Showing posts with label laws. Show all posts
Showing posts with label laws. Show all posts

In case you haven't already seen the video, the BBC decided to do a little investigation into how easy it was to acquire, use and deploy a small botnet against a particular web site for a segment on their tech show Click.

Here's what they uncovered:





So, the Click investigators managed to DDoS a honeypot web site with just sixty-odd computers' worth of traffic. (Botnet owners must be loving all these new DSL packages with high-speed upload.) Before self-destructing the network, they also (very sensibly, in my opinion) changed the background image of all infected botnet hosts. The image contained had a detailed description of how that machine was compromised, along with a link to a special page on the BBC Click web site which explained how to go about securing the system.

Personally, I think they did the Internet a service - unfortunately this comes at a time when everybody is scrutinising everything the Beeb is doing, and they've been in the spotlight a little too much recently. Some are harping on about how this was a breach of the law (and with a rigid interpretation of the Computer Misuse Act, it most definitely was); we have people like Graham Cluley, the regular Sophos spokesperson, offering the anti-virus manufacturer's slightly condescending take on events. Others are also debating the legality - Click's producers have claimed that as there was no malicious intent behind their actions, they didn't breach the Law, some are pointing out that technically, the Law has been broken irrespective of intent. Struan Roberrtson from Pinsent Masons pointed out that;


"The Act requires that a computer has been made to perform a function with intent to secure access to any program or data on the computer," he said. "Using the botnet to send an email is likely to satisfy that requirement. It also requires that the access is unauthorized — which the BBC appears to acknowledge.

"It does not matter that the BBC’s intent was not criminal or that someone else created the botnet in the first place." Still, Robertson said prosecution was unlikely because the exercise apparently did no harm and "probably did prompt many people to improve their security." The BBC responded that there was 'a powerful public interest in demonstrating the ease with which such malware can be obtained and used,' and that the network "has strict editorial guidelines for this type of investigation, which were followed to the letter."


I fall in line with the latter way of thinking on this - the BBC mention that they consulted their own lawyers before conducting this experiment so they must feel they have a fairly solid case for avoiding penalty. I suspect their culpability is limited as many thousands of the machines were most likely situated outside of the United Kingdom, bringing the scope and geographical constraints of our lovely British law into question. (Without extraditing the entire upper management of the BBC, I suspect there's little way the Corporation could be tried in a court of law for what they have done overseas).

More importantly, are the rest of us justified, as responsible netizens (as many of us claim to be, or would at least like to believe), in the belief that we can criticise the BBC's actions and call them out for dirty tricks here? For some of their past actions, maybe; this time: no. Personally, I think they've done the Internet a service. Not only have they taken a (small) botnet out of action, but they've helped illustrate just how easy it is to acquire a pool of compromised resources and hammer a web site into submission.

As a few more clueful people have observed, what Click unfortunately didn't spend enough time highlighting (probably due to time constraints) is the ease with which the true malicious users seem to be able to avoid getting caught when buying and selling access to these botnets. There must be a large amount of shady transactions taking place for unnamed or suspect items - and Internet payment services are effectively allowing these to happen. Why can't e-money services like PayPal watch for, and flag, transactions which might be related to payment for these kinds of nefarious darknet services?

Update: the BBC responded shortly after with a press release, along with a feature from Mark Perrow which fleshes out their reasoning and underlying motivation for the investigation on their Editors' Blog. The short statement is as follows:

"There is a powerful public interest in demonstrating the ease with which such malware can be obtained and used; how it can be deployed on thousands of PCs without the owners even knowing it is there; and its power to send spam email or attack other websites undetected. This will help computer users realise the importance and value of using basic security techniques to defend their PCs from such attacks.


The BBC has strict editorial guidelines for this type of investigation which were followed to the letter. At no stage was any other data other than the IP address used. We believe that as a result of the investigation, computer users around the world are now better informed of the importance and value of using basic security techniques to defend their PCs from attacks."




I still think this was a well-considered and justified insight into the underbelly of the interwebs, and if it raised peoples' awareness (and helped a few thousand people secure their machines) then surely the BBC has done the world a small favour? This invokes consideration of the classic White Hat / Grey Hat / Black Hat issue... Would you do something borderline (or completely) illegal if it was morally or ethically justified - or in the interest of the common good - in the long run? I'm not sure if I would (but then again, I can't hide behind a Corporation!)

... And that N is Nanaimo. Google's been busy; its latest venture has been the analysis, assimilation and compilation of just about all public data for a town in British Columbia, Nanaimo. No doubt this was part of their Master Plan all along (what happened to Don't Be Evil?), but it seems that nothing is beyond their reach these days.

For example, want to know where the fire engines are, and how many calls there have been today, this week or this month? Just click through to their web site for realtime statistics. Want street-level imagery of the entire town? Fire up Google Earth and there you go. And if that made you go 'wow', that's not the only stuff they can show you;

"With Nanaimo, they have mapped nearly every conceivable thing using Google Earth and Google Maps," Michael Jones, Google Earth's chief technology officer, said last August at a conference in Vancouver. "Their citizens have more information about their city than the people of San Francisco."

All hail the all-seeing-Google! Google knows all! For a while now, Street View vans have been making their way through our towns and cities (my housemate recently showed me his street level journey into Las Vegas, from hotel to convention centre, after returning from this year's CES. It wasn't just aerial view, it was street by street and junction by junction, at ground level, in 3D - a very odd experience). At the same time, businesses are moving their email and work-related info over wholesale to Google-based platforms, plus we have the millions of individuals using Google by default as their launchpad into the Web - no doubt the big G's getting some very nice statistics to refine their advertising algorithms with. Does anybody else find it a little disconcerting that there's a select few companies who are getting the lion's share of our personal and public data, aggregating it and then doing some deep analysis on it to glean all they can from it? Where does it stop? Will Google or start buying statistical information from retailers (e.g. Tesco's Clubcard scheme) to further profile you and put you into a socio-economic profile - then offer you services accordingly?

The retention, analysis and resale of personal data is a hot topic at the moment, so it seems oddly appropriate that I be discussing an entire town's data being collected and analysed by the world's largest search engine (and one of the world's largest holders of 'anonymous' web usage statistics?) It's particularly prescient given the recent debate and discussion surrounding the introduction of Phorm to several UK ISPs (and one ISP, TalkTalk, announcing that they'd changed their gameplan and are were going to only introduce Phorm on an opt-in basis, as opposed to a blanket opt-in with a partial opt-out).

Presently, I don't think the majority of consumers understand or care about the extent to which they're profiled on the web, largely because they either consider it to be unrealistic (but the future is today!) or they haven't been educated to the benefits and dangers correctly of what these kinds of ventures could entail.

Either way, for me, it's partly the ethics and partly the fact that it's a 'foot in the door' for just about anybody, public sector or Government, to ramp up the amount by which citizens are monitored, profiled, maybe even targeted for surveillance... Are we, as citizens, unwittingly handing over some of our crucial rights as individuals to the great cloud in the sky, only to realise too late we've handed over some of the very things that grant us privacy and peace of mind in our own lives?

This is great news! On top of the announcement fron Fon the other day that they're teaming up with BT to offer all their Total Broadband customers the chance to get a Fon wifi router (and share some of their wifi), McDonald's has just announced that they're going to offer free Wifi in partnership with TheCloud.

Now, normally you have to pay for TheCloud access, so that's very nice indeed. It also means that I can sit in the much posher upmarket sandwich shop with my laptop next to McDonald's in the centre of Brum and use their free wifi ;) It does make me wonder to an extent as to how vulnerable BT users are with regards to lawbreaking (because it's already acknowledged that running an insecure hotspot allows others to perpetrate IP theft and other cybercrime, punishable by UK law, and there's not much they can do to stop it), but I suppose BT is willing to take this into account - or just doesn't care - if it happens once BT users start opening up their networks.

I'm a little more worried for newbie home users, because they're the ones who may well become compromised security-wise. Back in January I had to make our wireless access point open for a couple of days (because one of our housemates was having problems connecting, something I eventually sorted out) but in the meantime someone who lives in the vicinity of us managed to get onto my laptop's root drive, save an RTF file to the root dir and inside write me a rather worrying message! I'm still figuring out how they managed to do that, because my Windows shares are pretty secure and I use strong passwords combined with an in/egress firewall... They must've done something along the lines of sniffing the wifi signal to retrieve some NTLM or MD5 hashes of my password, and then bruteforced their way onto my machine. A little bit worrying, but that was in January and my network setup is a lot stronger than it was back then. If I can have a machine compromised, it doesn't bode well for newbie users who just turn on and go with Windows Firewall. I may have even been compromised via my own La Fonera... Still investigating.

Back to business, however, and thinking about Fon, I must get round to posting my review of my La Fonera sometime! It's already been taken apart, photographed, examined, compared and praised/criticised, I've already done my own testing so I have my own real life results to post up! Might as well, I have them all on my laptop.


 

Copyright 2006 onwards Christopher Woods. Some Rights Reserved.
ITU uses a (highly) modified version of the K2 theme by GeckoandFly,
originally Bloggerised by Blogcrowds. Credit where credit's due. :)


Into The Unknown is licenced under a Creative Commons License.
(Attribution-Share Alike 2.0 UK: England & Wales, Some Rights Reserved).

Creative Commons License