Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

March 14th, 2009, 10:18 GMT · By

Security Experts Claim That BBC Broke the Law

SHARE:

Adjust text size:


BBC technology TV programme accused of breaking the law
Enlarge picture
An episode of the BBC Click technology program that is scheduled to air today has generated a lot of controversy in the IT security community. The documentary tries to raise awareness over the growing threat of computer botnets, but in doing so it might have broken the law, numerous security professionals claim.

In order to demonstrate the destructive power that hijacked computers can have, the BBC decided it required access to such a botnet. Therefore, Spencer Kelly, host of the BBC Click TV show, went on underground chatrooms and acquired, through unspecified means, what he calls a "low-value," but 22,000-strong army of infected computers.

The test scenarios chosen by the reporter involved spam and denial of service attacks. The DDoS was demonstrated with the help of security company PrevX, which allowed the BBC to target one of their backup servers. According to the results, the flood of requests sent by only 60 zombie computers were enough to clog the site's bandwidth and render it inaccessible.

The spam test was performed on two e-mail addresses specifically created for this purpose on Gmail and Hotmail. Each of the 22,000 computers were directed to send spam to these addresses and according to the program's description, "Within hours, the inboxes started to fill up with thousands of junk messages."

While the intentions of the BBC Click and this documentary might have been honorable, security researchers say that the show has violated the Computer Misuse Act, the UK anti-hacking law. Graham Cluley, senior technology consultant at anti-virus vendor Sophos pointed out that the company "has been asked many times by the media to take part in TV programmes like this, and has always made clear that we believe their legality to be questionable. Moreover, to our mind, the dubious ethics of such experiments are without question."

Mr. Cluley is backed up on this by professionals from other security companies, including Joe Llewelyn from Kaspersky, Larry Bridwell from AVG Technologies, Dave Marcus of McAfee and Patrik Runald of F-Secure. Meanwhile, BBC Click commented on Twitter that "We would not put out a show like this one without having taken legal advice." They all seem to agree that by controlling someone else's computer without their consent, BBC Click is guilty of "unauthorized access."

Some people argued that criminal intent is required for this law to be breached. However, Out-law.com editor and technology lawyer Struan Robertson does not agree. "Section three of the Computer Misuse Act describes the need for an intent to impair the operation of a computer or to hinder access to data. Such intent is not required for the section one offence of unauthorised access" the legal expert explains.

When the experiment was finished, BBC Click changed the desktop wallpaper on the infected computers to warn the unsuspecting owners that their security was compromised. This action also raises legal and ethical issues. Robertson concluded that "it is very unlikely that any prosecution will follow because the BBC's actions probably caused no harm. On the contrary, it probably did prompt many people to improve their security."

TELL US WHAT YOU THINK:

1,740 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Botnet Runner Sentenced to Four Years Behind Bars

Conficker to Hit Legit Websites

New Distributed Denial of Service Technique Explained

ICANN to Tackle the Fast Flux Issue

Botnet Serving Browser-Targeted Exploits

READER COMMENTS:


Comment #1 by: James Bigglesworth on 14 Mar 2009, 13:16 UTC reply to this comment

I agree that the BBC broke the 'technicalities' of the law, but certain people fail to understanding of the phrase 'intent'.

It was not the intent of the BBC to do any harm, and they targeted a system WITH authority of the owners. One could argue the technicalities until you are blue in the face, but the botnet was already in existence, so no fault should be aimed at the BBC.

The fools that own the zombied machines should be the ones to blame, because THEY are the problem. They should be prosecuted and banned from the internet for life. They have no business being on the internet if they cannot apply even the most basic of security.

I applaud the BBC Click programme for taking a bold and much needed step to raise awareness, and I hope the BBC continue to be the leaders in ground-breaking programmes to hit the messages home.

In addition, if it was so easy to get into a bot-net, then maybe more people should infiltrate them to change desktop pictures of the pond-scum that own zombied machines.

Sometimes you have to actually fight the problem, instead of sitting around spouting liberalistic nonesense like "oh you should not do that, it's naughty".

Learn people, learn.


Comment #2 by: Pete on 16 Mar 2009, 13:43 UTC reply to this comment

I'd like the BBC to explain how much money they spent on this, and who they gave that money too.

I'd also like to know how you disinfect 22,000 machines infected with spyware, some of which are switched off.

Because I simply don't believe a botnet operation is going to give you a self destruct button.

And in terms of warning people? It might have been nice to warn people before using the botnet rather than afterwards.

But lets say you're going to warn people, these machines were all over the globe (given the glmpses visible on TV). What use is it warning them in English if they don't speak English?

Ethically, exploiting people because they are vulnerable isn't very nice. BBC could and should have warned them immediately they got access to the botnet in that case.

No, this is very bad. Its like the phone in scams, a level of ethics barely rises above the crooks themselves.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM