised that companies like Comcast freak out because, while they want you to PAY for all that bandwidth, they don't actually want you to USE it!

    --
    If you've never been modded as "flamebait" or "troll," you've never tried to argue a minority viewpoint here!
  18. Re:Steal Wi-Fi? by TheRaven64 · · Score: 5, Insightful

    1) Published an article stating that I knew that my wireless connection could be used by others to commit crimes. I know the spade in my (unlocked / ungated) garden could be used to hit someone around the head and possibly even kill them. It could then be used to dig a shallow grave to bury the body. I have just posted on Slashdot stating that I know it can be used in this way (although I don't condone this use).

    2) Left my connection unsecured anyway. I have left the spade in my garden anyway and don't mind if my neighbours borrow it, as long as they return it promptly in the same condition.

    3) Was arrested because of illegal traffic. 4) Expect to be excused. I haven't been arrested on suspicion of being an accessory to murder, but I would expect to be acquitted if my only connection to the crime were that someone had borrowed my spade and used it as a murder weapon.
    --
    I am TheRaven on Soylent News
  19. What what WHAT? by Quiet_Desperation · · Score: 5, Funny

    Slashdot would suck if everyone had to call Rob before they felt they were allowed to use his web server.

    Wait! You mean I don't? Shit! All those wasted phone calls!

  20. ISP and integrity in the same comment? by Comboman · · Score: 5, Insightful
    with ISP you've specifically agreed you wont do that. Get some integrity!

    You mean the same ISP that agreed to give me unlimited downloads but cancels my service if I pass their secret limit? The same ISP that sold me unlimited high-speed but throttles it back for certain applications? Who is that needs the integrity?

    --
    Support Right To Repair Legislation.
  21. Re:Steal Wi-Fi? by hey! · · Score: 4, Interesting

    No, it's more akin to: I go to the grocery store and buy a 5 lb bag of sugar. Now I don't need to use that much sugar so I let the neighbors have some. That's not stealing because I paid for it. You're essentially doing nothing more than what a Starbucks or other cafe does.


    Actually, it's more like ordering the all you can eat buffet and letting your friend eat off your plate.

    If your friend says, "gee that looks good," and you say, "here, have a bite," the restaurant doesn't care. You had a good time, your friend had a good time, you'll probably come back for more. On the other hand, if your friends eats a dozen jumbo shrimp and couple of salmon fillets, the restaurant will be ticked off, because they priced the buffet around the probable range of one person's appetite. If everybody starts doubling or tripling up, then they have to raise prices, which mean they can't sell to individual diners.

    So the way this works is, the vendor makes rules, and they look the other way at insignificant bits of rule breaking that keep their customers happy. When people get organized about breaking rules to unilaterally drop the price of service, then they start to get a bit tetchy.
    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.