Slashdot Mirror


BBC Hijacks 22,000 PCs In Botnet Demonstration

An anonymous reader writes "'[The BBC] managed to acquire its own low-value botnet — the name given to a network of hijacked computers — after visiting chatrooms on the internet. The programme did not access any personal information on the infected PCs. If this exercise had been done with criminal intent it would be breaking the law. But our purpose was to demonstrate botnets' collective power when in the hands of criminals.' The BBC performed a controlled DDoS attack, 'then ordered its slave PCs to bombard its target site with requests for access to make it inaccessible.'"

72 of 457 comments (clear)

  1. why use botnet by fredan · · Score: 5, Funny

    when you can use slashdot!

    1. Re:why use botnet by Spazztastic · · Score: 5, Funny

      when you can use slashdot!

      Well, a botnet is probably faster. By the time your article gets through the submission queue the target would probably have gone offline along with the sun burning out.

      --
      Posts not to be taken literally. Almost everything is sarcasm.
    2. Re:why use botnet by Opportunist · · Score: 5, Funny

      The botnet is not stronger. But it is quicker. Easier. More seductive.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:why use botnet by N1AK · · Score: 5, Interesting

      I wrote about this story on my site and submitted it to The Reg at 10:20 this morning when I read the story on their website. Now its been aired on TV it seems to be getting a lot of coverage. I added an update a few minutes ago covering the two areas of the Computer Misuse Act that are likely to be quoted quite a bit in the debate about the legality.

      I find it amazing that something this dubious was allowed to get all the way to airing without someone at the BBC having a hissy fit. Perhaps they have received legal advice that said it was legit?

      As an aside, if I had wanted to submit my page to Slashdot is there a way I could of done it that (assuming it got published) wouldn't result in my host wishing a painful death upon me? I didn't change it partly because it's a short write up and partly for that reason.

    4. Re:why use botnet by Piranhaa · · Score: 5, Funny

      This demonstration never really took place. They made up a bogus story that will get Slashdot to DoS the site for them.

    5. Re:why use botnet by DiLLeMaN · · Score: 2, Funny

      mmm, double d.

      --
      /var/run/twitter.sock is a twitter socket puppet.
    6. Re:why use botnet by PsychoElf · · Score: 4, Funny

      I dunno...I'm sure most people on here are pretty quick and easy.

    7. Re:why use botnet by Teancum · · Score: 4, Interesting

      I suppose that the BBC views themselves as a branch of the British government. Yes, I know that it is supposedly an "independent" organization, but it is fully-funded by taxpayers in the UK.

      Then again, would many people consider a similar investigation by the U.S. Department of Defense or Department of Justice to be legit?

      Real monetary damages can be calculated here as well, as depreciation value and CPU time... not to mention access to network resoruces are certainly not "free" for the taking. Furthermore, technician time spent to remove these bot program, scanner software required to find this stuff.... removing this software is likely to be the more expensive part.

      Assuming â100 per computer that was infected (a rather low estimate), that would be around â200,000 that this reporter has potentially set up his company for liability damages.

    8. Re:why use botnet by growse · · Score: 2, Informative

      Well, it's fully funded by tv-owners. Not all taxpayers own tvs, and vice-versa.

      --
      There is nothing interesting going on at my blog
    9. Re:why use botnet by TheRaven64 · · Score: 2, Informative

      Technically, by anyone with equipment that receives live TV broadcasts. This includes video recorders and PCs that are used to stream live events (e.g. sports) from the BBC web site, but does not include TVs used solely to watch DVDs or PCs that use iPlayer to watch shows an hour or more after they are broadcast.

      --
      I am TheRaven on Soylent News
    10. Re:why use botnet by Hatta · · Score: 3, Funny

      Is it also fitter, happier, and more productive?

      --
      Give me Classic Slashdot or give me death!
    11. Re:why use botnet by jabithew · · Score: 2, Insightful

      Erm, did you RTFA? The botnet was previously existing, the BBC spammed two accounts they'd set up, and DDOS'd a site they'd set up. I'd be shocked if they didn't tell the hosts what they were going to do. As a final step, they notified all members of the botnet that they'd been hacked by changing their desktop background. I think it would be difficult to claim damages as the BBC did not propagate the botnet and anyone in their clutches got off lightly.

      --
      All intents and purposes. Not intensive purposes.
    12. Re:why use botnet by MatB · · Score: 5, Informative

      I suppose that the BBC views themselves as a branch of the British government.

      Hah! You jest, surely?

      Yes, I know that it is supposedly an "independent" organization,

      It is

      but it is fully-funded by taxpayers in the UK.

      Incorrect.

      The BBC is funded by a licence fee that all TV set owners pay, it's raised independently of the government and is specifically not a tax, the money never goes anywhere close to the Treasury. Many people chose not to have a TV and thus don't need to pay the license (I was one of these people for about 3 years, I had dial-up and a DVD collection, what'd I need a TV for?)

      It also gets money from overseas sales and a semi-independent part dedicated to overseas broadcasts is funded by the Foreign Office in the same way as Radio America and similar.

      I suspect the BBC has broken the law. I suspect they'll get investigated. I think that, regardless, they did the right thing--most people have no idea what a botnet is, let alone how much damage they do. Anything that raises awareness amongst domestic users in an open and transparent way is good. Those that had their PCs hijacked mught do well to upgrade their security (again).

      --
      Mat Bowles
    13. Re:why use botnet by Cederic · · Score: 2, Interesting

      Evidence of actual crime is being published by the BBC. It is illegal to use computing resources owned by other people without their permission.

      Illegal. That means it's a crime.

      I completely accept that there's minimal harm to any given individual. This does not make it legal.

      I don't want punitive damages. I don't really care about punishment of any tangible form. I do want prosecution and the full process of the law.

    14. Re:why use botnet by bluefoxlucid · · Score: 2, Funny

      ENOTXKCD, EAGAIN

    15. Re:why use botnet by shermo · · Score: 2, Funny

      And he actually lost karma in the entire exchange.

      Now I'm sure someone's going to vote me down in a poor attempt at irony, but hopefully my correct use of apostrophes will save me.

      --
      Insanity: voting in the same two parties over and over again and expecting different results
  2. Now this... by kcbanner · · Score: 4, Informative

    ...is good journalism. Good job BBC, the masses need to know about NOT USING IE6 TO SURF THE WEB.

    --
    Obligatory blog plug: http://www.caseybanner.ca/
    1. Re:Now this... by sopssa · · Score: 5, Informative

      Accessing and modifying data on other peoples computers is illegal. Better article written by a known security researcher Dancho Danchev, who also thinks it was controversial and illegal act.

      Even if your intentions are good, I DO NOT WANT you using my computer or making changes to it without my permissions.

    2. Re:Now this... by sakdoctor · · Score: 5, Insightful

      Then get some security.

      No unlocked car or house door analogy is even slightly useful in this case.

      Computer security by law is worse than security by obscurity, or security by Symantec product.

    3. Re:Now this... by N1AK · · Score: 4, Interesting

      Accessing and modifying data on other peoples computers is illegal.

      It's not that simple, accessing someones computer itself is a crime under the Computer Misuse Act. Modifying data is another crime but I think the BBC can safely argue that they didn't have 'requisite intent':

      For the purposes of subsection (1)(b) above the requisite intent is an intent to cause a modification of the contents of any computer and by so doing--
      (a) to impair the operation of any computer;
      (b) to prevent or hinder access to any program or data held in any computer; or
      (c) to impair the operation of any such program or the reliability of any such data.

      I have written a longer analysis of the Computer Misuse Act and how it relates to the BBC Click Botnet if you are interested. Please note IANAL and I don't mean in the kinkeh sex sense either.

    4. Re:Now this... by Eternauta3k · · Score: 4, Informative

      This reminds me of a certain video by The Onion

      --
      Yeah. Would you choose a neurosurgeon who pokes around people's brains in his spare time? I wouldn't.
    5. Re:Now this... by mike2R · · Score: 3, Informative
      Out Law have an article:

      Though the activity is likely to have been technically illegal, Robertson said that it is unlikely that the corporation will be punished for it.

      "The maximum penalty for this offence is two years' imprisonment. But it is very unlikely that any prosecution will follow because the BBC's actions probably caused no harm. On the contrary, it probably did prompt many people to improve their security," he said.

      A blog posting from security firm Sophos suggests that the BBC has committed an offence of making unauthorised modifications to a computer. Robertson said that that is unlikely.

      "The offence of unauthorised modification requires a recklessness or an intent that I don't think the BBC has displayed," he said.

      Section three of the Computer Misuse Act describes the need for an intent to impair the operation of a computer or to hinder access to data. Such intent is not required for the section one offence of unauthorised access, said Robertson.

      The BBC did not respond to OUT-LAW's request for comment. However, a message on the programme's Twitter account suggests that the team did consult lawyers. "We would not put out a show like this one without having taken legal advice," it said.

      --
      This sig all sigs devours
    6. Re:Now this... by ciderVisor · · Score: 4, Interesting

      I hope you took time to explain to them that Windows Defender is not a firewall. If you want a firewall then Windows....erm, Firewall might be more appropriate, funnily enough.

      I've been running Windows XP malware-free for over 2 years thanks to Windows Firewall, Windows Defender and LUA accounts. Do your friends a favour and set them up properly. Free them from third-party AV hell.

      --
      Squirrel!
    7. Re:Now this... by Nick+Ives · · Score: 2, Interesting

      Ditto. Vista's much derided UAC actually makes running Windows securely much easier too, it's actually the best part about Vista and I'm disappointed that MS is sacrificing security for ease of use in Win7. MS needs to stand firm against apps that bring up UAC prompts during normal operation whilst streamlining the UI to make the prompts more descriptive and eliminate multiple UAC prompts during certain operations.

      To paraphrase, those who sacrifice security for ease of use deserve neither.

      --
      Nick
    8. Re:Now this... by Ralish · · Score: 4, Informative

      Free them from third-party AV hell.

      Windows Defender is an anti-spyware product, and not a virus scanner. It will NOT protect you against most virus threats, nor is it intended to.

      In this respect, a 3rd-party virus scanner is still required if the detection and removal of viruses is important to you. Yes, there is Windows Live OneCare, but apart from the fact that it's scheduled to be discontinued in the future, you still have to pay for it.

    9. Re:Now this... by Anonymous Coward · · Score: 2, Funny

      I've been using Antivirus 2009 (recently updated from 2008 per recommendations even from all the other anti-virus websites).
      Since using it, I haven't had any viruses at all. I really don't understand how people can still get caught out in this day and age where we have such good tools available to us.

  3. Breaking the law by qoncept · · Score: 5, Interesting

    If this exercise had been done with criminal intent it would be breaking the law.

    Ok, so, I don't know much about the laws, but it is illegal, isn't it?

    --
    Whale
    1. Re:Breaking the law by jeffmeden · · Score: 5, Funny

      Don't worry, it was a "low value" botnet... That makes it OK.

    2. Re:Breaking the law by Spazztastic · · Score: 4, Informative

      If this exercise had been done with criminal intent it would be breaking the law.

      Ok, so, I don't know much about the laws, but it is illegal, isn't it?

      Regardless of intent it is illegal. They are gaining unauthorized access to someones PC and using it for their own personal gain. If I were to demonstrate how to crack someones WEP key in 5 minutes without the victim's explicit written permission it would be illegal, even if done just for "educational purposes." Sure, it's edgy reporting, but it is still highly illegal.

      I doubt anything will come of it though.

      --
      Posts not to be taken literally. Almost everything is sarcasm.
    3. Re:Breaking the law by snowraver1 · · Score: 2, Funny

      What's a botnet?

      --
      Copyright 2010. All rights reserved. This comment may not be copied in any way including, but not limited to caching.
    4. Re:Breaking the law by PhilHibbs · · Score: 4, Insightful

      No, it's more like if your door is already busted wide open and burglars are coming in and out, and a reporter wanders in.

    5. Re:Breaking the law by unlametheweak · · Score: 4, Insightful

      Regardless of intent it is illegal.

      Isn't the BBC "owned" by the government of Britain ("a quasi-autonomous statutory corporation as a public service broadcaster and is run by the BBC Trust; it is, per its charter, supposed to "be free from both political and commercial influence and answer only to its viewers and listeners", Ref: http://en.wikipedia.org/wiki/Bbc)? If so it would appear that they are immune from the law because, as contemporary history demonstrates, "intent", when the government is involved is never criminal in nature, but rather for the good of mankind.

    6. Re:Breaking the law by Dr+Caleb · · Score: 5, Funny

      It's an electrically charged net that we use to catch runaway robots. Like the Ethernet we use to catch the EtherBunny.

      --
      "History doesn't repeat itself, but it does rhyme." Mark Twain
    7. Re:Breaking the law by Opportunist · · Score: 5, Insightful

      It's ok to tell him to get the f.. out. But most people, to return the analogy to the PC, don't even care that someone is standing there, in the middle of their living room, making unsolicited phone calls from your landline, telling everyone about your tv watching habits or even stuffing your jacket pockets with leaflets. As long as they don't trash the place, most people don't care that someone is standing there, coming and going as they please, leaving the window open for any burglar that wants to come in.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    8. Re:Breaking the law by Gryften · · Score: 5, Funny

      The EtherBunny is the one that runs around anaesthetizing kids to commemorate the ressurection of Jesus, right?

    9. Re:Breaking the law by yo_tuco · · Score: 4, Funny

      "I don't know much about the laws, but it is illegal, isn't it?"

      It is legal if you wear a suit-n-tie and work in a corporate office. But if you wear a tee-shirt working from your basement, you're under arrest for unauthorized access.

    10. Re:Breaking the law by Ontheotherhand · · Score: 2, Funny

      Well. it is more draconian than american law, not underpinned by a constitution as such, but usually interpreted by a non political group of Judges so that in general it works. recent right wing hastily passed laws on anti terrorism and new fangled computer thingies not withstanding.

    11. Re:Breaking the law by Opportunist · · Score: 4, Insightful

      ...and you complaining about the reporter who told you that burglars are coming and going, because he made you look stupid. Instead of thanking him and asking him how to get rid of the burglars. Or at least cursing him and asking him how to get rid of them.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    12. Re:Breaking the law by odourpreventer · · Score: 2, Interesting

      The police still needs permission from you the property owner (the computer being your property), otherwise it is illegal.

    13. Re:Breaking the law by ciderVisor · · Score: 4, Funny

      It's more like eating a nectarine and marvelling at how juicy and delicious it is, then realising that it's not a nectarine you're eating but a human head !

      --
      Squirrel!
    14. Re:Breaking the law by Sockatume · · Score: 4, Informative

      Actually English, Scots, and US law do distinguish between performing the same act (actus reus) with different intent (mens rea). It's a common lay misconception that "doing X" is illegal. In fact, traditionally "doing X" with one intent is usually a particular crime, while "doing X" with a different intent is a lesser crime, or not illegal at all. A simple example would be injuring another human being. Firstly, the law distinguishes between a deliberate or accidental act. Further, the law distinguishes deliberate injury with the intent to defend oneself from injury, accidental injury through deliberate negligence of safety standards, etc. etc.

      I'm not sure what the mens rea is on cyber-crime in any legal system that uses the concept, mind you. And it seems that legal systems are reworking mens rea into "circumstances" to eliminate the human part of the equation, i.e. in some legal systems if you're in situation X and you do Y, that is always illegal, regardless of intent. It's likely that, given their youth, cyber-crime laws in the UK are worded as such.

      --
      No kidding!!! What do you say at this point?
    15. Re:Breaking the law by tygerstripes · · Score: 4, Insightful

      NO!!!

      Your quote diametrically refutes your posit! It is funded by the public and given a mandate of political neutrality and autonomy by that charter. That charter was issued by the government many years ago and has been essentially sacrosanct since then. The BBC is "owned" by the people, more so than the government is.

      Contemporary History, with regards to the BBC, demonstrates that they have managed to maintain that detachment and impartiality - even to the detriment of the ruling government - on many occasions. It's out of keeping with the increasingly totalitarian character of UK government, I know, but somehow the Beeb seems to be just-about maintaining its function. Whether that will continue indefinitely is anybody's guess, but for god's sake, give them credit where it's due for now...

      --
      Meta will eat itself
    16. Re:Breaking the law by debrain · · Score: 5, Informative

      Regardless of intent it is illegal. They are gaining unauthorized access to someones PC and using it for their own personal gain. If I were to demonstrate how to crack someones WEP key in 5 minutes without the victim's explicit written permission it would be illegal, even if done just for "educational purposes." Sure, it's edgy reporting, but it is still highly illegal.

      Why do you say that? These statements have no legal meaning or merit.

      I'm not overly familiar with British criminal law, per se, but I am handy in the commonwealth legal principles (having studied law in three commonwealth countries, and being a lawyer in a commonwealth country and New York state), and while anyone would need legal advice specific to their jurisdiction (i.e. none of what I'm saying is legal advice), I can say with reasonable confidence that this act of the BBC would be criminal in only two scenarios:

      1. There was mens rea, or the guilty mind, component of a criminal act; or

      2. The BBC committed a crime where mens rea is not required (viz. a crime of strict or absolutely liability).

      As the guilty mind seems to be lacking on these facts, only crimes of strict liability may be laid against the BBC. As I don't know of any strict liability crime arising from these facts, I surmise that they have not broken one, but I stand to be corrected.

      It may be a civil wrong that is a species of trespass, or that violates some statute specific to computers and/or the internet, but in the absence of provable damages by someone affected (i.e. the botnet computer owners or the DoS'd computer), there is no cause of action that would give rise to a lawsuit. The botnet owners don't know they are on a botnet, so their damages are negligible -- if anything I would argue they benefit from being taken over by the BBC as opposed to someone with actual malicious intent. The DoS'd machine is presumably one owned by the BBC.

      Even if found to be guilty of civil or criminal wrongdoing, the BBC may have a complete defence because their act was taken as part of a protected form of investigative journalism or alternatively because they are acting as a good Samaritan in the public interest. They seem to be acting with the interest of exposing to the public and documenting a very important situation on the internet. Their investigative journalism is good for the public and the owners of the botnet who may thus become aware of their participation in this grand malicious scheme. In addition to these defences, it would be bad public policy to stifle such valuable investigative journalism.

      In any case I'm confident that the lawyers for the BBC have given this due consideration. That a large, sophisticated corporation actually did this for the purpose of publication, and then did publish it, strongly suggests that it is not illegal.

      In the United States your mileage may vary (i.e. taking control of a botnet even with good intentions may be illegal). There are a large number of laws that are driven by commercial interest groups, which laws give rise to "criminality" in spite of the public's interests to the contrary. Thankfully most of the world, including the BBC, isn't generally subject to these laws.

      Please don't mislead people with sensationalistic statements like "highly illegal", without at least providing some modicum of support for these otherwise bald assertions. What criminal law do you think the BBC broke? Your post appears wholly incorrect, unsupported and misleading. It distracts from the real issues at hand, wastes readers' time, and is disrespectful to those who value facts and truth. Please consider taking the time to research your assertions before posting to a public forum like this. Thank you.

    17. Re:Breaking the law by tygerstripes · · Score: 2, Interesting

      Yes, this is illegal. There was an embarrassing attempt to cover their asses with the following:

      If this exercise had been done with criminal intent it would be breaking the law.

      There's no question of mens rea - they knew exactly what they were doing, whether or not they thought it was a crime - while actus reus is satisfied if they undertook the crime. The crime in this case was gaining unauthorised access to personal computers. "Criminal intent" doesn't come into it - they deliberately did something which is a criminal act.

      However, they won't get prosecuted. This has nothing to do with "ties to the guv'mint", and everything to do with journalistic licence. They exposed criminal activity without effecting any damage to property or reputation, and in doing so helped to inform and protect not only the several thousand people directly involved, but a whole nation of news-reading, tech-ignoring proles.

      This is exactly what investigative journalism is about. While technically they broke the law, there is a fine history of decades of case-law precedent where journalists went undercover and got involved in criminal practices purely in an effort to expose and prevent it in future.

      There's no way in hell the CPS (the body responsible for prosecuting criminal cases) would touch this. Flimsy though it may be, journalistic integrity is afforded impressive leniency in British culture and law, provided it is seen to be of public benefit.

      --
      Meta will eat itself
    18. Re:Breaking the law by tygerstripes · · Score: 4, Informative

      Almost.

      Mens Rea is almost always about your level of intent, not what you intended to do. This is important for things such as assault or murder, where intent can range from "I meant to kill him" to "I just wanted to stop him hitting me" to "I didn't know he was standing there". As such, the mens rea will affect the nature of the crime.

      However, in most cases it is merely a case of "Did you intend to do it?" In the case of burglary, for example, the only way you could argue the mens rea would be either by pleading insanity (didn't know you were doing it) or demonstrating that you thought you had the right to enter the place you entered and take what you took. You're pleading that you were not knowingly guilty of doing what you did. For the majority of crimes you can't be excused by claiming that you did it with good reason; though that may mitigate your sentencing, it won't mitigate the conviction.

      Since the crime in this case was illegal access of someone's personal computer, the crime was knowingly undertaken irrespective of what the ultimate intention was. However, as I've said in a later post, I don't think this particular case will even see the courts; nor do I think it should.

      --
      Meta will eat itself
    19. Re:Breaking the law by tygerstripes · · Score: 4, Interesting

      1. Nobody comes to arrest you. Why the hell would the police get involved? You'll get increasingly strongly-worded letters and then, eventually, a court summons.

      2. What if you don't pay your gas/credit-card/porn-subscription bill? Same story. Does that mean NPower/Barclays/shemaleswithdiseasedsheep.com is affiliated with the government?

      3. I said they were autonomous, not completely independent and uninvolved. This means they can follow that charter in whatever way they see fit.

      Know what? I'm tired of discussing this point. The Beeb's history and reputation speaks for itself. If you have a serious point then please make it, and then show me a more effective alternative. Insofar as it's possible, the Beeb is as I've described.

      --
      Meta will eat itself
  4. They paid hackers by Anonymous Coward · · Score: 2, Interesting

    It seems a bit stupid to pay the hackers, as now they will have more money to set up botnets with. I suppose if they didn't a spammer would have done anyway, at least they have a chance of shutting them down now I guess.

    Just wait until a botnet DDOS's Click's website.

  5. It gets better by blowdart · · Score: 5, Insightful

    Controlling machines without permission? Against the computer misuse act.

    They used the botnet to spam two email accounts, one at gmail and one at hotmail. That's against the computer misuse act.

    And they changed the wallpaper on the machines on the botnet. Against the computer misuse act.

    Their "justification" doesn't fly; not having criminal intent is not a defence against the law.

    1. Re:It gets better by Clipless · · Score: 3, Funny

      But it is all OK because they didn't have any "criminal intent."

      I wish I had known that was a valid argument during my little DUI incident.
      Live and Learn I guess.

    2. Re:It gets better by PhilHibbs · · Score: 4, Insightful

      Controlling machines without permission? Against the computer misuse act.

      Correct.

      They used the botnet to spam two email accounts, one at gmail and one at hotmail. That's against the computer misuse act.

      Not if it's their own hotmail and gmail accounts or if they have permission, I can spam myself if I want to, and you could spam me as well if I gave you permission.

      Their "justification" doesn't fly; not having criminal intent is not a defence against the law.

      Journalists have a high degree of freedom in this respect, there are plenty of cases of journalists smuggling guns past airport or other border security as a demonstration.

    3. Re:It gets better by Spatial · · Score: 4, Insightful

      I'd be more interested in hearing about whether you think it was the right thing to do or not, instead of shouting "You broke the rules!" like a child in a schoolyard. If they didn't do any harm it isn't very important that they broke the law. Follow the spirit, not the letter.

      Reading the article tells me: They disabled the botnet and told the computer owners afterward, and they advised them on how to secure their gear in future. They performed a DDoS on a site, but with prior agreement from the owner.

      That's thousands of people who probably learned a valuable lesson. Better to learn that way than to have their credit card details stolen, or their bandwidth used in a malicious DDoS. Given the incredible amount of PCs that are compromised in general, this would seem inevitable without some education to prevent it.

      Of course you can make a good argument that it was unethical to invade their PCs, but don't just dismiss the benefits of this out of hand. It's boring, and not really insightful at all.

  6. Not against the law??? by RingDev · · Score: 5, Insightful

    If this exercise had been done with criminal intent it would be breaking the law.

    So if I install software on your machine that you paid for, consume the bandwidth that you are paying for, burn extra electricity that is paid for by you, all with out ever even letting you know about it, so long as I'm doing it for finding a cure for cancer, it's perfectly legal?

    What if I use that bot net to distribute the load of rendering animated gaping anal gay midget porn movies? It's not a crime to render animated gaping anal gay midget porn movies, so I have no criminal intent, so it must be legal, right?

    -Rick

    --
    "Most people in the U.S. wouldn't know they live in a tyrannical state if it walked up and grabbed their junk." - MyFirs
  7. Agreed. Mod parent up. by mmell · · Score: 5, Insightful

    I've been on the bad side of this one - a lack of criminal intent does not mitigate or extenuate criminal action. Their guilt is quite plain (having been admitted, even published by the BBC itself). Now, their lack of criminal intent does have a bearing on sentencing. Inasmuch as the BBC did not wilfully cause damage or fiscal loss to anybody (except, potentially, themselves?), the sentence should be something on the light side, perhaps even suspended; but the matter of their guilt is simple black-letter law.

  8. Illegal and unethical to boot! by unsupported · · Score: 4, Insightful

    This is both highly illegal and unethical. Illegal in that they accessed the PCs without the owners permission, they sent spam, and changed the settings on the computer.

    Unethical even if their motive was not to do criminal intent.

    It is like creating a "white worm" to patch servers from an unpatched vulnerability.

    --
    Yopu for you?
  9. armchair lawyers by Anonymous Coward · · Score: 2, Insightful

    Ah, time to bring out the armchair lawyers. Nevermind that the BBC has its own legal team that reviewed this activity before it happened. I'm sure all of you know better. Especially all you Americans who are well-versed in British law.

    1. Re:armchair lawyers by xorsyst · · Score: 4, Informative

      Feel free to read the law first. It's actually quite readable, even to non-lawyers. It looks like they might have some wiggle room with clause (3)(2) to me.

      --
      Get free bitcoins: http://freebitco.in
  10. I'm sure some were in the US by JeanBaptiste · · Score: 2, Interesting

    if you go randomly grab 22,000 computers for your botnet, it's far more likely than not that some would be in the US. Even if they only targeted BBC registered users or something (didn't read TFA), there'd still be overseas users and such, some in the US. Not that I'm an expert, but I don't think they could reliably get computers from only inside GB.

    1. Re:I'm sure some were in the US by mjjw · · Score: 2, Interesting

      The BBC has a GeoIP database which they use to determine whether or not you are eligible to use services such as iPlayer. Whether or not they checked if the computers were in the UK I do not know, but they certainly could have done.

      --
      If you aren't far left by the age of 18 you have no heart. If you aren't far right by 30 you have no brain.
  11. In other news... by Dishwasha · · Score: 4, Funny

    the notorious underground computer hacking group self-labeled /. deploys over 30,000 Anonymous Cowards to take down the BBC news website by maliciously posting a link to this news article.

  12. Don't focus on the legality by Reality+Master+201 · · Score: 5, Insightful

    Everyone's going on about how it's actually illegal and the intent doesn't matter (I don't know either way - it is Britain and maybe things work differently there).

    What about the fact that some guys from the BBC were able to gain control of 20k infected machines on the web just for the purposes of doing a story? To me, the implications of that are far worse than any possible criminality.

  13. Skewed views of the law by grayn0de · · Score: 5, Interesting

    Way to go, BBC. You have moved past bringing the populace breaking news stories to creating them! I am looking forward to the next headline, regarding this. I think we all agree that gaining unauthorized access to another computer is, not only unethical, but illegal. I am surprised, being that this article is on slashdot, now, that the BBC is not already feeling the ramifications of its actions. I highly doubt they asked everyone in those chat rooms: "Hi, we are from the BBC, we would like to pwn your computer in the name of exposing cyber security risks. Is this okay, with you? Great, Thanks!"

  14. Good to know! by Exitar · · Score: 2, Informative

    "If this exercise had been done with criminal intent it would be breaking the law."

    So, if I run over a pedestrian with my car while absentminded I obviously have no criminal intent so I'm not breaking the law?

  15. British computers only? by dazedNconfuzed · · Score: 3, Insightful

    You SURE only British law applies? As noted in another post, when you start hijacking 22,000 computers on the Internet, most likely SOME of those will be in the USA (or other countries where such activity IS illegal). You sure those BBC lawyers know enough about technology to be sure that the activity was limited to British computers, and this did not actually risk becoming an international incident?

    --
    Can we get a "-1 Wrong" moderation option?
  16. Some information missing from the summary by ais523 · · Score: 4, Informative

    Once the BBC had finished with their botnet, they changed the desktop background of all the infected computers to tell people what had happened and link them to this webpage, which contains some information on how to secure Windows. Then, they uninstalled the botnet software.

    --
    (1)DOCOMEFROM!2~.2'~#1WHILE:1<-"'?.1$.2'~'"':1/.1$.2'~#0"$#65535'"$"'"'&.1$.2'~'#0$#65535'"$#0'~#32767$#1"
    1. Re:Some information missing from the summary by Yacoby · · Score: 3, Insightful

      Computer Misuse Act (1990) forbids the unauthorized modification of computer material. How is changing the desktop not modification of computer material?

  17. It is illegal by furby076 · · Score: 3, Informative

    Actually, hijacking any computer - even if you didn't do anything bad and were trying to demonstrate a security flaw - is illegal. There have been other cases in our past where someone wanted to show the flaws in security...all to end up getting arrested.

    --

    I do not support "The Man". I also do not support your irrational stupidity
  18. What?!? They destroyed it? by rnddev · · Score: 3, Insightful

    They are apparently oblivious to the fact that DDOSing a site also means saturating the connection of the PCs involved in the attack which could have a critical function within a business. Do they even know the way that the backdoor application works? Is it possible that it is spreading through local shares and otherwise wrecking havoc on some network by propagating through some unpatched exploit?

    "Click has now destroyed its botnet, and no longer controls any hijacked machines."
    This quote worries me as they don't seem to understand what they're doing. Did they click a button that said "destroy botnet"? By destroy, do they mean wipe out some critical files?

  19. Screenshot by xororand · · Score: 3, Informative

    Here's a slightly blurry screenshot of the wallpaper: http://www.heise.de/bilder/134489/0/1

  20. Clarification by awpoopy · · Score: 2, Insightful

    Let me fix that for you:
    "[The BBC] managed to acquire its own low-value botnet http://news.bbc.co.uk/1/hi/programmes/click_online/7932816.stm the name given to a network of hijacked MICROSOFT Windows computers - after visiting chatrooms on the internet. The programme did not access any personal information on the infected MICROSOFT Windows PCs. If this exercise had been done with criminal intent it would be breaking the law. But our purpose was to demonstrate botnets' collective power when in the hands of criminals." The BBC performed a controlled DDoS attack, "then ordered its slave MICROSOFT Windows PCs to bombard its target site with requests for access to make it inaccessible."
    Now it's been edited to show the facts.

    --
    I say things which affects my Karma negatively. (and I don't care) For instance; All religion is false.
  21. Re:May I know your address? by Spatial · · Score: 3, Insightful

    Why, are you going to perform a denial of furniture attack on my neighbours?

    Theft from my house is making the analogy inaccurate. They didn't take anything but a minor amount of transfer bandwidth. That's about as serious as stealing the oxygen in my house by breathing.

    The analogy would be closer if you simply got into my house without telling me (causing no damage), performed some pre-arranged DDoS with a security company who agreed to it previously, and then vacated, leaving everything as it was before you arrived. After leaving, you then proceed to tell me why you did it, how you did it and how to stop you doing it again. Later you tell the world about such things through a respected news service, in a report about the insecurity of houses like mine and the people who exploit them for profit to the detriment of others.

    In that case, I wouldn't like it much but I wouldn't want to sue you or anything either. It would be embarrassing and annoying. I'd probably become quite conscious about the crappy security of my house and fix it up.

  22. Re:The BBC Already did it by ais523 · · Score: 2, Informative

    Beat the Burglar might only have targeted volunteers, but the more recent The Real Hustle didn't. (In one episode they went and fraudulently tricked a locksmith into opening someone else's house, then went in and installed secret cameras and stole things from it. Presumably according to BBC reasoning that's OK because they gave the things back and got permission to show the footage.)

    --
    (1)DOCOMEFROM!2~.2'~#1WHILE:1<-"'?.1$.2'~'"':1/.1$.2'~#0"$#65535'"$"'"'&.1$.2'~'#0$#65535'"$#0'~#32767$#1"
  23. Unbelievable by ppentz · · Score: 5, Insightful

    Ugh, I can't stand the attitude here. Botnets are a HUGE problem. People need to know if their PCs are hijacked and they need to be fixed. If my PC is hijacked, I want to know about it. Now. When someone's PC is used in a DDOS attack, isn't that illegal activity? I've always heard that ignorance of the law is not an excuse, so if someone is not aware their PC is being used illegally, their PC is still being used for illegal purposes ... should they be held accountable? If there is an activity that is *questionably* legal but can potentially help with the Botnet problem, I'm all for it.