Header illustration for "WiFi testing law in Australia: what you can legally audit"

"WiFi testing law in Australia: what you can legally audit"

WiFi testing law in Australia: what you can legally audit

Australia has some of the more navigable security-research law in the world, but "navigable" is not "anything goes." If you're getting into WiFi auditing with an ESP32 or a laptop, here's the map — and the rule that every tool we sell is framed around: audit what you own, or what you have written permission to test.

The three regimes that touch you

1. The Criminal Code Act 1995 (Commonwealth). Unauthorised access to, modification of, or impairment of computer systems is criminal under Part 10.7 — most relevantly sections 478.1–478.3. Capturing handshakes and cracking someone else's WPA key, or logging into an AP you don't control, fits squarely here regardless of whether you "meant harm." (ICLG Australia Cybersecurity 2026)

2. The Telecommunications Act and ACMA rules. Interfering with telecommunications services — which deauthentication attacks against networks you don't own can constitute, depending on effect — sits under ACMA's regime. Radio transmitter equipment also must not cause interference outside licence conditions. Practical reading: deauth tools are for detecting deauths on your own networks, not for knocking neighbours offline.

3. State and territory law. Most states have their own unauthorised-access and device-interception offences that run in parallel. Victoria, NSW and Queensland each have Crimes Act provisions that don't depend on the Commonwealth ones being charged.

What you can legally do

What is never fine

How this applies to the tools we sell

Every WiFi-capable device we build ships with lawful-use documentation because capability and permission are different things. An ESP32 that can detect deauthentication frames doesn't care whose network it's pointed at; only you decide that. Our listings state the intended use, our blog states the law, and neither of us gets to outsource the judgement call to the hardware.

If you're training toward professional pentesting work, the legal frameworks above are the same ones you'll operate under with client engagements — just with contracts instead of handshake agreements. Learning on your own lab under the same rules you'll work by later is the cheapest way to build that discipline.

A practical scope template

Before any engagement, even an informal one, write down: target networks and devices, permission from the owner, test window, techniques allowed (passive scan? handshake capture? deauth against your own AP only?), and how findings will be reported. One page. It keeps you honest and it's the habit that separates hobbyists from professionals.

We stock WiFi analysis hardware and prebuilt ESP32 audit tools with lawful-use framing on every listing, and we're happy to point you at scope documentation before you buy. Start with the StealthDeck ESP32 builds or the starter toolkit.

← All posts