if so, what about those school and other institution's network, they all have the same problem.
Preventing an untrusted party to access somebody else network would be the first step to consider and it is not unlikely there are security policies for all trusted parties to follow (I assume that methods to _not_ compromise a network are likely to be mentioned)
Even a password provide no security if written on a post-it and stickied on the monitor. Nor even a supposedly unknown password provide any protection
if it can be easily guessed in reasonable amount of time.
I'm no expert but I guess there is no single answer to such question.
Penetration testing is used to evaluate specific scenarios as part of a
security audit.
If you find a legitimate forum meant for related security researchers (but also open to general pubic) which address these aspects in an ethical and responsible way please let me know.
