The major thing is that if someone else is in charge of the LAN (the network your friend was using) they can see everything that isn't encrypted that goes through the router (with the right knowledge).
WEP doesn't matter. WEP or WPA encrypts the data from a computer using wireless to connect to the access point. Once the data hits the AP isn't no longer encrypted.
My guess is that the person is using a packet sniffer on the Linux box to record the data going through the router and then looking at the stuff that interests them.
You can use one of the IM clients that encrypts messages between the two parties.
|