actually some more about that ap stuff:

they kindof forgot about security when they made the standart so they patchet it with wep so the client authenticate himself (with a 40 bit key and the same initialisation vector... doesn't resists 15 mins ) but what prevent you from taking over the whole ap ? i mean what if you show up out there with you own ap with a 50 dbi (illegall by the way in most countries) and start advertising your services ...true they'll loose network connectivity but you'll gain access ...
fun isn't it ...

btw that won't last