Advertisement
Promo

Security threats Toolkit

Email bomber to be electronically tagged

Colin Barker and Graeme Wearden ZDNet.co.uk

Published: 23 Aug 2006 12:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A UK teenager pleaded guilty on Wednesday to breaking the Computer Misuse Act (CMA) by crashing the email server of his former employer.

David Lennon, 18, was sentenced to a two-month curfew by a judge sitting at Wimbledon Magistrates court.

Lennon had originally been cleared of the charges in November 2005, after another judge ruled that it wasn't an offence to overwhelm an email server with millions of messages. This ruling was later challenged by the Crown Prosecution Service, and in May 2006 the case was sent back to the Magistrates Court.

On Wednesday morning, Judge Dixon ruled that Lennon should be subject to a curfew, which meant he must stay at home between the hours of 12.30am and 7am on weekdays, and between 12.30am and 10am on weekends. If he breaks this curfew, he risks a more serious sentence.

The curfew has been timed so as not to interfere with Lennon's work at a local cinema. Judge Dixon said it was "a happy coincidence" that it will end the day before Lennon starts college in September.

The prosecution dropped their demand that Lennon should pay costs amounting to £29,000, which arose from his attack on Domestic and General Group in which five million emails crashed its servers.

The defence argued that Lennon should receive a conditional discharge, given the confusion over whether the CMA outlawed the sending of masses of emails — known as an email bomb. Judge Dixon, though, argued that this was inappropriate.

"Even given his age at the time, this was a grave offence and caused serious damage, so I need to impose something to make him think again," Judge Dixon told the court.

The case was brought by the Metropolitan Police, which said that Lennon's conviction showed that such cyber-offenses would be treated seriously.

The CMA, which was introduced in 1990, explicitly outlaws the "unauthorised access" and "unauthorised modification" of computer material. Section 3, under which he was charged, concerns unauthorised data modification and tampering with systems.

Lennon's original case was heard by District Judge Kenneth Grant, who ruled that an email bomb did not violate the CMA because email servers were set up to receive emails. As such, each individual email could be ruled to make an "authorised modification" to the server.

The CMA is now seen as insufficient to combat the rise of cybercrimes such as denial-of-service attacks. A series of amendments are being introduced by the Government to update it.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
303 out of 372 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters