"WiFi testing law in Australia: what you can legally audit"
WiFi testing law in Australia: what you can legally audit
Australia has some of the more navigable security-research law in the world, but "navigable" is not "anything goes." If you're getting into WiFi auditing with an ESP32 or a laptop, here's the map — and the rule that every tool we sell is framed around: audit what you own, or what you have written permission to test.
The three regimes that touch you
1. The Criminal Code Act 1995 (Commonwealth). Unauthorised access to, modification of, or impairment of computer systems is criminal under Part 10.7 — most relevantly sections 478.1–478.3. Capturing handshakes and cracking someone else's WPA key, or logging into an AP you don't control, fits squarely here regardless of whether you "meant harm." (ICLG Australia Cybersecurity 2026)
2. The Telecommunications Act and ACMA rules. Interfering with telecommunications services — which deauthentication attacks against networks you don't own can constitute, depending on effect — sits under ACMA's regime. Radio transmitter equipment also must not cause interference outside licence conditions. Practical reading: deauth tools are for detecting deauths on your own networks, not for knocking neighbours offline.
3. State and territory law. Most states have their own unauthorised-access and device-interception offences that run in parallel. Victoria, NSW and Queensland each have Crimes Act provisions that don't depend on the Commonwealth ones being charged.
What you can legally do
- Test your own networks. Your home AP, your own devices, your own lab. This is the bulk of what a learning toolkit should ever touch.
- Test with authorisation. A written scope — who, what networks, what window, what techniques — is the professional standard even between friends.
- Passive monitoring of your own traffic, capture and analyse frames on networks you control.
- Responsible disclosure. If your testing on your own or authorised gear turns up a vulnerability in someone else's product, reporting it through their security contact is lawful and encouraged. Australia's 2024 Cyber Security Act also moved the country toward a statutory framework for IoT security standards, which gives disclosure more formal footing. (C-PRAV summary)
What is never fine
- Attacking or deauthing networks you don't own or aren't engaged for — including "it was just a test."
- Intercepting other people's communications content.
- Selling or sharing captured credentials.
- Assuming public/open WiFi is fair game. It isn't.
How this applies to the tools we sell
Every WiFi-capable device we build ships with lawful-use documentation because capability and permission are different things. An ESP32 that can detect deauthentication frames doesn't care whose network it's pointed at; only you decide that. Our listings state the intended use, our blog states the law, and neither of us gets to outsource the judgement call to the hardware.
If you're training toward professional pentesting work, the legal frameworks above are the same ones you'll operate under with client engagements — just with contracts instead of handshake agreements. Learning on your own lab under the same rules you'll work by later is the cheapest way to build that discipline.
A practical scope template
Before any engagement, even an informal one, write down: target networks and devices, permission from the owner, test window, techniques allowed (passive scan? handshake capture? deauth against your own AP only?), and how findings will be reported. One page. It keeps you honest and it's the habit that separates hobbyists from professionals.
We stock WiFi analysis hardware and prebuilt ESP32 audit tools with lawful-use framing on every listing, and we're happy to point you at scope documentation before you buy. Start with the StealthDeck ESP32 builds or the starter toolkit.