Showing posts with label Eircom. Show all posts
Showing posts with label Eircom. Show all posts
Monday, March 26, 2012
Eircom admits user disconnection is illegal; wants other Irish ISPs to do it anyway
You couldn't make it up. Eircom, not content with shooting itself in the foot by agreeing to introduce a "three strikes" system which wasn't required by the law, now wants its rivals to do the same. Presumably that would be the same three strikes system which Eircom's head of public policy has admitted is in breach of European law.
Wednesday, January 25, 2012
Ireland's SOPA to permit three strikes; TDs asked to debate something they haven't seen
It's been a peculiar day in relation to Ireland's SOPA.
First of all, junior minister Sean Sherlock said on lunchtime radio that he intends to hold an emergency Dáil debate on the law - within 24 hours no less! - and is happy to meet with me and other representatives of StopSOPAIreland.com to discuss it. While I'm glad to see that he's softened his position, it's remarkable that he still hasn't published the text of his proposals and doesn't show any signs of doing so. Consequently, I'm not sure what there is to discuss or what he expects the Dáil to debate. Asking TDs to have a debate in the dark about a document they haven't seen doesn't show much respect for Parliament.
But let's leave that aside for the moment. Assume TDs are given the proposal at some point tomorrow. Pretend that despite the short notice they might have sufficient time to digest a complex area of law. Ignore the fact that citizens will be prejudiced by being denied the chance to adequately brief TDs. The point remains - a hurried debate on its own isn't sufficient.
Normally laws are made through a measured process where both the Dáil and the Seanad are given adequate time to scrutinise a Bill, identify weaknesses and pass amendments. It's clear that what Sean Sherlock proposes won't enable them to do that. Instead, TDs will be left impotent with the Dáil being treated as a talking shop, unable to make any changes to a document drafted behind closed doors.
(Incidentally, it also contradicts the minister's own Programme for Government which states that "The situation can no longer be tolerated where Irish Ministers enact EU legislation by statutory instrument. The checks and balances of parliamentary democracy are by-passed." I couldn't agree more.)
The need for greater transparency is obvious from a second remarkable development today. In a briefing note circulated to TDs and senators, Séan Sherlock has confirmed that his proposals go even further than we had thought, and respond to the music industry demands in the EMI v. UPC case:
If you're worried by these proposals and want to see an open and transparent discussion take place then please support the campaign at StopSOPAIreland.com.
First of all, junior minister Sean Sherlock said on lunchtime radio that he intends to hold an emergency Dáil debate on the law - within 24 hours no less! - and is happy to meet with me and other representatives of StopSOPAIreland.com to discuss it. While I'm glad to see that he's softened his position, it's remarkable that he still hasn't published the text of his proposals and doesn't show any signs of doing so. Consequently, I'm not sure what there is to discuss or what he expects the Dáil to debate. Asking TDs to have a debate in the dark about a document they haven't seen doesn't show much respect for Parliament.
But let's leave that aside for the moment. Assume TDs are given the proposal at some point tomorrow. Pretend that despite the short notice they might have sufficient time to digest a complex area of law. Ignore the fact that citizens will be prejudiced by being denied the chance to adequately brief TDs. The point remains - a hurried debate on its own isn't sufficient.
Normally laws are made through a measured process where both the Dáil and the Seanad are given adequate time to scrutinise a Bill, identify weaknesses and pass amendments. It's clear that what Sean Sherlock proposes won't enable them to do that. Instead, TDs will be left impotent with the Dáil being treated as a talking shop, unable to make any changes to a document drafted behind closed doors.
(Incidentally, it also contradicts the minister's own Programme for Government which states that "The situation can no longer be tolerated where Irish Ministers enact EU legislation by statutory instrument. The checks and balances of parliamentary democracy are by-passed." I couldn't agree more.)
The need for greater transparency is obvious from a second remarkable development today. In a briefing note circulated to TDs and senators, Séan Sherlock has confirmed that his proposals go even further than we had thought, and respond to the music industry demands in the EMI v. UPC case:
"to prevent infringement of the record companies’ sound recording copyright, through... internet “peer-to-peer” services, possibly involving a 'three strikes and you’re out' scenario. This is where the ISP sends three warnings of increasing severity and if the infringement continues, discontinues access to the Internet. It is sometimes referred to as a 'graduated response'."In short, the proposals aren't simply about website blocking, but could also allow courts to require ISPs to introduce three strikes systems. It's surprising and disappointing that this is happening now - after the Data Protection Commissioner has shown the unreliability of these systems by taking proceedings against Eircom for wrongly threatening innocent users with disconnection - and truly remarkable that the department seems content with the possibility for such systems to be introduced at the discretion of judges with no legislative controls.
If you're worried by these proposals and want to see an open and transparent discussion take place then please support the campaign at StopSOPAIreland.com.
Monday, January 02, 2012
Christmas and New Year privacy roundup
Blogging has been light in the run up to Christmas and the New Year but there have been a few recent developments which deserve to be noted.
Eircom's three strikes system - down but not out?
The week before Christmas brought the significant news that the Data Protection Commissioner had found Eircom's three strikes system to be in breach of data protection law and had ordered Eircom to discontinue the system within 21 days (TheJournal | SiliconRepublic). Without sight of the ruling it's hard to comment, but I wrote about the background to the investigation previously and the statement from the DPC at that stage suggests that the system was viewed as being a disproportionate use of personal data, particularly in light of its impact on the right to access the internet.
Eircom has not accepted the DPC's decision and (according to Mark Tighe in yesterday's paywalled Sunday Times) has now appealed to the Circuit Court. It's hard to see what the troubled Eircom stands to gain from this - though it may be that failure to appeal would jeopardise their deal with the music industry to offer streaming and downloads. In any event, the appeal offers some breathing space - going by past experience, this appeal should take approximately 6 months or so to resolve, enabling Eircom to continue to operate three strikes until then. Incidentally, Mark Tighe also confirms that no Eircom customers have yet been disconnected for four "offences", though a number have had their accounts suspended for seven days.
Ireland's first prosecution for data disclosure
The same week also brought news of what seems to be the first successful prosecution in Ireland for deliberate disclosure of personal information (Irish Times | Independent | Examiner). This case centred on a corrrupt Revenue worker who disclosed information on six separate individuals to her own father (as a "favour to a business associate of his") and to her father in law - a retired garda who was working as a private investigator for Quinn Insurance.
Significantly, this came to light only due to initial fears that the victims were being targeted for criminal attacks - accounting for the garda involvement which led to this prosecution being brought. As I've already blogged, despite the existence of a "culture of snooping" within the Revenue previous cases have not been referred to police. This case isn't exceptional in involving snooping - it is exceptional only in seeing criminal consequences. Had this case not involved particularly sensitive targets (an executive of Brinks Allied security company and a former Revenue official now working against cigarette smuggling in Europe) then it is likely that no prosecution would have been brought.
All three defendants pleaded guilty to data protection offences. Unfortunately, the media coverage doesn't indicate the precise offences involved but it seems likely that each was charged with the offence of disclosing personal information obtained without authority, contrary to section 22 of the Data Protection Act 1988. This presents an interesting issue in the case of the Revenue worker, as the section 22 offence doesn't apply to "a person who is an employee or agent of the data controller or data processor concerned". Consequently, it is hard to see how this charge could have been brought against her unless as a civil servant she was regarded as not being an "employee" for the purposes of that section. [Update - I'm now informed that the charge against the Revenue worker was brought under section 21, which specifically targets employees also. However section 21 is limited to data processors rather than data controllers, which presents a further issue as to whether Revenue should properly be treated as a mere data processor.]
The case also reveals a lack of awareness amongst the Irish judiciary of the importance of data protection. In a worrying comment, the judge stated that "the breaches in this case were not unduly sinister and that they were possibly done without an appreciation of the seriousness of the actions". Remarkably, each offender was given the benefit of the Probation Act and allowed to escape conviction on condition that they donate €1,000 to charity. This can only be viewed as derisory in the context of a serious and repeated breach of trust (on the part of the Revenue worker) and a deliberate attempt to profit from wrongdoing (the private investigator) and if anything highlights the urgent need to introduce custodial sentences and not merely fines for this type of offence. As UK MPs recently noted, these trivial fines mean that "there is no deterrent because the financial gain resulting from the crime far exceeds the possible penalty".
(Yet another) Irish company spying on employees
Unfair dismissal actions have a way of exposing employers with a cavalier attitude to data protection. In November it was Dunnes Stores making secret use of CCTV. December revealed that Galen - a Northern Ireland pharmaceutical company - had covertly fitted GPS trackers to the cars of employees. According to the Employment Appeals Tribunal Galen had "breached the trust of its employees" by doing so, though it didn't address the question of whether this evidence was inadmissible as a result. Incidentally, I see from their website that Galen's motto is "Doing the right thing with the right priorities".
Eircom's three strikes system - down but not out?
The week before Christmas brought the significant news that the Data Protection Commissioner had found Eircom's three strikes system to be in breach of data protection law and had ordered Eircom to discontinue the system within 21 days (TheJournal | SiliconRepublic). Without sight of the ruling it's hard to comment, but I wrote about the background to the investigation previously and the statement from the DPC at that stage suggests that the system was viewed as being a disproportionate use of personal data, particularly in light of its impact on the right to access the internet.
Eircom has not accepted the DPC's decision and (according to Mark Tighe in yesterday's paywalled Sunday Times) has now appealed to the Circuit Court. It's hard to see what the troubled Eircom stands to gain from this - though it may be that failure to appeal would jeopardise their deal with the music industry to offer streaming and downloads. In any event, the appeal offers some breathing space - going by past experience, this appeal should take approximately 6 months or so to resolve, enabling Eircom to continue to operate three strikes until then. Incidentally, Mark Tighe also confirms that no Eircom customers have yet been disconnected for four "offences", though a number have had their accounts suspended for seven days.
Ireland's first prosecution for data disclosure
The same week also brought news of what seems to be the first successful prosecution in Ireland for deliberate disclosure of personal information (Irish Times | Independent | Examiner). This case centred on a corrrupt Revenue worker who disclosed information on six separate individuals to her own father (as a "favour to a business associate of his") and to her father in law - a retired garda who was working as a private investigator for Quinn Insurance.
Significantly, this came to light only due to initial fears that the victims were being targeted for criminal attacks - accounting for the garda involvement which led to this prosecution being brought. As I've already blogged, despite the existence of a "culture of snooping" within the Revenue previous cases have not been referred to police. This case isn't exceptional in involving snooping - it is exceptional only in seeing criminal consequences. Had this case not involved particularly sensitive targets (an executive of Brinks Allied security company and a former Revenue official now working against cigarette smuggling in Europe) then it is likely that no prosecution would have been brought.
All three defendants pleaded guilty to data protection offences. Unfortunately, the media coverage doesn't indicate the precise offences involved but it seems likely that each was charged with the offence of disclosing personal information obtained without authority, contrary to section 22 of the Data Protection Act 1988. This presents an interesting issue in the case of the Revenue worker, as the section 22 offence doesn't apply to "a person who is an employee or agent of the data controller or data processor concerned". Consequently, it is hard to see how this charge could have been brought against her unless as a civil servant she was regarded as not being an "employee" for the purposes of that section. [Update - I'm now informed that the charge against the Revenue worker was brought under section 21, which specifically targets employees also. However section 21 is limited to data processors rather than data controllers, which presents a further issue as to whether Revenue should properly be treated as a mere data processor.]
The case also reveals a lack of awareness amongst the Irish judiciary of the importance of data protection. In a worrying comment, the judge stated that "the breaches in this case were not unduly sinister and that they were possibly done without an appreciation of the seriousness of the actions". Remarkably, each offender was given the benefit of the Probation Act and allowed to escape conviction on condition that they donate €1,000 to charity. This can only be viewed as derisory in the context of a serious and repeated breach of trust (on the part of the Revenue worker) and a deliberate attempt to profit from wrongdoing (the private investigator) and if anything highlights the urgent need to introduce custodial sentences and not merely fines for this type of offence. As UK MPs recently noted, these trivial fines mean that "there is no deterrent because the financial gain resulting from the crime far exceeds the possible penalty".
(Yet another) Irish company spying on employees
Unfair dismissal actions have a way of exposing employers with a cavalier attitude to data protection. In November it was Dunnes Stores making secret use of CCTV. December revealed that Galen - a Northern Ireland pharmaceutical company - had covertly fitted GPS trackers to the cars of employees. According to the Employment Appeals Tribunal Galen had "breached the trust of its employees" by doing so, though it didn't address the question of whether this evidence was inadmissible as a result. Incidentally, I see from their website that Galen's motto is "Doing the right thing with the right priorities".
Monday, August 31, 2009
The Pirate Bay block takes effect
Today, September 1st, is the day that the Eircom is scheduled to start blocking The Pirate Bay. It will be interesting to see how it is implemented and whether there are any technical side effects (along the lines of the recent IWF / Wikipedia fiasco). If you're an Eircom customer, perhaps you might post a comment as to whether you can still access thepiratebay.org or the other URLs / IP addresses which are being blocked or whether you've noticed any other effects of the blocking.
Friday, August 28, 2009
Eircom, three strikes and false positives
Some of these cases will be due to Eircom's own incompetence in issuing up to 250,000 wireless routers with easily guessable passwords - which will result in some people piggybacking on Eircom users' connnections. But there is a wider problem, in that the investigators used by the music industry have a track record of making false copyright infringement claims.
A particularly interesting study from the University of Washington (Zeropaid story | Full details and paper) shows the risks.
In that study, the researchers document receiving 487 notices under the DMCA: all wrongfully alleging that files were being illegally shared over BitTorrent. Among the alleged culprits were three laserjet printers which between them were accused on nine separate occasions of downloading movies. (Bad printers! No toner for you tonight.)
The research conclusions?
Practically any Internet user can be framed for copyright infringement today.In light of these findings, I wonder how reliable the evidence presented by the music industry to Eircom will be, and whether the flaws identified in this study will be addressed. So far, all we have to go on are leaked details of a draft protocol between Eircom and the music industry on the information to be provided with each accusation.
By profiling copyright enforcement in the popular BitTorrent file sharing system, we were able to generate hundreds of real DMCA takedown notices for computers at the University of Washington that never downloaded nor shared any content whatsoever.
Further, we were able to remotely generate complaints for nonsense devices including several printers and a (non-NAT) wireless access point. Our results demonstrate several simple techniques that a malicious user could use to frame arbitrary network endpoints.
Even without being explicitly framed, innocent users may still receive complaints.
Because of the inconclusive techniques used to identify infringing BitTorrent users, users may receive DMCA complaints even if they have not been explicitly framed by a malicious user and even if they have never used P2P software!
Those details are, however, too vague at this stage to be useful.
For example, the draft apparently provides that "the information which will be provided by the record companies will be of the same type as that used in the three previous disclosure actions in the Irish High Court". What precisely does this mean? Similarly, the protocol appears to require the music industry to provide "the digital fingerprint/hash for copyright material detected". Does this mean that before a complaint can be made, the investigators must download the entire file allegedly shared by the user? There is also apparently provision for "reputable annual independent certification that the necessary ... I.T. ... controls relating to the obtaining, generating and processing of data by Detecnet ... have been complied with". Will this require certification that the types of problems identified by the University of Washington and others have been solved? In fairness to Eircom, it does appear that it has made some efforts to include elements in the agreement which might meet some of these problems. But without more detail on the agreement it's impossible to be confident that innocent users (or printers!) will not be wrongly accused.
Tuesday, August 25, 2009
Technical aspects of The Pirate Bay blocking
Eircom's block of The Pirate Bay comes into force on September 1st. With that in mind it might be worth examining precisely what Eircom is obliged to do. The relevant portion of the court order (to which Eircom consented) is the following:
Whatever the reason, this highlights one problem with the order - there's no provision for the possibility that an IP address or domain name initially associated with TPB later comes to be associated with a different and innocent site. I'm told (by someone who should know) that this is unlikely at least in the short term in the case of TPB - but that's no excuse for an order which doesn't even consider this risk, much less provide for any safeguard.
Of course, the order doesn't specify the methods to be used by Eircom to "block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs". Any thoughts on what these might be and their possible pitfalls?
IT IS ORDEREDAstute readers might have guessed that the list of IP addresses would rapidly go out of date and checking today that seems to be the case. This might be related to the fact that earlier today TPB upped and moved servers in response to the Swedish authorities ordering their connectivity provider to disconnect them from the internet.
(1) Pursuant to Section 40(4) of the Copyright and Related Rights Act, 2000 that the Defendant do block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs listed in the Schedule attached hereto together with such other domain names IP addresses and URLs as may reasonably be notified as related domain names by the Plaintiffs to the Defendant from time to time...
Schedule
The Pirate Bay main site
Thepiratebay.org main site is hosted on a server with IP address 192.121.86.15
The Pirate Bay trackers
The Pirate Bay current tracker URL is:
http://tracker.thepiratebay.org:80/announce
udp://tracker.thepiratebay.org:80/announce
This URL resolves to the following IP addresses:
192.121.86.2
192.121.86.3
192.121.86.4
192.121.86.5
192.121.86.6
192.121.86.7
192.121.86.8
Domain names that re-direct to The Pirate Bay
Piratebay.net
Piratebay.org
Piratebay.se
Thepiratebay.com
Thepiratebay.net
Thepiratebay.nu
Thepiratebay.se
Pro-piracy.nl
Smais.org
Thepiratebay.org
Piratebay.no
The re-directs are all hosted on the main server with IP 192.121.86.15 (owned by The Pirate Bay)
The Pirate Bay .torrent files
The Pirate Bay .torrent files are hosted on IP 192.121.86.19 with (sub)domain
http://torrents.thepiratebay.org
Whatever the reason, this highlights one problem with the order - there's no provision for the possibility that an IP address or domain name initially associated with TPB later comes to be associated with a different and innocent site. I'm told (by someone who should know) that this is unlikely at least in the short term in the case of TPB - but that's no excuse for an order which doesn't even consider this risk, much less provide for any safeguard.
Of course, the order doesn't specify the methods to be used by Eircom to "block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs". Any thoughts on what these might be and their possible pitfalls?
Wednesday, August 19, 2009
Eircom to block the Pirate Bay from September; UPC not so keen
In the latest twist in the Irish filesharing wars, it's emerged today that Eircom will start blocking access to The Pirate Bay from the first of September, while UPC has rejected music industry demands that it do so also. (The Irish Times | RTE). So what's going on?
First - the Eircom situation. When Eircom settled the case brought against it by the music industry it agreed - in addition to implementing a three strikes system against its users - not to oppose any application to the court to block access to The Pirate Bay. The predictable result was that an unopposed application would be granted without any real judicial scrutiny - and this has now happened. On the 24th of July, on the consent of Eircom, Mr. Justice Charleton in the High Court granted an order requiring it to:
Despite this, however, the music industry appears to have been emboldened by the order, which takes us on to the UPC situation. It seems that the plaintiffs then wrote to UPC demanding that it also block The Pirate Bay, lest customers "migrate" from Eircom, and threatening immediate proceedings unless it blocked access also. UPC - which is already being sued by the music industry in separate proceedings essentially demanding it implement "three strikes" - has rejected this demand, and indicated that it will vigorously defend any additional action also.
The current state of play raises some interesting questions. For example: Will users begin to migrate from Eircom? Is it appropriate for a court - even on consent - to make an order which will have the effect of blocking user access to a great deal of legitimate content? (While the percentage of legal torrents on The Pirate Bay might be contested, there's no doubt but that it indexes a great deal of legitimate content.) Should such an order allow plaintiffs to (apparently unilaterally) determine which sites are "related" and require those to be blocked also? Why have Eircom been so shy about revealing the existence of the blocking? Expect these, and other issues to come to the fore over the next few days.
Adrian Weckler has more, including the UPC press release.
First - the Eircom situation. When Eircom settled the case brought against it by the music industry it agreed - in addition to implementing a three strikes system against its users - not to oppose any application to the court to block access to The Pirate Bay. The predictable result was that an unopposed application would be granted without any real judicial scrutiny - and this has now happened. On the 24th of July, on the consent of Eircom, Mr. Justice Charleton in the High Court granted an order requiring it to:
block or otherwise disable access by its subscribers to the website thePirateBay.org and related domain names, IP addresses and URLs ... together with such other domain names, IP addresses and URLs as may reasonably be notified as related domain names by [the music company plaintiffs] to [eircom] from time to time.That order requires Eircom to put such a block in place from the start of September (and, remarkably, to block additional sites designated by the plaintiffs as "related" - something presumably designed to avoid evasion but which may be prone to abuse). Crucially, however, Mr. Justice Charleton stressed that he had only heard one side, and that consequently any decision he made was on the basis of one side putting forward an unopposed application - expressly noting that had the matter being argued, a different conclusion might have been reached by a different court. In short, the order has no precedential value.
Despite this, however, the music industry appears to have been emboldened by the order, which takes us on to the UPC situation. It seems that the plaintiffs then wrote to UPC demanding that it also block The Pirate Bay, lest customers "migrate" from Eircom, and threatening immediate proceedings unless it blocked access also. UPC - which is already being sued by the music industry in separate proceedings essentially demanding it implement "three strikes" - has rejected this demand, and indicated that it will vigorously defend any additional action also.
The current state of play raises some interesting questions. For example: Will users begin to migrate from Eircom? Is it appropriate for a court - even on consent - to make an order which will have the effect of blocking user access to a great deal of legitimate content? (While the percentage of legal torrents on The Pirate Bay might be contested, there's no doubt but that it indexes a great deal of legitimate content.) Should such an order allow plaintiffs to (apparently unilaterally) determine which sites are "related" and require those to be blocked also? Why have Eircom been so shy about revealing the existence of the blocking? Expect these, and other issues to come to the fore over the next few days.
Adrian Weckler has more, including the UPC press release.
Friday, August 07, 2009
Eircom briefing note on "three strikes" filesharing settlement leaked
I've just stumbled on a document on scribd which purports to be a "Briefing Note on arrangement between Eircom and the Irish Recorded Music Association (IRMA) with regard to Copyright Infringement" dating from March. While there's no indication as to who posted the document or whether it is authentic, it certainly appears to be genuine and to reflect Eircom's position. There are some very interesting details in the document as to how Eircom proposes to implement "three strikes" and here's an excerpt:
Update (19.08.09): Torrentfreak and SiliconRepublic have since run stories about this document.
Under the draft protocol, the notification shall include the following information (at a minimum):Full text.
* details of copyright holder (name and address);
* why the notification is being sent (i.e. setting out the breach of copyright);
* the actual copyright work that has been infringed (information on copyright material, for example artist, song, title and album title);
* the IP address;
* the time stamp of when the investigation was initiated;
* the time stamp of when the investigation was completed, the peer to peer application/software used by the customer;
* and, the digital fingerprint/hash for copyright material detected;
The last item, the digital fingerprint/hash of the copyright material detected, allows eircom to verify that the copyright work identified by the record companies is in fact owned by them.
In addition, the information which will be provided by the record companies will be of the same type as that used in the three previous disclosure actions in the Irish High Court involving the parties and eircom will not act upon a notification from the record companies that does not contain the information set out above.
eircom has also requested that the record companies provide independent certification that the notification has been lawfully obtained by and on behalf of the record companies.
The record companies are also to provide reputable annual independent certification that the necessary legal, I.T., entity level and regulatory controls relating to the obtaining, generating and processing of data by Detecnet (or any other supplier engaged by the record companies) have been complied with.
Update (19.08.09): Torrentfreak and SiliconRepublic have since run stories about this document.
Wednesday, July 08, 2009
Eircom hacking shows flaws in Irish computer crime law
Today's Irish Times has a report of an apparent denial of service attack against Eircom:
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
MANY OF Eircom’s 500,000 internet subscribers have been left offline or experienced delays in web browsing at times this week because of a suspected attack by hackers.I've said it before but it's worth repeating: Irish law does not adequately deal with computer crime at the moment (with denial of service attacks being one of many areas left without adequate sanctions) and legislation to implement the Cybercrime Convention and the Framework Decision on Attacks Against Information Systems is now long overdue.
Some customers who tried to connect to popular sites such as RTÉ, Facebook or Bebo were redirected to incorrect websites, often displaying images of advertising or scantily clad women.
The company blamed the problems on “an unusual and irregular volume of internet traffic” directed at its website, which affected the systems and servers that provide access to the internet for its customers.
Internet discussion groups speculated that the problems were caused by a hacker accessing Eircom’s domain name server (DNS) system through a denial-of-service attack.
This involves a target site being saturated with messages and requests to the point it can no longer function properly.
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
Whether or not such an attack would amount to an offence under Irish law will vary depending on the precise structure of the attack.
For example, suppose that A sets out to harm B by sending several million emails to B’s server. The effect is not only to use up B’s bandwidth but also to use his disk capacity. In this case, it might be possible to charge A with criminal damage under section 2 of the Criminal Damage Act 1991, on the basis that A has damaged B’s data within the meaning of section 1 by adding to it without lawful excuse.
This result is supported by the English decision in DPP v. Lennon. In that case the defendant was a 16 year old who took umbrage at the circumstances of his dismissal and sent five million emails to his former employer with the expressed intention of “causing a bit of a mess up”. He was charged with unauthorised modification to a computer system with intent to impair the operation of the computer, contrary to section 3(1) of the Computer Misuse Act 1990 (the equivalent provision to section 2 of the Criminal Damage Act 1991). His defence was that the company had implicitly consented to receiving emails and as such he had not made unauthorised modifications. Although the trial judge accepted this argument, on appeal the Divisional Court held that any implied consent did not extend to emails sent for the purpose of disrupting the system. Per Jack J.:“I agree, and it is not in dispute, that the owner of a computer which is able to receive emails is ordinarily to be taken as consenting to the sending of emails to the computer. His consent is to be implied from his conduct in relation to the computer. Some analogy can be drawn with consent by a householder to members of the public to walk up the path to his door when they have a legitimate reason for doing so, and also with the use of a private letter box. But that implied consent given by a computer owner is not without limit. The point can be illustrated by the same analogies. The householder does not consent to a burglar coming up his path. Nor does he consent to having his letter box choked with rubbish. That second example seems to me to be very much to the point here. I do not think that it is necessary for the decision in this case to try to define the limits of the consent which a computer owner impliedly gives to the sending of emails. It is enough to say that it plainly does not cover emails which are not sent for the purpose of communication with the owner, but are sent for the purpose of interrupting the proper operation and use of his system.”However, if the facts of a denial of service attack are varied slightly then criminal damage may no longer be an appropriate charge. Suppose for example that C sets out to hinder access to D’s publicly available website, and does so by programming several computers to repeatedly download large pages from the site. The result is to use up D’s bandwidth and ensure that other users cannot get through to the site, though the server itself continues to function. What crime, if any, has been committed?
In this case C would not have damaged D’s data (assuming that C downloaded data only and did not make any modifications to the data on the server). It might be argued that C has committed criminal damage to the server itself given the extended definition of “damage” under section 1, which includes situations where a person “whether temporarily or otherwise, render[s] inoperable or unfit for use or prevent[s] or impair[s] the operation of” property.
Such a charge would, however, prevent some difficulties. It might be successful if the effect of a denial of service attack was to cause the server to crash – that temporary inoperability would certainly seem to constitute damage within the meaning of section 1. In the hypothetical above, however, C has not rendered the server inoperable but merely inaccessible – which would seem to fall outside the scope of the criminal damage offence.
On the other hand, using the reasoning in DPP v. Lennon it might be possible to characterise the attack as unauthorised access contrary to section 5 of the Criminal Damage Act 1991. The argument could be made that while public websites carry with them an implied permission to access the site, this permission does not (to use the words of Jack J.) cover visits which are “the purpose of interrupting the proper operation and use of [the] system”, so that such a visit would constitute operation of the server with intent to access data without lawful excuse.
Subscribe to:
Posts (Atom)
