BBC botnet investigation turns hacks into hackers

Changing PCs without permission always wrong


An investigation by the BBC into cybercrime may itself have broken UK computer crime law.

BBC Click got its hands on a botnet of 22,000 compromised PCs from an underground forum. It used these machines to send spam to two accounts it had established with Gmail and Hotmail. The programme also used these zombie machines to show how they might be used in a denial of service attack.

After getting permission from security firm Prevx, which commented on camera but did not otherwise participate in the investigation, BBC Click used the compromised machines to flood a backup site run by the security firm with junk traffic.

BBC Click found that only 60 compromised machines were needed to render Prevx's site inaccessible.

The broadcaster then warned the owners of the infected computers that their machines were compromised, and advised on how to clean them, by changing their screensaver.

BBC Click claimed that "If the exercise had been done with criminal intent it would be breaking the law".

But this position has been disputed by lawyers and security experts contacted by El Reg. While acknowledging that the BBC acted with the best intentions, they describe its action as naive and potentially criminal.

"The BBC appears to have broken the Computer Misuse Act by causing 22,000 computers to send spam," said Struan Robertson, editor of out-law.com and legal director at solicitors Pinsent Masons. "It does not matter that the emails were sent to the BBC's own accounts and criminal intent is not necessary to establish an offence of unauthorised access to a computer."

"The Act requires that a computer has been made to perform a function with intent to secure access to any program or data on the computer. Using the botnet to sending an email is likely to satisfy that requirement. It also requires that the access is unauthorised - which the BBC appears to acknowledge. It does not matter that the BBC's intent was not criminal or that someone else created the botnet in the first place."

"The maximum penalty for this offence is two years' imprisonment. But it is very unlikely that any prosecution will follow because the BBC's actions probably caused no harm. On the contrary, it probably did prompt many people to improve their security."

Graham Cluley, senior technology consultant at security firm Sophos, added that changing people's desktop wallpaper to present a message from BBC Click (see end of video clip here) clearly crossed the line.

"Even if it was done with the best intentions and in the public interest, that is unauthorised modification of a computer and an offence under the Computer Misuse Act," Cluley told El Reg.

"The computer security industry has found itself in the situation before where it has been able to do this (or remove malware on a botnet-infected computer) without permission of the computer user (after all, we don't know where they are based in the world) but has NOT because it's illegal for us to change people's computers without their permission."

Cluley added that even though it was unlikely that anyone would be prosecuted it was still a "dangerous precedent for others to turn a blind eye to our computer crime legislation". Sophos has been invited to participate in similar exercises in the past but declined. Cluley explained that it was possible to illustrate the computer security risk posed by botnets without breaking the law. ®

Broader topics


Other stories you might like

  • Will Lenovo ever think beyond hardware?
    Then again, why develop your own software à la HPE GreenLake when you can use someone else's?

    Analysis Lenovo fancies its TruScale anything-as-a-service (XaaS) platform as a more flexible competitor to HPE GreenLake or Dell Apex. Unlike its rivals, Lenovo doesn't believe it needs to mimic all aspects of the cloud to be successful.

    While subscription services are nothing new for Lenovo, the company only recently consolidated its offerings into a unified XaaS service called TruScale.

    On the surface TruScale ticks most of the XaaS boxes — cloud-like consumption model, subscription pricing — and it works just like you'd expect. Sign up for a certain amount of compute capacity and a short time later a rack full of pre-plumbed compute, storage, and network boxes are delivered to your place of choosing, whether that's a private datacenter, colo, or edge location.

    Continue reading
  • Intel is running rings around AMD and Arm at the edge
    What will it take to loosen the x86 giant's edge stranglehold?

    Analysis Supermicro launched a wave of edge appliances using Intel's newly refreshed Xeon-D processors last week. The launch itself was nothing to write home about, but a thought occurred: with all the hype surrounding the outer reaches of computing that we call the edge, you'd think there would be more competition from chipmakers in this arena.

    So where are all the AMD and Arm-based edge appliances?

    A glance through the catalogs of the major OEMs – Dell, HPE, Lenovo, Inspur, Supermicro – returned plenty of results for AMD servers, but few, if any, validated for edge deployments. In fact, Supermicro was the only one of the five vendors that even offered an AMD-based edge appliance – which used an ageing Epyc processor. Hardly a great showing from AMD. Meanwhile, just one appliance from Inspur used an Arm-based chip from Nvidia.

    Continue reading
  • NASA's Psyche mission: 2022 launch is off after software arrives late
    Launch window slides into 2023 or 2024 for asteroid-probing project

    Sadly for NASA's mission to take samples from the asteroid Psyche, software problems mean the spacecraft is going to miss its 2022 launch window.

    The US space agency made the announcement on Friday: "Due to the late delivery of the spacecraft's flight software and testing equipment, NASA does not have sufficient time to complete the testing needed ahead of its remaining launch period this year, which ends on October 11."

    While it appears the software and testbeds are now working, there just isn't enough time to get everything done before a SpaceX Falcon Heavy sends the spacecraft to study a metallic-rich asteroid of the same name.

    Continue reading

Biting the hand that feeds IT © 1998–2022