Generally I think it's stealing, but it also shows the incompetence of the owner (or more the dumbing down of the default "works out of the box" setup)
I personally would be more worried about what YOU are sending through their connection. Anyone in range can sniff out packets, so if you log into any sites that use cookies or HTTP basic authentication they can see your details.
|