Re: Legality of Packet Sniffing
Caleb Phillips <[email protected]> Thu, 25 Oct 2007 16:58:15 -0600
| Newsgroups | gmane.network.wireless.portland.general |
|---|---|
| Message-ID | <[email protected]> |
At first it seems like you've contradicted section 2.1 of the paper, and IANAL, but I need more clarification: > it is perfectly legal to sniff unencrypted wireless networks. the > legal ambiguities come into play concerning disclosure of that data in > whole or in part. > > 0. Electronic Communications Privacy Act 18 U.S.C. § 2511 > "(g) It shall not be unlawful under this chapter or chapter > 121 of this title for any person— > _(i) to intercept or access an electronic communication > made through an electronic communication system that is > configured so that such electronic communication is > readily accessible to the general public; This seems like the strongest clause. I can, however, imagine arguments about what "configuration" is required to make something "non-public" or "public". Additionally, 18 U.S.C. Chapter 206, prohibits (universally it would seem) the use of a pen register or a trap device. Since such a device is necessarily included in a sniffer (i.e. a sniffer logs IPs and MACs too), then is it true that this exception in the Electronic Communications Privacy act is precluded by the Pen Register Trap and Trace act? Perhaps this means it's okay to sniff publicly accessible traffic so long as you never see or log the addressing bits? That's a bit silly. http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00003121----000-.html > _(ii) to intercept any radio communication which is > transmitted— ... > __(III) by a station operating on an authorized frequency > within the bands allocated to the amateur, citizens band, > or general mobile radio services; I'm not sure what "general mobile radio services" is. This certainly doesn't say anything about ISM bands. Maybe ISM bands are implicitly included in "general mobile radio services"? > _(v) for other users of the same frequency to intercept any > radio communication made through a system that utilizes > frequencies monitored by individuals engaged in the > provision or the use of such system, if such communication > is not scrambled or encrypted. > " If I'm reading 2.g.V. correctly, this is allowing me to intercept unencrypted communication on a system that I am using so long as the implementation requires me to monitor those communications. For instance, 802.11x is in the CSMA/CA family of protocols, which do carrier sensing to determine when the channel is idle. Therefore, it isn't illegal if my WiFi card intercepts something not intended for me in the process of sensing the channel. However, if I am not participating in the system, and am simply intercepting the traffic (as with passive capture, monitor-mode,etc.), I'm not sure this clause applies. > http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00002511----000-.html > 18 U.S.C. § 2511(2)(g)(v) (2004) > 18 U.S.C. § 2511(1)(a). > > anyone who suggests there is a legal basis for "expectation of > privacy" on public wireless network is not only incorrect, but > actively perpetuating harmful misinformation that is detrimental to > the privacy of users on these networks. Of course, just because something may or may not be illegal doesn't make you safe from it! -- Caleb Phillips -- The Personal Telco Project - http://www.personaltelco.net/ Donate to PTP: http://www.personaltelco.net/donate Un/Subscribe: http://lists.personaltelco.net/mailman/listinfo/general/ Archives: http://news.gmane.org/gmane.network.wireless.portland.general/ Etiquette: http://www.personaltelco.net/index.cgi/MailingListEtiquette