Which one of you tards was this v. no wireless network PW

BUFFALO, N.Y. – Lying on his family room floor with assault weapons trained on him, shouts of “pedophile!” and “pornographer!” stinging like his fresh cuts and bruises, the Buffalo homeowner didn’t need long to figure out the reason for the early morning wake-up call from a swarm of federal agents.

That new wireless router. He’d gotten fed up trying to set a password. Someone must have used his Internet connection, he thought.

“We know who you are! You downloaded thousands of images at 11:30 last night,” the man’s lawyer, Barry Covert, recounted the agents saying. They referred to a screen name, “Doldrum.”

“No, I didn’t,” he insisted. “Somebody else could have but I didn’t do anything like that.”

“You’re a creep … just admit it,” they said.

Law enforcement officials say the case is a cautionary tale. Their advice: Password-protect your wireless router.

Plenty of others would agree. The Sarasota, Fla. man, for example, who got a similar visit from the FBI last year after someone on a boat docked in a marina outside his building used a potato chip can as an antenna to boost his wireless signal and download an astounding 10 million images of child porn, or the North Syracuse, N.Y., man who in December 2009 opened his door to police who’d been following an electronic trail of illegal videos and images. The man’s neighbor pleaded guilty April 12.

For two hours that March morning in Buffalo, agents tapped away at the homeowner’s desktop computer, eventually taking it with them, along with his and his wife’s iPads and iPhones.

Within three days, investigators determined the homeowner had been telling the truth: If someone was downloading child pornography through his wireless signal, it wasn’t him. About a week later, agents arrested a 25-year-old neighbor and charged him with distribution of child pornography. The case is pending in federal court.

It’s unknown how often unsecured routers have brought legal trouble for subscribers. Besides the criminal investigations, the Internet is full of anecdotal accounts of people who’ve had to fight accusations of illegally downloading music or movies.

Whether you’re guilty or not, “you look like the suspect,” said Orin Kerr, a professor at George Washington University Law School, who said that’s just one of many reasons to secure home routers.

Experts say the more savvy hackers can go beyond just connecting to the Internet on the host’s dime and monitor Internet activity and steal passwords or other sensitive information.

A study released in February provides a sense of how often computer users rely on the generosity – or technological shortcomings – of their neighbors to gain Internet access.

The poll conducted for the Wi-Fi Alliance, the industry group that promotes wireless technology standards, found that among 1,054 Americans age 18 and older, 32 percent acknowledged trying to access a Wi-Fi network that wasn’t theirs. An estimated 201 million households worldwide use Wi-Fi networks, according to the alliance.

The same study, conducted by Wakefield Research, found that 40 percent said they would be more likely to trust someone with their house key than with their Wi-Fi network password.

For some, though, leaving their wireless router open to outside use is a philosophical decision, a way of returning the favor for the times they’ve hopped on to someone else’s network to check e-mail or download directions while away from home .

“I think it’s convenient and polite to have an open Wi-Fi network,” said Rebecca Jeschke, whose home signal is accessible to anyone within range.

“Public Wi-Fi is for the common good and I’m happy to participate in that – and lots of people are,” said Jeschke, a spokeswoman for the Electronic Frontier Foundation, a San Francisco-based nonprofit that takes on cyberspace civil liberties issues.

Experts say wireless routers come with encryption software, but setting it up means a trip to the manual.

The government’s Computer Emergency Readiness Team recommends home users make their networks invisible to others by disabling the identifier broadcasting function that allows wireless access points to announce their presence. It also advises users to replace any default network names or passwords, since those are widely known, and to keep an eye on the manufacturer’s website for security patches or updates.

People who keep an open wireless router won’t necessarily know when someone else is piggybacking on the signal, which usually reaches 300-400 feet, though a slower connection may be a clue.

For the Buffalo homeowner, who didn’t want to be identified, the tip-off wasn’t nearly as subtle.

It was 6:20 a.m. March 7 when he and his wife were awakened by the sound of someone breaking down their rear door. He threw a robe on and walked to the top of the stairs, looking down to see seven armed people with jackets bearing the initials I-C-E, which he didn’t immediately know stood for Immigration and Customs Enforcement.

“They are screaming at him, ‘Get down! Get down on the ground!’ He’s saying, ‘Who are you? Who are you?’” Covert said.

“One of the agents runs up and basically throws him down the stairs, and he’s got the cuts and bruises to show for it,” said Covert, who said the homeowner plans no lawsuit. When he was allowed to get up, agents escorted him and watched as he used the bathroom and dressed.

The homeowner later got an apology from U.S. Attorney William Hochul and Immigration and Customs Enforcement Special Agent in Charge Lev Kubiak.

But this wasn’t a case of officers rushing into the wrong house. Court filings show exactly what led them there and why.

On Feb. 11, an investigator with the Department of Homeland Security, which oversees cybersecurity enforcement, signed in to a peer-to-peer file sharing program from his office. After connecting with someone by the name of “Doldrum,” the agent browsed through his shared files for videos and images and found images and videos depicting children engaged in sexual acts.

The agent identified the IP address, or unique identification number, of the router, then got the service provider to identify the subscriber.

Investigators could have taken an extra step before going inside the house and used a laptop or other device outside the home to see whether there was an unsecured signal. That alone wouldn’t have exonerated the homeowner, but it would have raised the possibility that someone else was responsible for the downloads.

After a search of his devices proved the homeowner’s innocence, investigators went back to the peer-to-peer software and looked at logs that showed what other IP addresses Doldrum had connected from. Two were associated with the State University of New York at Buffalo and accessed using a secure token that UB said was assigned to a student living in an apartment adjacent to the homeowner. Agents arrested John Luchetti March 17. He has pleaded not guilty to distribution of child pornography.

Luchetti is not charged with using his neighbor’s Wi-Fi without permission. Whether it was illegal is up for debate.

“The question,” said Kerr, "is whether it’s unauthorized access and so you have to say, ‘Is an open wireless point implicitly authorizing users or not?’

“We don’t know,” Kerr said. “The law prohibits unauthorized access and it’s just not clear what’s authorized with an open unsecured wireless.”

In Germany, the country’s top criminal court ruled last year that Internet users must secure their wireless connections to prevent others from illegally downloading data. The court said Internet users could be fined up to $126 if a third party takes advantage of their unprotected line, though it stopped short of holding the users responsible for illegal content downloaded by the third party.

The ruling came after a musician sued an Internet user whose wireless connection was used to download a song, which was then offered on an online file sharing network. The user was on vacation when the song was downloaded.

http://www.huffingtonpost.com/2011/04/24/unsecured-wifi-child-pornography-innocent_n_852996.html

I just switched mine to WPA2 after being the default WEP Verizon key.

It’s not like someone couldn’t just easily break a WEP key and use someone elses wireless…

Even WPA isn’t that hard

How do you get the job of investigator with the Department of Homeland Security? I want to get paid to look at kiddie porn all day.

wait, why the fuck is homeland security involved with this?!

On a side note this would be a great defense if the RIAA came knocking at your door about torrents or some BS

Yeah, it’s easy to crack it, but it’s even easier to just keep driving until you find one that’s open.

I hate this conversation. I have the same one with people regarding erasing drives. Could someone do it? Sure…is it probable that they will…nope. If I’m looking to download something illegally I’d hit up a McDonald’s…because I hate them so much.

Funny, just last night I put a password on my wireless because I read this happening to people. What’s the best setting for my linksys, they don’t make it that easy to put a password in them, so many options like wap wap2 and all the others.

WPA2

Yea?

It’s happen to people though same shit with people tossing computers with HDs unformatted/unwiped out.

Look at all the people who got pwned on unsecure wireless at starbucks and other places…

If you’re going to run WPA/WPA2 at least change the SSID name to something non default and unique. There are precomputed rainbow tables to help crack WPA passwords quicker since the key is hashed against the SSID.

Is that the best setting?

for most retail/consumer wireless routers, yes. As stated above though, there are other precautionary measures that should be taken.

If you use WPA2, change the SSID, and also remove the setting to broadcast the SSID then you should be pretty safe from attackers.

What is the verizon default stuff again?

I tried what I thought was the standard admin/password1 combo on a friends router and could not change their security settings.

The installer never wrote it down for them. They are also not wireless users, so have little interest in calling to get it.

They changed all passwords to the serial # on the modem

This is what I was thinking the whole time.


thats now long my wpa2 is. letters and numbers.
if someone gets on it, theyre looking for something.

oh and an FYI
easiest way to protect your network is disable broadcast, have a password, AND set up MAC filtering.

MAC filtering is actually a fucking joke and more of annoyance it’s also not a security feature

Also no broadcasting your SSID is :tif:

There are about 20 broadcast networks around me. No one is going to bother figuring out how to get in to mine when they can log in to any of the three “linksys” networks with the default PW.

:tinfoilhat:crew always makes me lol

I’m not paranoid

I work and consult with a bunch of companys I have seen independent reports about shit happening to regular people.

WPA2 AES for me. Broadcasting my SSID but it’s a custom one. Fuck mac filtering. I’m not changing router configs every time I want to let someone on my wifi.

The last wide open wifi in range of my house finally went secure a few months ago. It was nice having it as a failover network any time I was having issues with my connection.