BBC uses botnet to hack 22,000 unsuspecting users

happygeek 0 Tallied Votes 549 Views Share

Botnets are, without any doubt, a huge and growing problem. The technology news feeds are bursting to the seams with stories about them: how botnets boost click-fraud rates, how botnets control sex spam zombies, how the cyber-criminals are and even how some botnet builders are selling their wares complete with guarantees that they cannot be detected.

However, one thing you do not expect to read about is the people behind the news stories, the reporters themselves, being involved in acquiring a botnet which hacks into the computers of some 22,000 people. Yet that is exactly what seems to have happened over in the BBC newsroom. The makers of the BBC news technology show 'Click' have proudly announced that, as part of an investigation into global cyber crime, they acquired a 'low value botnet' and then spammed users in order to get them infected. The exercise proved successful, so successful that almost "22,000 computers made up Click's network of hijacked machines" according to the BBC.

It then launched a Distributed Denial of Service attack against a test site owned by security specialists Prevx, with the agreement of the company concerned. By bombarding the target site with requests for access the site was made inaccessible very quickly, and with the use of only 60 of the compromised machines within the botnet itself.

The BBC are quick to point out that it has warned all 22,000 people that their PCs are infected, as well as advising them on the best way to prevent such an infection happening again. It has also stated that it did not access any personal data held on the infected computers.

The BBC claims that because it was only done with an intention to demonstrate the collective power of the botnet when in the hands of criminals, and it itself had no criminal intent, it was not breaking the law. When it comes to ethics, though, it sucks elephants through a straw backwards.

Well I wish them luck with that one, although I suspect the BBC lawyers did their homework before allowing this stunt to go ahead. I am all for exposing security issues, and have been known to top toe around the law in order to get the evidence myself in the past. But I am not sure what this particular exercise proves other than botnets are bad and DDoS attacks are bad. The BBC really did not need to infect the computers of 22,000 innocent folk in order to tell us what we already know.

Dani AI

Generated

Good thread — raises the ethical concern and is right to flag the legal risk. Two clarifying points that help evaluate this kind of stunt: what the law actually criminalises, and what safer, defensible research practices look like.

The UK Computer Misuse Act targets both unauthorised access and unauthorised acts that impair computers (the provision typically applied to DDoS-style conduct). Prosecutors also apply a public‑interest test to media cases, but that test does not give journalists a blanket immunity from criminal liability; each case is judged on the evidence and proportionality. See the Act and the CPS guidance for how those elements are assessed. (Computer Misuse Act — s.3) (CPS: media & public interest guidance).

Security researchers and newsrooms that need to demonstrate threats can do so without commandeering other people’s machines. Established ethical frameworks and practitioner codes recommend balancing benefit and harm, minimising risk to bystanders, and documenting informed legal oversight. Useful guidance includes the Menlo Report on ICT research ethics and the Honeynet Project’s rules for sinkholing/takedowns. (Menlo Report) (Honeynet Project: ethics).

Practical, lower‑risk alternatives (best practice):

  • run lab simulations or use instrumented honeypots rather than live infections;
  • partner with CERT/LEA and get written authorisations before active experiments;
  • use sinkholes or passive telemetry and aggregate results (no remote modification);
  • coordinate with ISPs and affected vendors and publish remediation steps;
  • get independent legal sign‑off and an ethical impact assessment before filming.

The BBC episode sparked heavy criticism in the security press while some vendors defended the public‑interest intent; the dispute shows why transparency, minimal collateral harm, and documented legal/ethical review matter. (example coverage of the debate).

jbennet 1,618 Most Valuable Poster Team Colleague Featured Poster

The BBC are gonna get in trouble

The computer misuse act is quite strict.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.