Good point but I think his comment was about how there still be no proof of who "actually" was doing the wrong doing. It just proves that it's coming from that connection. So I'd say if there's a router or firewall involved with NAT, you're screwed because there's no way to prove the LAN IP of the machine or whether the machine was one that got access to the LAN via unsecured wireless.