BBC Rents a Russian Botnet and Spams and DOSes in Name of Journalism   - 787 Views,

Summary: The BBC is under fire today for a stunt that it pulled a few days ago, in which it rented a Russian bot net (also sometimes called a spam bot), and then sent millions of pieces of spam, and DOSed a corporate server.

Previous Article « Worst Problem on the Internet is Stupid Users, Survey Says
Read Next Article » Criminal Uses Google Maps to Steal Roofs Off Buildings

  Follow Anne on Twitter     Friend Anne on Facebook

The BBC is under fire today for a stunt that it pulled a few days ago, in which it rented a Russian botnet (also sometimes called a spambot), and then sent millions of pieces of spam, and DOSed a corporate server.

For a piece for the BBC program “Click”, the BBC went to Russia to determine, they said, “just how sophisticated cybercrime has become.” For the sum of a few thousand dollars, they rented a botnet that was made up of 21,696 compromised PCs the world over.

According to the BBC, it was so easy to operate the botnet, that “anyone could do it.”

Controlling the botnet, the BBC then proceeded to send out a large run of spam - to themselves. That is, to email addresses that they had registered, at both Gmail and MSN/Hotmail.

Of course, they don’t own the servers that host those email addresses, so in the doing, they also spammed Google and Microsoft.

They then turned the botnet to another task: that of DOSing a server belonging to security firm Prevx. This was by agreement with Prevx, although most likely, again, not with the agreement of Prevx’ host and upstream providers (although of course we don’t know for sure).

The BBC’s rationale for this was that, again, they wanted to see just how sophisticated cybercrime had become, and to educate their readers (and persumably users) about the dangers of botnets.

In fact, after they were done, they left a message on each of the 21,696 compromised PCs, telling the PC owners that their machine had been part of the botnet, and then they dismantled the botnet (at least, that is what they claim - how they would have done that has not been revealed, and if they did do that, it seems that there would be several Russian criminals looking to kneecap them right now, at least).

The big issue that everyone has with this - about which all the news outlets are taking - is this: did the BBC break the law in doing this? Was what they did legal - or illegal.

The answer to these questions is complicated, not the least of which by the fact that the BBC is a British entity, and so subject to British computer security laws such as the Computer Misuse Act (CMA), but they also intentionally commited acts in the U.S. (where Google and MSN’s servers are), and have a pronounced U.S. presence. So even if their legal advisors told them that what they were going to do was legal in Britain (as the BBC claims they were told), that would not shield them from legal issues in the U.S. - or, indeed, anywhere that their actions seriously and negatively impacted computer or other resources.

When I was interviewed about this by the Tech Herald, I explained that “First, it is of course illegal to use a botnet. This is because by its very definition, a botnet consists nearly entirely of private computers which have been illegally trespassed upon.” We discussed several other legal issues that arose from what the BBC had done, at the end of which I concluded that “the other side of that is that U.S. law also gives great protection to the press, which I’m sure the BBC would attempt to invoke if there were any legal action here. All that said - do I think that any legal action will result from this? Probably not. And, if it does, it’s anybody’s bet as to which way it would be resolved.”

(You can read all of my comments in the Tech Herald here, and you can read the full Tech Herald article here.)

So, what do you think about these issues? Brave journalism? Dunderheaded illegal stunt? Or a bit of both?

BBC Rents a Russian Botnet and Spams and DOSes in Name of Journalism

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Worst Problem on the Internet is Stupid Users, Survey Says
Read Next Article » Criminal Uses Google Maps to Steal Roofs Off Buildings

Read more:

»  The Real Profile of a Zombie Botnet Waking Up and Taking Over an ISP’s Customers Computers

»  Russian Dating Scam Hits Match.Com, Other Dating Sites

»  Get Your Drugs Through WiFi! Wireless Technology Used to Deliver Drugs

»  AOL Sues Instant-Message Spammers (with Apologies to Dr. Seuss)

For additional similar stories check out our archives on Around the World, Internet Law, What Do You Think?

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 3/17/2009
The Internet Patrol
Patrolling the Internet for You!