May 11, 2006 10:16 AM PDT
Teenage 'e-mail bomber' heads back to court
- Related Stories
U.K. cybercriminals threatened with 10-year termJanuary 26, 2006
Tsunami 'hacker' keeps security jobNovember 11, 2005
British teen cleared in 'e-mail bomb' caseNovember 2, 2005
British teen in court over 'e-mail bomb' chargesNovember 1, 2005
Alleged hacker: U.S. defense sites poorly securedJuly 13, 2005
Tech firms call for approval of cybercrime treatyJune 29, 2005
David Lennon, who is now 18 and can therefore be named for the first time, is alleged to have used an e-mail-bombing program called Avalanche to send approximately 5 million messages to his former employer, Domestic & General Group, in early 2004. The flood crashed the company's e-mail server.
The case against him, brought under the Computer Misuse Act, was dismissed in November by District Judge Kenneth Grant at Wimbledon Magistrates Court in London. At the time, Grant said that Section 3 of the act, which concerns unauthorized modification of data, had not been breached, as e-mails sent to a server configured to receive e-mails could not be classified as unauthorized.
But on Thursday, judges at the Royal Courts of Justice in London sent the case back to the Magistrates Court, saying Grant "was not right to state there was no case to answer."
Justice Jack said the judge should consider what answer Lennon might have expected if he had asked Domestic & General about the messages before starting the mail bombing.
The U.K.'s Crown Prosecution Service, which had appealed against the original judgment, said it was pleased by Thursday's ruling. "We have sought to clarify a point of law, to update the interpretation of that law to cope with contemporary high-tech crime. As technology develops at an ever-increasing pace the law may sometimes need to be interpreted in new ways," it said in a statement.
"The police and CPS are determined to ensure that those who use the Internet for crime are not beyond the reach of the law, and to make the Internet a safe place for both businesses and domestic users," it said.
The case highlighted flaws in the 16-year-old Computer Misuse Act, passed in the days before Internet crime became a significant problem. Critics have complained that it does not specifically outlaw denial-of-service attacks, for example.
Security expert Peter Sommer, who has called for the law to be updated, was a defense witness in Lennon's trial last year. He said on Thursday that "the defense (had been) asking the court to take a fairly narrow and literal view of the CMA."
"My own view is that they could have made a decision either way. The fact that the Court of Appeal has reversed it is not a colossal surprise," he told ZDNet UK.
David Meyer of ZDNet UK reported from London.