Dear Petzl, Argh, KH, *
finally I worked out some interesting laws about the big question: "Is wardriving in Germany legal or not!?" I'm from Germany and I can only speak for my country - keep that in mind. First I'll mention the laws and then some conclusions.
Here in Germany we have the so called StGB (Strafgesetzbuch)/GG (Grundgesetz) and there I found something. But before I go on here is my personal definition of wardriving:
Diving around with my car and my homebrew antenna on top, using Kismet or Wellenreiter + GPS to find APs or clients. Laughing about strange SSIDs, but never never enter or touch any APs, Networks or clients (according the DEFCon-Ethics). If there is the change to get in touch with the net-owner I offer my support to close the security gap for free. I just keep the generated XML-File for Wigle upload the rest goes to dev0.
Now is the question: Is my acting legal or not?
First of all we take a look to the StGB/GG and we find.:
§ 202a, "Spying out traffic" (Ausspähen von Daten).
§ 263a, "Computing fraud" (Computerbetrug).
§ 265a, "Subreption of service" (Erschleichen von Leistungen).
§ 303a, "Data influencing" (Datenveränderung).
§ 303b, "Sabotage of Computers" (Computersabotage).
§ 88, "Confidentiality telecommunication" (Fernmeldegeheimnis).
Lets go...
§ 202a (1) means collecting data which is crypted/secured and not for puplic use is facts constituting an offence in sence of this §. This can bring you 3 years into prison or you have to pay a lot of money.
§ 202a (2) is about the data itself, it says in sence of (1) data of any kind or traffic data of any kind.
I.Conclusion.:
Ok, I collecting data but only the SSID and BSSID and these are never crypted they are the puplic part of the traffic - but a part and thats the main problem. However the uncrypted part are also not made for me and puplic use -> Wigle... so I have a problem.
§§ 263a, 265a, 303a, 303b these laws do not hit me because my wardriving-ethic in general these laws are made for the black sheeps who try to penetrate into networks and also for men in the middle attacks and so on.... I think you know what I mean
.
§ 88, "Confidentiality telecommunication" (Fernmeldegeheimnis)(1) as the name says it defines secured communication. It is not allowed to take part on aktive communikations and also not allowed is the successless try. (2) not so important for us. (3) Furthermore it is not allowed to collect information and everything around the communication. The law means also the user and the tech behind this act of communication process and it is not allowed to bring any kind of the mentioned information into puplic...
II.Conclusion.:
..I wonder everything seems to be forbitten here in Germany
.
I ask my Prof. on the Uni and some lawyers in my neigborhood they confirmed my conclusions - the only legal way to do wardriving is to ask all the people for an agreement, but this is nonsence. I know all the arguments for wardriving but law is law. The main problem - as we already know - is that the act of Wardriving itself is not clearly defined by German law; they just transfere old exsisting laws to new technology - so it seems that the court can see it as they like to see it. I'm at a loss to understand how should this system work in futur. However my advice for all Wardrivers who live or visit Germany just realize your risc.
yours sincerely
Laurin