In case you haven't already seen the video, the BBC decided to do a little investigation into how easy it was to acquire, use and deploy a small botnet against a particular web site for a segment on their tech show Click.
Here's what they uncovered:
So, the Click investigators managed to DDoS a honeypot web site with just sixty-odd computers' worth of traffic. (Botnet owners must be loving all these new DSL packages with high-speed upload.) Before self-destructing the network, they also (very sensibly, in my opinion) changed the background image of all infected botnet hosts. The image contained had a detailed description of how that machine was compromised, along with a link to a special page on the BBC Click web site which explained how to go about securing the system.
Personally, I think they did the Internet a service - unfortunately this comes at a time when everybody is scrutinising everything the Beeb is doing, and they've been in the spotlight a little too much recently. Some are harping on about how this was a breach of the law (and with a rigid interpretation of the Computer Misuse Act, it most definitely was); we have people like Graham Cluley, the regular Sophos spokesperson, offering the anti-virus manufacturer's slightly condescending take on events. Others are also debating the legality - Click's producers have claimed that as there was no malicious intent behind their actions, they didn't breach the Law, some are pointing out that technically, the Law has been broken irrespective of intent. Struan Roberrtson from Pinsent Masons pointed out that;
"The Act requires that a computer has been made to perform a function with intent to secure access to any program or data on the computer," he said. "Using the botnet to send an email is likely to satisfy that requirement. It also requires that the access is unauthorized — which the BBC appears to acknowledge.
"It does not matter that the BBC’s intent was not criminal or that someone else created the botnet in the first place." Still, Robertson said prosecution was unlikely because the exercise apparently did no harm and "probably did prompt many people to improve their security." The BBC responded that there was 'a powerful public interest in demonstrating the ease with which such malware can be obtained and used,' and that the network "has strict editorial guidelines for this type of investigation, which were followed to the letter."
I fall in line with the latter way of thinking on this - the BBC mention that they consulted their own lawyers before conducting this experiment so they must feel they have a fairly solid case for avoiding penalty. I suspect their culpability is limited as many thousands of the machines were most likely situated outside of the United Kingdom, bringing the scope and geographical constraints of our lovely British law into question. (Without extraditing the entire upper management of the BBC, I suspect there's little way the Corporation could be tried in a court of law for what they have done overseas).
More importantly, are the rest of us justified, as responsible netizens (as many of us claim to be, or would at least like to believe), in the belief that we can criticise the BBC's actions and call them out for dirty tricks here? For some of their past actions, maybe; this time: no. Personally, I think they've done the Internet a service. Not only have they taken a (small) botnet out of action, but they've helped illustrate just how easy it is to acquire a pool of compromised resources and hammer a web site into submission.
As a few more clueful people have observed, what Click unfortunately didn't spend enough time highlighting (probably due to time constraints) is the ease with which the true malicious users seem to be able to avoid getting caught when buying and selling access to these botnets. There must be a large amount of shady transactions taking place for unnamed or suspect items - and Internet payment services are effectively allowing these to happen. Why can't e-money services like PayPal watch for, and flag, transactions which might be related to payment for these kinds of nefarious darknet services?
Update: the BBC responded shortly after with a press release, along with a feature from Mark Perrow which fleshes out their reasoning and underlying motivation for the investigation on their Editors' Blog. The short statement is as follows:
"There is a powerful public interest in demonstrating the ease with which such malware can be obtained and used; how it can be deployed on thousands of PCs without the owners even knowing it is there; and its power to send spam email or attack other websites undetected. This will help computer users realise the importance and value of using basic security techniques to defend their PCs from such attacks.
The BBC has strict editorial guidelines for this type of investigation which were followed to the letter. At no stage was any other data other than the IP address used. We believe that as a result of the investigation, computer users around the world are now better informed of the importance and value of using basic security techniques to defend their PCs from attacks."
I still think this was a well-considered and justified insight into the underbelly of the interwebs, and if it raised peoples' awareness (and helped a few thousand people secure their machines) then surely the BBC has done the world a small favour? This invokes consideration of the classic White Hat / Grey Hat / Black Hat issue... Would you do something borderline (or completely) illegal if it was morally or ethically justified - or in the interest of the common good - in the long run? I'm not sure if I would (but then again, I can't hide behind a Corporation!)
Tags: bbc, botnet, Click, Computer Misuse Act, darknet, hacking, hot water, investigation, laws, news, technology
So good, even I want one! And I hate Macs!
Tags: Apple, cult of mac, gadgets, Mac, ONN, parody, parody... or is it, technology
I love beginnings of years, they're really exciting technology-wise. With CES on right now, and more big tech news to come, we're going to be seeing a bucketload of new standards and revisions to existing ones, new formats (and revisions to existing ones!) and new discussions (and revisions... you get the point). Data portability and agnosticism is going to be the next big thing, and as if this wasn't enough, the topic was recently highlighted by the farce surrounding Robert Scoble being banned (and subsequently unbanned) from Facebook by scraping his contacts' details to import them into one of his other accounts... In years to come, our children will look back and laugh when they're told that we had to sign up for each web site separately!
Taken your pinch of salt yet? Right, some of the key emerging trends (I predict) are going to include:
- DRM-free audio and video content! (finally!)
- Open platforms (want to do anything with any site you're a member of? Sure, here's our API, go mad)
- Widespread CSS3 support
- Data Portability (more at dataportability.org) (which also encompasses the nascent APML and existing standards like OpenID and microformats)
... And they're just a few. Blanket HSDPA 3G coverage and the rollout of HSUPA (fast download and upload speeds, versus just fast download) is going to be the next big thing in the mobile connectivity arena - and in my opinion this has been long overdue. HSDPA is great, but the upload really stymies any real rich media interactivity - 3G video calling is awful quality because of the poor upload, and that's its main problem. As soon as the quality reaches a good enough threshold to become bearable, mobile operators will find their revenues (and usage) skyrocketing.
The TV industry's going to see a lot more convergence and shift from traditional broadcasting to IP-based shiftcasting (to coin a term) - the iPlayer's already gaining in its popularity (moreso since the site revamp, offering on-demand in-browser Flash Video streams of their downloads) and IPTV is most likely going to start to usurp your regular broadcasts, particularly given the increasing spread of high-speed broadband connections and all-in-one STBs. If you've not got some form of digital receiver in your home yet, I think it's definitely time to get one.
Broadband's just getting faster and faster, but super-fast, very short range data standards are going to be the next big thing in the home (ultra wideband support in AV devices is going to be killer when it comes to market). Sony announced its own version of short-range, high-speed (500mbps) wireless data connectivity at CES today (make that yesterday, now), so if they're bringing to market, expect others to follow suit. It's a no-brainer really, why bother with wires if you can just sit your camera on top of its dock?
Wireless charging is what I'm really holding out for, but I'm not expecting even protypes of that until at least Q1 2009.
Hopefully, 2008 will also be the year the UK begins to go fully HD (HD on Freeview is the next big step for the industry to take, though it's mired in problems and negotiations at the moment) - and hopefully I'll finally get myself an HDTV this year! That's the most important potential development of the next twelve months ;)
Tags: 2008, connectivity, data, emerging, hd, high definition, hsdpa, hsupa, itu, mobile, portability, prediction, technology, trend
I know that whenever something comes over from the US (or Japan), the price conversion is more often than not a straight $ -> £ conversion (so $20 would equal £20, even though at present $20 is only worth £10). This has really hacked me off, and the iPhone is no exception - the 8Gb model going on sale in the UK for £269, equivalent to $542 (given that £1 = ~$2). In the US, the 8Gb model is on sale for $369. What really spurred me on was reading the SiliconValley.com article about O2 being announced as the exclusive UK carrier (Dear god, they must have been desperate for the custom, O2 is one of the worst networks in the UK - I should know, I was dicked about for 12 months by them before moving to T-Mobile!) The article wrote off the higher UK price to "value added tax." Well, it's not all VAT, and here's my quick maths to prove it:
(All sums done with Google btw because I'm lazy and it has currency conversion built in, and decimals rounded up to nearest £ or $ because that's what they all do anyway.)
# globals
let VAT = 17.5%, or 1.175
let $1 = $2.015 (thanks Google)
VAT-inclusive UK price in USD: $536 = £266 according to the article, but £269 from Google = $542. For the sake of simplicity, let's go with the article's figure.
£269 (UK sale price for 8gb model) x.85 = £228.65 before VAT = $462.
$536 (UK sale price VAT incl.) - $397 (US sale price) = $139 difference = £69 difference.
$397 (US sale price) = £197 in GBP (plus VAT).
Now, if the world was fair, we should be being charged £200 (well, £197, 'but what's £3 between friends,' quipped Steve Jobs).
Therefore,
£200 x 1.175 = £235 with VAT, which is what we *should* be being charged for the 8Gb iPhone. Ha.
So, somewhere, somebody's making £34 to £35 on each sale ($70, by the current exchange rate). Maybe it's for Ives' pension fund? And, even though I don't think the iPhone is a particularly great device save for two things - its multi-touch interface and its form factor - I still get really annoyed when companies bring their products to the UK and rip us off. The iPhone's not the most spectacular example of this, consoles and PCs being much worse for this problem, but it still hacks me off. If you're planning on becoming a beta tester for a new product (i.e., early adopter), you really have to have a fat wallet to survive this kind of hobby.
And yeah, if you're wondering, I have posted this elsewhere, I am active in more than one place on the Internet. ;)








