Click here to see all pictures from November 2005
More Pictures by Nisis DV5
Please donít get me wrong, this isnít a blog, but there was a news article recently that caused me concern, it was this story which was about a teenager that caused a denial of service attack on a company. There are no good explanations of what a denial of service attack is on the web, so for the untechie people it's basically where you flood the service/server with requests. In this case the flood was five million emails. At some point the service (i.e. the mailserver in this case) cannot continue and/or genuine requests get turned away. The business suffers due to lack of genuine requests or emails and the time it takes to rectify the failing server costs and so does the clean up of the five million mails.
The judge ruled that the unnamed teen could not be prosecuted under law... and quite rightly. My problem is that this sends a strong message out, and every online business should be worried where people could be prosecuted under the UK law from a denial of service attack which (as the judge said) are not illegal.
In itself this sort of seems OK in that the law has been maintained, but the problem is that in the last five or eight years denial of service attacks are the mainstay for blackmailers and the like. These people we cannot stop is a sense, they route through servers in ISPs in China who don't care and history says they have at many points hit the gambling industry at key points. Whilst I don't think this is right, this isn't the problem that I'm talking about. What I am saying is that any script kiddie with a PC or many PCs can launch an attack on a company they don't like and this is fine in UK law.
OK it's not big potatoes, but let's get the little things right before we start tackling the real tough ones. As a an employee of an online business I really don't like the idea that a disgruntled customer can legally shut down our site or our email system with little effort, whilst I have no doubt that the big boys in the world could do it with zombie pcs allowing anyone with a grudge to do so and legally and traceably seems silly.
Of course it needs a change to the law and perhaps that what I shall be fighting for.
0 comments have been left
Make a Comment