All the latest UK technology news, reviews and analysis

Security experts blast BBC over botnet stunt

by Shaun Nichols

17 Mar 2009

Comments: 9

  • Tweet this
BBC building
The BBC's actions have been condemned on legal and ethical grounds

Security firms around the world have criticised the BBC over its conduct in a recent episode of the programme Click.

The episode involved BBC reporters enlisting the help of third-party security experts to conduct an investigative report on building a botnet. The team was able to purchase a network of 22,000 controlled systems which were used to send emails and perform a denial-of-service attack on a test web site.

The BBC later dismantled the botnet and informed the owners of the compromised systems, but the story drew criticism from security experts. Sophos senior security consultant Graham Cluley condemned the attacks as a breach of the Computer Misuse Act.

In the days following the report, it has become apparent that Cluley is far from alone in his condemnation.

"The BBC simply didn't need to go as far as it did to demonstrate the cyber criminal possibilities of a botnet," argued Paul Ducklin, head of technology for Sophos' Asia-Pacific branch, in a blog post.

"The demonstration it filmed could easily, more scientifically, probably more effectively, and definitely more quickly, easily and safely, have been done in a research laboratory."

A Sophos web site poll found that 56 per cent of visitors felt that the action was wrong on either legal or ethical grounds, while only 33 per cent felt that the awareness raised by the report justified the BBC's actions.

Researchers and executives from other security firms, such as McAfee, F- Secure and Sunbelt Software, are throwing their support behind Sophos.

"You just don’t get involved, because it's wrong and there are too many unintended consequences that can occur," wrote Sunbelt chief executive Alex Eckelberry in a blog post.

"To have a TV show use a botnet to 'prove a point' is beyond the pale, particularly since the point could have easily been proven in other ways."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Lead PHP Developer - Technical Architect - Ecommerce Manager

Lead PHP Developer - Technical Architect - Ecommerce...

C# / .NET Software Engineers – Leeds City Centre – C# (£30-50k)

C# Software Engineers required to join rapidly expanding...

Java / J2EE Developers – Leeds City Centre – Java / J2EE (£30-50k)

Java / J2EE Software Engineers required to join rapidly...

Developer (MIS - SQL / T-SQL, HTML, CSS or Javascript)

Developer (MIS / Business Systems - SQL / T-SQL, HTML...

To send to more than one email address, simply separate each address with a comma.