Sweden to Make Denial of Service Attacks Illegal 108
paulraps writes "Sweden is to pass legislation making Denial of Service attacks illegal. The offense will carry a maximum jail term of two years, and is thought to be a direct response to the attack which crashed the Swedish police's web site last summer. Nobody was charged for that, but the fact that it came shortly after a raid on the Pirate Bay's servers was thought by many to be not entirely coincidental. Sweden's move follows the UK, which is even tougher on web attackers — there the sentence can be over five years in prison."
Slashdotted. (Score:5, Funny)
Re:Slashdotted. (Score:4, Funny)
It's worth a try!
*cough* [sweden.gov.se]
Re: (Score:2)
Re: (Score:1, Informative)
That wasn't the case when one of my sites made the front page of Slashdot, Digg and Reddit on the same day. In terms of the number of hits, Digg had the most, followed by Slashdot and then Reddit. I don't recall off-hand the absolute values, but I remember Digg bringing about 30% more hits than Slashdot. I remember that because it surprised me. I didn't realize how
Digg and Slashdot users are not mutually exclusive (Score:2, Interesting)
It would be interesting to see how many people regularly visit both sites. I think that people who often check Digg, will RTFA even less often than regular
Re:Digg and Slashdot users are not mutually exclus (Score:2)
I would have thought you'd have a higher percentage of people RTFAing on Digg, simply because there isn't really anything else they'd want to do there Certianly applies to all (five or so) people I know who visit Digg.
Legality? (Score:1)
Not really, but this has other political flavours (Score:1, Insightful)
However, no one mentions the political change that occurred this autumn.
After twelve years of social democrats (left) we (swedes) now have the so called "alliance" (right) since a few months back.
Even though the social democrat's minister of justice (Tomas Bodström) was just the same kind of openly left and inner right kind of parrot that Blair is -- repeating whatever baloney the monkey in the white house spits out, there were
Mostly pointless... (Score:2)
Re:Mostly pointless... (Score:5, Interesting)
This law will allow the police to obtain the identity of the person using the IP address that is used for the DOS attack, even if this DOS attack is directed from Sweden to the outside world. I am sure there is a large amount of political pressure from the US in this matter and Swedish politicians are easy to intimidate.
It is important to note that the sentence term of 2 years was not chosen at random. When a crime carries this sentence as a possiblity, the Swedish police gets greater powers to use surveillance, wiretapping and raids to secure evidence such as the identity of person using a specific IP address.
In fact, this is also why thePiratebay.org exists and is so successful - since file sharing carries a sentence which is usually much less than 2 years, the police are not allowed to raid or subpoena the ISPs for the identity of the person that is using a specific IP address. (The Swedish MPAA aka APB have treid hard to get a criminal conviction for file sharing for this reason.)
Re:Mostly pointless... (Score:5, Informative)
No. The pirate bay exists because its not illegal to link to illegal copyrighted material in Sweeden. The pirate bay doesnt share illegal material, just torrent files, which are essentially a link to where the material actually is.
Not a crime but accessory to one (Score:2)
The problem with prosecuting the Pirate bay is that someone must be found guilty of a crime for another to be guilty of being an accessory to thet crime. The users of Piratebay are not suspected of a crime carrying a sentence of two years or more, meaning the police can't get their IP numbers, meaning they can't be charged wi
Re: (Score:1)
Re: (Score:2)
A very common form of DDoS attack is a SYN flood where the source IP in the packets is NOT the IP of the bot being used.
Last time someone had a go at our servers, the forged IPs traced back to well known locations which obviously weren't the real source (mostly US government labs like LLNL and Sandia).
I see a risk here where DDoS is used specifically to frame the real owner of an IP.
In any event, a moderately competent hacker will use a botnet which is managed using wardriving sessions, or from a server in
Re: (Score:2)
So, wait. The _objective measurement_ of the severity of the crime (i.e. the level of police response required) is tied to the _possible sentence_ it can carry? While in theory this shouldn't be a problem, since the sentence should reflect the harm done by the criminal, that kind of stipulation has _ludicrous_ potential for abuse.
Re: (Score:2)
I honestly think the system is pretty sane. They can not search my house, even if I'm suspected of shop lifting. They can, however, search the house of the drug dealer living down the road. Somewhere the line has to be drawn, and if it has to be drawn, there has to be some way of figuring out which side any particular case should end up on. They've chosen the penalty of the crime the suspect is suspected of. Care to come up with a better measurement?
And by the way, I live in Sweden, if that's
Re: (Score:2)
Geek vigilante fest! (Score:3, Funny)
Also, if you catch someone in the act of committing, or appearantly fleeing from the scene of crime of, a crime that carries a maximum penalty of more than two years, you may make a "citizen's arrest", that is grab a
Re: (Score:1)
Actually, DoS attacks are more commonly performed from within the country, because who in Canada, for instance, would bother DoS'ing a Swedish company? Nobody would care.
The problem, however, is that the bots the local attacker uses are typically outside the country, which makes it impossible to track down the attack.
Oh, that will solve it (Score:2)
Breaking their fingers is a good thought as well.
Tracking (Score:3, Insightful)
Re: (Score:3, Insightful)
Re: (Score:2)
Uhmmm...No.
Sen. Ted "The Tubes" Stevenson is all over the 'internets' with his trucks.
And he STILL is not getting his internets on a timely basis, but he'll keep those trucks humpin' up the tubes!
Re: (Score:2)
At least making it illegal will hopefully catch the sloppy operations and make the angry geek at home think twice about attacking a site.
The pay-per-click scamming is an interesting point. My old site was getting forum spammed in to oblivion by the old UMAXPPC search sites. Would have been nice at the time if there was legal recourse since the sites w
Re: (Score:2)
It's a political feel-good law. The Swedish government can say "We're getting tough on this" without much worry that they'll have to bother prosecuting anyone.
Re: (Score:2)
No idea in all honesty. At least if someone decides to carry out a major DoS attack on a Swedish server, there is the possibility of extradition.
Re: (Score:2)
Re: (Score:2)
Makes people realise that it is serious (Score:2)
As the internet continues to be extended to provide vital services (including access to emergency services etc), making denial of service illegal makes sense.
Moral of the Story (Score:1)
A link to their govt site? (Score:2)
Good luck (Score:2)
Not going to work (Score:2, Insightful)
Re: (Score:2)
1) The vast majority of smokers don't like marijuana, they prefer tobacco.
or
2) The vast majority of smokers don't smoke habitually marijuana because it's illegal. This could be because they don't want legal hassle or perhaps they can't easily buy it.
Even if you can't eliminate a crime
Re: (Score:1)
Re: (Score:2)
Yeah, I should have been mentioned that it depends on the location really.
Re: (Score:1)
Re: (Score:2)
Virus writing is a relatively underground past-time but we can still examine the techniques used and improve our defences. My main hope with the law is that it'll deter the "me to" script kiddies who are looking for a few minutes of notoriety.
You're right that this won't stop all of them. The big boys who have real gains to make from these att
Re: (Score:1)
Re: (Score:2)
Looks like the prison lobby (Score:1)
Re: (Score:1, Insightful)
Re: (Score:1)
Pointless (Score:4, Insightful)
Re: (Score:3, Insightful)
I think of it this way: You take something from society, you should give up something of your own in exchange. Ideally, you should give up something that pays society back in exchange for what you took, but in practice this is difficult to manage. (However, in America at least, we do have civil courts for people who want to try to get paid back in this way.) Instead, societies over the years ha
Good! (Score:1, Insightful)
Re: (Score:1)
Yay for being swedish! (Score:1)
Too bad (Score:4, Insightful)
You can do just about anything on the Internet and are safe from prosecution. Why? Because the Internet crosses international borders and we all know that international law enforcement is just about impossible. No two countries have the same laws, the same penalties or even agree that the same things are criminal acts.
So, Sweden can pass all the laws they want to, but it will have no effect unless every country on the planet agrees that DDOS attacks are a criminal act with at least two years in jail being an appropriate penalty this will have no effect.
What is likely to happen is they will track some stupid show-off bragging script kiddie to Canada where it will be declared that they aren't going to extradite because it would bruise the delinquents ego. Or, the perp will be tracked to Romania where the response will be "So?"
Under the right circumstances, the US would probably even shield a perpetrator.
No, unfortunately for many people the Internet is destined to remain consequences-free for a long time to come.
Re: (Score:1, Interesting)
You raise an interesting point which I never considered. What happens when two countries *do* both have laws concerning the situation. If I crash a Swedish police website from here in Flori
Re: (Score:1)
Re: (Score:1)
if you remember, a few big spammers have had their lives jerked around, been stopped, fined and jailed.
I know of someone who hacked into some corporate computers in the 90s, just for fun - he never did any damage. He got off on a bond, but it chewed up two years of his life, lost him his job and really screwed him up.
There needs to be some deterrent otherwise people will do exactly as they please, without caring what it does to other people and with no fear it can hurt the
Re: (Score:1)
My rights online! (Score:5, Funny)
Re: (Score:1, Insightful)
Blowing up mailboxes is of course illegal and has been since long before there were mailboxes.
So... (Score:3, Interesting)
It has been illegal (Score:2)
It has been illegal, just not in the same sense as it now will be, as now it will be covered by the law regarding computer intrusion. The DDoS attacks against the police's website last year were filed under "taking the law into one's own hands" (egenmäktigt förfarande). Which is a bit nebulous of a category for it.
I am very sceptical that this law will have any real effect. Just some sable rattling to give an illusion that the government is in control of these things.
Re: (Score:2)
There, now it makes sense
-nB
botnets (Score:1, Funny)
seems reasonable (Score:4, Interesting)
Its basically always been illegal to screw around with someone elses machinery.
Re: (Score:1)
You poor people, the richest country on earth, I guess it's fitting.
Re: (Score:2)
Obviously changing your friend's round lawnmower weels with cubes, is something of a funny joke, and probably harmless and in theory you may be aquitted on the legal defense of "prank". (which sometimes works)
But tampering with a lawnmower is similar to tampering with a car. How would you
Punishment... (Score:4, Interesting)
At least the 'maximum punishment' of 2 years they are seeking does not seem too severe. If that maximum sentence isn't abused, and used only for those repeat offenders who just don't learn it seems alright...
Re: (Score:2)
Huh, well ... (Score:2)
So This Means... (Score:2)
Heh (Score:1)
I'm soooo moving to Sweden (Score:1)
Of course, this being /. I didn't read TFA but any country where if I stagger into a bar already drunk, they deny me service and throw me out physically and _they_ get charged for it is alright by me!
Re: (Score:1)
More importantly (Score:3, Informative)
Re: (Score:1, Insightful)
Oh, having a botnet of a few hundred zombies comes to mind...
Re: (Score:2)
Cell mate conversation (Score:1)
inmate two:yea, what are you in for?
inmate one:I murdered my family. You?
inmate two:... DOS
Maximum two years? (Score:2)
Isn't is already illegal? (Score:2)
Prior law (Score:2)
Don't they fall under some sort of Don't be an asshole common-law ?
simple javascript reload function (Score:2)
What a novel idea (Score:2)
What do you mean, it doesn't work? It has to, or they wouldn't pass a law making a DDoS illegal. Or do you mean they would pass an unenforceable law, because
a) DDoSs are by their very definition international
b) Drones are used that don't even know they participate
c) Finding a
Re: (Score:1)
Re: (Score:2)
Personally, I find this law ridiculous. But when you put it that way, it suddenly becomes very sensible and sane.
Re: (Score:1)
Re: (Score:2)
DoS - definition & punishment to whom? (Score:1)
Re: (Score:2, Informative)
Re: (Score:1)
Re: (Score:1)