Showing posts with label news. Show all posts
Showing posts with label news. Show all posts

In case you haven't already seen the video, the BBC decided to do a little investigation into how easy it was to acquire, use and deploy a small botnet against a particular web site for a segment on their tech show Click.

Here's what they uncovered:





So, the Click investigators managed to DDoS a honeypot web site with just sixty-odd computers' worth of traffic. (Botnet owners must be loving all these new DSL packages with high-speed upload.) Before self-destructing the network, they also (very sensibly, in my opinion) changed the background image of all infected botnet hosts. The image contained had a detailed description of how that machine was compromised, along with a link to a special page on the BBC Click web site which explained how to go about securing the system.

Personally, I think they did the Internet a service - unfortunately this comes at a time when everybody is scrutinising everything the Beeb is doing, and they've been in the spotlight a little too much recently. Some are harping on about how this was a breach of the law (and with a rigid interpretation of the Computer Misuse Act, it most definitely was); we have people like Graham Cluley, the regular Sophos spokesperson, offering the anti-virus manufacturer's slightly condescending take on events. Others are also debating the legality - Click's producers have claimed that as there was no malicious intent behind their actions, they didn't breach the Law, some are pointing out that technically, the Law has been broken irrespective of intent. Struan Roberrtson from Pinsent Masons pointed out that;


"The Act requires that a computer has been made to perform a function with intent to secure access to any program or data on the computer," he said. "Using the botnet to send an email is likely to satisfy that requirement. It also requires that the access is unauthorized — which the BBC appears to acknowledge.

"It does not matter that the BBC’s intent was not criminal or that someone else created the botnet in the first place." Still, Robertson said prosecution was unlikely because the exercise apparently did no harm and "probably did prompt many people to improve their security." The BBC responded that there was 'a powerful public interest in demonstrating the ease with which such malware can be obtained and used,' and that the network "has strict editorial guidelines for this type of investigation, which were followed to the letter."


I fall in line with the latter way of thinking on this - the BBC mention that they consulted their own lawyers before conducting this experiment so they must feel they have a fairly solid case for avoiding penalty. I suspect their culpability is limited as many thousands of the machines were most likely situated outside of the United Kingdom, bringing the scope and geographical constraints of our lovely British law into question. (Without extraditing the entire upper management of the BBC, I suspect there's little way the Corporation could be tried in a court of law for what they have done overseas).

More importantly, are the rest of us justified, as responsible netizens (as many of us claim to be, or would at least like to believe), in the belief that we can criticise the BBC's actions and call them out for dirty tricks here? For some of their past actions, maybe; this time: no. Personally, I think they've done the Internet a service. Not only have they taken a (small) botnet out of action, but they've helped illustrate just how easy it is to acquire a pool of compromised resources and hammer a web site into submission.

As a few more clueful people have observed, what Click unfortunately didn't spend enough time highlighting (probably due to time constraints) is the ease with which the true malicious users seem to be able to avoid getting caught when buying and selling access to these botnets. There must be a large amount of shady transactions taking place for unnamed or suspect items - and Internet payment services are effectively allowing these to happen. Why can't e-money services like PayPal watch for, and flag, transactions which might be related to payment for these kinds of nefarious darknet services?

Update: the BBC responded shortly after with a press release, along with a feature from Mark Perrow which fleshes out their reasoning and underlying motivation for the investigation on their Editors' Blog. The short statement is as follows:

"There is a powerful public interest in demonstrating the ease with which such malware can be obtained and used; how it can be deployed on thousands of PCs without the owners even knowing it is there; and its power to send spam email or attack other websites undetected. This will help computer users realise the importance and value of using basic security techniques to defend their PCs from such attacks.


The BBC has strict editorial guidelines for this type of investigation which were followed to the letter. At no stage was any other data other than the IP address used. We believe that as a result of the investigation, computer users around the world are now better informed of the importance and value of using basic security techniques to defend their PCs from attacks."




I still think this was a well-considered and justified insight into the underbelly of the interwebs, and if it raised peoples' awareness (and helped a few thousand people secure their machines) then surely the BBC has done the world a small favour? This invokes consideration of the classic White Hat / Grey Hat / Black Hat issue... Would you do something borderline (or completely) illegal if it was morally or ethically justified - or in the interest of the common good - in the long run? I'm not sure if I would (but then again, I can't hide behind a Corporation!)

We thought we could make money on the Internet, but while the Internet is new and exciting for creative people, it hasn't matured as a distribution mechanism to the extent that lets you trade real and immediate opportunities of income for the promise of online revenue. It will be a few years before digital distribution of media on the Internet can be monetised to an extent that necessitates content producers to forego their fair value in more traditional media.

-- Kyle Broflovski to Stan Marsh, Canada On Strike
So, thought for the day: If a fictional nine year old can explain, in a nutshell, why the Internet doesn't work as a distribution mechanism, why can't the music and movie industries seem to understand that we're still only really playing in the sandpit when it comes to legal digital content? Once the traditional industry heavyweights let the technology organically progress and develop into a ubiquitous distribution channel, letting things like broadband availability and speed, format support and hardware plateau, then they can monetise it. No sooner. We'll look back in five/ten years and see how iTunes was nothing more than a brief (and well-marketed) flash in the pan.

Moving on now - well, hasn't this past week been eyebrow-raising? MySpace officially announcing their (expected) music offering, with three of the four majors on board and the fourth expected to join suit shortly. A hooray! for DRMless downloads, but a booooo! for going with MP3. Another hooray! for (like Amazon) forcing the music labels' hand though on the DRM issue, the fight between AmazonMP3 and MySpace Music is going to a good one if they both continue apace. Though, all that aside, when you have some record labels forging ahead of the curve and going / already offering FLAC or WAV lossless audio for only a little more than MP3s, it makes you wonder why we're still paying so much for digital music - and we're putting up with it!

I know a little about this: for the past nine months I've been on work placement at a small indie label. Our primary revenue stream is iTunes thanks to our 30-year back catalogue, but we still get a pittance in terms of money we actually see from sales. People would be surprised if they found out how little we get from each sale. Only the dominant vendor is the real winner in any online distribution scenario, as they have little overheads, instant content for monetisation, and in this case iTunes also has the closed - and somewhat captive - userbase (for the moment).


TheNextWeb 2008 looked like a big success - a shame the web streaming completely gave up when Diggnation was being filmed. Still, we had a Dutchman telling post-watershed jokes on a live webstream at 5pm, Jim Louderback (bless him) not dropping or breaking something on-stage for once (watch near enough any DL.TV episode he's featured in to see what I mean). And if that wasn't enough, Kevin Rose and Alex Albrecht turned up half an hour late, got ludicrously drunk on stage, were accosted at various points by a kilt-adorned Scotsman and a cheeky PR guy - and to top it off, there was a girl wearing a moustache. I also didn't have to pay $1,000 to watch the live stream. That, and no cost of plane ticket and accommodation to get there... I class that as a win.

In the UK, Ofcom announced their decision and their initial roadmap for digital terrestrial TV's migration to HD [free registration required], and not everybody's happy with them... likewise, the Freeview Consortium's relative inaction (or inability) to wrangle a good solution for the future of digital terrestrial broadcasts, combined with their apparent hatred for good programming and worthwhile use of the available spectrum has irked quite a few people (myself included). My housemate even wrote an open letter to them.

Oh, and in other news, I'm putting together a brand new design for ITU. The current look (Glossy Blue by Nick La, found via BlogCrowds) worked well as a placeholder while I gathered my ideas together, but I hate basing sites on templates (however good they are)... Any designer will know what I mean when I say "It just doesn't feel 'mine' 'til I've done the design." (A poet and I don't know-et.)

Until next time, stay classy.

I was going through the server logs on one of my (pretty much unadvertised) blogs (uniblog.co.uk) when I started noticing a LOT of hits from bots all calling themselves "Onfolio/3.0 Beta 2".

Since I'd never heard of this, I went exploring... Turns out it was a maturing web service which seems to aggregate online content and research which was recently acquired by Microsoft. From their site,

Onfolio is an add-in for the Windows Live Toolbar that helps you collect and organize online content, read RSS news feeds, and share content in emails, blogs and documents. With Onfolio, you get all of these tools built into your browser for simplicity. Whether you are planning a trip, looking for a job, investigating a major purchase, or simply looking for a better way to keep up with the news that interests you, Onfolio will help you be more efficient, thorough and organized.


From what I see, there's either existing or planned development of:


  • Blogging and commenting integration

  • News aggregation via XML/RSS

  • Collaborative researching and sharing of information

  • Creating an archive of files, research and other miscellanea for retrospective review

  • Tight(er) integration into the browser to complement standard searching



... and more besides. There's loads of info on the OnFolio site.

I've had loooooooads of hits from various IPs in various subnets, but all with reverse DNSes ending in .as9105.com - one which I recognise from past experience as a Freeserve-now-Tiscali AS.

So, is it just pure coincidence that loads of (only) Tiscali users are using the OnFolio IE Search Toolbar plugin, or is there something else going on? All the IPs I checked out resolved to dynamically-assigned IPs in the ADSL ranges (194-247-239-150.dynamic.dsl.as9105.com [194.247.239.150] and 212-1-142-110.dynamic.dsl.as9105.com [212.1.142.110] are two examples) but for the life of me I can't quite work out why there's no requests from anywhere else aside from Tiscali subnets!

Anyway, this tool looks quite nifty - all the requests have been for my XML feeds, which I assume ties in with the ability of the software to aggregate news via RSS (go figure) but still, I'd not really heard about this at all and now all of a sudden looks like they're gearing up to a larger webcrawl to get their content together. And if they're spidering my little old web sites... They must be nearing out-of-beta.

So, go check out OnFolio - now owned by Microsoft (hiss) but it still looks fairly cool to use if you're into your inline toolbar widgets. There's also an OnFolio Group Blog if you're thusly-inclined, I'm pretty sure if you had any more questions about the service or where it's headed, they're all answered on there.


 

Copyright 2006 onwards Christopher Woods. Some Rights Reserved.
ITU uses a (highly) modified version of the K2 theme by GeckoandFly,
originally Bloggerised by Blogcrowds. Credit where credit's due. :)


Into The Unknown is licenced under a Creative Commons License.
(Attribution-Share Alike 2.0 UK: England & Wales, Some Rights Reserved).

Creative Commons License