HKSAR v. Tse Man Lai

Please refer to CACC455/2012 for the relevant appeal(s) to the Court of Appeal.
Case No.DCCC 1318/2011
Court
District Court
Date24 Oct 2012
Judge
Case Document
100%

DCCC1318/2011

IN THE DISTRICT COURT OF THE

HONG KONG SPECIAL ADMINISTRATIVE REGION

CRIMINAL CASE NO. 1318 OF 2011

----------------------

  HKSAR  
  v.  
  Tse Man-lai  
----------------------
Before: Deputy District Judge Longley
Date: 24 October 2012 at 9.36 am
Present: Ms Olivia Tsang, SPP, of the Department of Justice, for HKSAR
  Mr Bernard Chung, instructed by Messrs Cheung & Liu, assigned by the Director of Legal Aid, for the Defendant
Offence: (1) & (2) Obtaining access to computer with criminal or dishonest intent (有犯罪或不誠實意圖而取用電腦)

---------------------

Reasons for Verdict

---------------------

1.The defendant, Tse Man-lai, faces two charges of obtaining access to a computer with a view to dishonest gain for himself or another, contrary to section 161(1)(c) of the Crimes Ordinance, Cap. 200.

2.The prosecution case is that on two successive days, 12 and 13 August 2011, he accessed the desktop computer, Exhibit 15, at his home at Flat C, 23rd Floor, Block 5, Kenswood Court, Kingswood Villas, Tin Shui Wai, New Territories, and launched a denial of service attack of the web server of HKExnews, a website set up by Hong Kong Exchanges & Clearing Limited to disseminate news and price‑sensitive information.  It was admitted that the first attack occurred between 13:17:09 and 13:23:39 on 12 August 2011 and lasted 390 seconds.  The second attack occurred between 03:25:06 and 03:26:16 on 13 July 2011 and lasted about 70 seconds. 

3.There is no dispute that the attacks were launched from IP addresses successively assigned to a desktop computer, Exhibit P15, at the defendant’s home which he admitted that he alone used.  It is admitted that the first attack on 12 August used 48 per cent of the band width of HKExnews website and the attack on 13 August 54 per cent of the band width of the website.  Fortunately, because the remaining band width was unimpaired, the attacks did not affect the accessibility of the website by members of the public.

4.It is alleged that during the attacks on the web server of HKExnews, he created, insofar as the first attack is concerned, computer print screen in pictures and insofar as the second attack is concerned, video footage depicting the attacks and purporting to show their effect.  The prosecution allege that the dishonest gain sought by the defendant was still images, Exhibits P3, P4 and P5, of the first attack and the video footage, Video 20, of the second attack.  The prosecution case is that the defendant sought these images to promote the business of his company, Pacswitch Globe Telecom Limited by suggesting that it could provide protection against such attacks.

5.The background to the two charges is that on 10 August 2011, two days before the defendant is alleged to have first launched an attack, there were two denial of service attacks launched against the HKExnews website from overseas.  The first attack started at 10.45 am and lasted about 32 minutes.  The second attack started at about 11.30 am and lasted about 1 day 10 minutes.  There is no suggestion the defendant had anything to do with these attacks.  Unlike the attacks alleged to have been subsequently activated by the defendant which were a simple denial of service attacks (DoS attacks) launched from one computer, the two attacks launched on 10 August were what is known as distributed denial of service attacks (DDoS) launched from more than 300 different sources.

6.The effect of the attacks on 10 August was such that the top management of the Hong Kong Exchange inter alia ordered that trading in seven listed companies which had arranged to distribute market messages on 10 August 2011 be suspended.  As a result of these attacks, measures were taken by the Hong Kong Exchange to protect the HKExnews website, including 1) causing the system’s intrusion prevention system (IPS) to block the IP addresses which had launched the attacks and 2) upgrading the band widths on the system from 30 to 50 megabits per line.

7.In support of its case against the defendant, the prosecution adduced a variety of computer evidence, much of it derived from the desktop computer itself.  The prosecution inter alia adduced evidence of the following from the defendant’s computer:-

1) Three still images, Exhibit P3, P4 and P5, created on the defendant’s computer at 13:18:48, 13:19:11 and 13:19:40 respectively on 12 August which the prosecution say were images created showing the 1st defendant’s first attack underway.

2) A UDP flooder programme which the prosecution say was used to launch both of the defendant’s two attacks which was created on the defendant’s computer just before his first attack on 12 August.

3) Three video files recorded by a cam-studio programme on the defendant’s computer which the prosecution say were produced before and during the defendant’s second attack on 13 August 2011. In particular, Video File 43 showing that the user had browsed a news article at the website of Yahoo News relating to the two attacks from overseas on 10 August just before the defendant’s second attack and those parts of Video File 20 that were recoverable, namely 1 minute 53 seconds, showing what the prosecution say was a video film of the defendant’s second attack on 13 August being executed.

4) A webpage showing that the user had established a blog webpage entitled “Blogger Ernest Networking”. The prosecution rely upon what is said upon this blog, Exhibit P28, to which the images, Exhibit P3, P4 and P5, were attached, as evidence that the defendant was maintaining that it was easy to launch a DDoS attack on HKExnews. The prosecution also rely on this blog coupled with a cached version of it made at 18:03:24 on 13 August 2011, Exhibit P11, with certain words added, as evidence that the defendant intended to use the images he had made to promote the business of his company.

5) A draft of an e-mail from the defendant to the internet news site of Ming Pao saved at 03:23 on 13 August 2011, i.e. during his second attack on HKExnews entitled “Simple steps to DDoS HK Ex Website Demo” to which he had attached the images Exhibits P3, P4 and P5.

6) An e-mail sent by the defendant to someone called Mark at 02:51 am on 13 August 2011, Exhibit P32(2) just before he activated his second attack in which he said that he was interested in developing “anti-DDoS solution for customer”.

8.The prosecution also adduced evidence that the defendant had posted comments on two news pages of the Yahoo News website which contained reports of the DDoS attacks on HKExnews from overseas on 10 August. The prosecution allege that at 13:49:17 on 12 August, i.e. shortly after the defendant’s first attack, he posted a message headed “Attack on HK Ex Website: demo” to which he had added a website link to his blog, Exhibit P33.

9.The prosecution also rely on two comments which they say were posted by the defendant on another news page of Yahoo News, the first posted at 12:55:49 on 12 August 2011, i.e. shortly before what the prosecution say was his first attack in which he states how easy it is to launch DDoS attacks and that Hong Kong people are ignorant concerning them. The second was posted 13:46:14 on 12 August shortly after the first attack commenting that there were “ways to 100 per cent stand the attack of DDoS”.

10.There has been no dispute that the defendant was the person who physically caused the two attacks on the website of HKExnews which are the subject of the charges before the court by activating the UDP flooder programme which he had downloaded onto his computer, Exhibit P15, nor is there any dispute that he created the still and video images depicting or purporting to depict attacks on the HKExnews website.  His defence is that he had no intention to affect the HKExnews website nor any intention to gain any benefit from his action. 

11.Insofar as the first attack between 13:17:09 and 13:23:39 on Friday, 12 October 2011 is concerned, he maintains that he intended to write a tutorial article describing how a DDoS attack occurred and in obtaining images for this article had not realised that his computer was still connected to the internet.  As far as the second attack is concerned, while he accepts he launched the attack he claims that he believed that the measures recently instituted by the HKExnews website were effective to prevent an attack on its website and he wished to create a video to add to his article demonstrating to members of the public that that was so. 

12.The defendant’s evidence was that he was an investor on the Hong Kong Stock Exchange and had learnt of the suspension of trading in the seven shares on 10 August but had only learnt that it was the result of a computer attack on 12 August.  That morning he had read an article in Yahoo News, Exhibit P34, about the attack as well as comments posted by other readers.  He said he felt shocked that such a thing could happen in Hong Kong and that people in Hong Kong had so little knowledge about DDoS attacks.  He also felt angry that the additional precautionary measures referred to in the article had not been taken earlier.  He believed that there were ways of safely blocking DDoS attacks.  He therefore added his own comment to the news article at 12:55 in which he said that it was extremely easy to launch a DDoS attack and decried the ignorance of people in Hong Kong. 

13.He said that after he had posted the comment, the idea came to him to write a tutorial article to teach others about the nature of DDoS attacks.  In order to create the images for his article, at 13:14 he had downloaded a UDP Flooder programme as it was the sort of programme hackers would use to launch an attack as well as a programme called Watchmouse which would demonstrate the accessibility of a particular website.  Having downloaded the Watchmouse programme, he keyed in the website address of HKExnews and activated the programme.  According to him, the image that appeared on the screen showed that the website of HKExnews was fully accessible.  He says he had used screen capture software to capture the image and after doing so had used Photoshop software to alter the screen image so it appeared as in Exhibit P5.  These alterations resulted in the image which appeared to show that HKExnews website was inaccessible.  He said that this was for the purpose of depicting in his article the effect of a successful attack. 

14.Having created the image, P5, he then took what he believed were the necessary steps to disconnect his computer from the internet.  He said that he did this as he did not “want any further action to affect HKExnews website”.  He then took steps which would normally open the website of HKExnews which resulted in the image P4 indicating that his web browser Google Chrome was unable to load the webpage of HKExnews.  He then captured that image for his article as the image would be similar to that which would appear after a successful DDoS attack.  He then opened the UDP Flooder programme which he had earlier downloaded, typed in the website address of HKExnews and filled in the particulars in the flooder to similate an attack on the HKExnews website.  He pushed the “go” button and then captured that image, Exhibit P5, before pushing the “stop” button.

15.In order to start to write his tutorial on his blog, he had gone to activate the internet connection only to find that he was still online and had not, as he had believed, logged off.  He nonetheless thought that the measures put in place by HKExnews after the overseas attacks on 10 August described in the Yahoo news article, Exhibit 34, would have prevented any attack affecting its website.  He had thereafter gone to his blog account and started to draft his tutorial incorporating the images P3, P4 and P5.  He claimed that as he was in hurry to leave for the office, he had saved the blog before it was finished as a draft.  He said that P28 is that draft. He had then posted a link from the unfinished article on his blog to another Yahoo news page, Exhibit P33.  He claimed that he did so to save time as he would be able to access his draft more conveniently at this site later when he wished to carry on editing it.  Later in cross-examination, he also claimed that he posted this link to this webpage so that his comments when they were ultimately published would be the first to appear on that page.  In the meantime, despite the link, his blog would be inaccessible to members of the public until he had finished editing it and had published it. 

16.His explanation for the second attack was that after he arrived home at around 2.45 am on the morning of 13 August, he decided to continue to edit the unfinished article, P28, on his blog.  As the final part of his blog tutorial was to prove to members of the public, including those who had left messages on the Yahoo website, Exhibit P34, that HKExnews was by that stage, as a result of the measures taken after the overseas attacks on 10 August, able to counter a cyber attack, he had downloaded a programme called Cam Studio to create a video demonstrating how he had launched a UDP attack on HKExnews using two UDP flooders operating at maximum level and that HKExnews had been unaffected.  After he had activated the two UDP flooders, he eventually found that both the Watchmouse programme and the HKExnews website itself indicated that HKExnews website was inaccessible.  He therefore stopped both UDP flooder programmes because in his words, “I didn’t know if it was caused by the problem of my computer, I wanted to stop everything and reboot the system”.  He then stopped the Cam Studio recording and restarted the computer and there was no problem.

17.As far as Exhibit P11, the cached image reflecting what was on the website “http:/pacswitchreview.blogsplot.com/2011/08/demo.html” at 6.03 pm on 13 August 2011 and would therefore have been accessible to members of the public if they had clicked on the link at the Yahoo News website, P11, the defendant said that he first saw it on his wife’s laptop when he woke up.  He said that insofar as the relevant contents differed from his draft, P28, the alterations had not been made by him.  He said that he had asked his wife about it but he called no evidence as to how it had come about. 

18.In assessing the evidence in this case and the credibility of the account given by the defendant, I have borne in mind that the defendant is a man of previous good character.

19.I am however in no doubt that the defendant’s account of how the attacks on the website of HKExnews which he admits were activated by him came about were untrue.  I propose to refer to just some of the reasons that led me to that conclusion.

20.I found implausible his explanation that his purpose in creating the three images, Exhibits P3, P4 and P5, was simply to educate the public as to how DDoS attacks occurred.  Bearing in mind what he drafted in P28, it is difficult to imagine what educational value or interest they would have had since Exhibit P4 and P5 simply show that HKExnews website was inaccessible and on his account he had cut out the name of the UDP flooder programme from Exhibit P3 lest it be used by what he described as “real hackers”.

21.I find equally implausible his account that his purpose in creating Video 20 was to demonstrate to members of the public that the measures adopted by HKExnews to prevent cyber attacks were successful.  He was only launching an attack from one computer whereas the attacks on 10 August had shown, and it had been reported in the Yahoo news article, Exhibit P34, that the website was open to attack by hundreds of computers. 

22.It was the defendant’s evidence that he had read the article in the Yahoo News of the overseas attacks on 10 August and the measures taken by HKExnews to prevent further attacks before the first attack activated by him on 12 August.  His assertion that he believed the HKExnews website was then a 100 per cent capable of countering further attacks affecting it is undermined not simply by the article, Exhibit P34, itself which indicated that despite the new measures adopted by HKExnews the second wave of attacks on 10 August had still slowed down its website, albeit when the attack was from multiple computers rather than one, but more significantly by the reason given by him for allegedly disconnecting from the internet before activating the UDP flooder programme on 12 August, namely because he did not want “any further action to affect HKExnews website”.

23.As far as the first attack activated by him on 12 August is concerned, I did not believe that a man with his background in computers both academic and as a director and main shareholder of a company providing computer networking services would have failed to ensure that his computer was disconnected from the internet before activating the UDP Flooder programme.  I did not believe his evidence as to the manner and sequence in which he had created the images P3, P4 and P5.  No reason was given as to why there should have been a difference in the times he captured the images and then created the images on his computer which indicated that Exhibits P3, P4 and P5 were created in that sequence, 13:18:48, 13:19:11 and 13:19:40 respectively during the defendant’s first attack which is admitted lasted from 13:17:09 until 13:23:39 on 12 August.  Moreover, if he had mistakenly failed to disconnect his computer from the internet, there is no apparent reason why the image, P4, indicating that Google Chrome was unable to load the HKExnews webpage should appear. 

24.I disbelieved his evidence of how he captured an image after accessing Watchmouse.com and then edited it using Photoshop to produce the image P5.  I am satisfied that there would not have been sufficient time for him to do this bearing in mind that he accessed the Watchmouse.com website at 13:16:16 on 12 August and created the image P5 at 13:19:40 the same day and that the editing would have involved not merely changing the ticks on the screen to crosses, altering the figures on the left of the page and removing the dark bars on the image but in doing so selecting identical crosses, identical typeface and identical colouring to that which would appear on the webpage if it was genuine when he was also performing other activities on the computer.  I find that P5 represents an image which resulted from the attack activated by him against HKExnews on 12 August.

25.The wording of the defendant’s blog, Exhibit P28, in itself alone demonstrates the falsity of the defendant’s account. According to him, it was drafted after he had read of the additional measures taken by HKExnews to protect their website and he was satisfied they were effective yet in the article he says, “In fact the HKExnews of SEHK has done nothing to guard against DDoS attack, only three steps can kick down”.  He then illustrated this with Exhibits P3, P4 and P5 and later went on, “Their IT department is composed of a bunch of people without network knowledge, how can they protect Hong Kong?”  I disbelieved his explanation that in writing these words he was referring to a time in the past.  They clearly refer to the present.  I am satisfied that what this article was suggesting was that at the time he wrote this article the website was still vulnerable to a DDoS attack which was very easy to launch and he was illustrating it by showing that he had launched a very simple attack from one computer which had affected the website. 

26.I have no doubt that the defendant deliberately launched the attack on 12 August referred to in charge 1 and captured the images, Exhibits P3, P4, P5, to illustrate it.  I am also satisfied that the defendant deliberately launched the attack which is the subject of charge 2 and that the video footage 20 was taken by him in the course of the attack to illustrate the same thing. 

27.I am further satisfied that the purpose behind these attacks was to promote the services of the defendant’s company, Pacswitch Globe Telecom Limited.  It is clear from Exhibit P11, the amended version of the defendant’s blog, Exhibit P28 which was captured at 6.13 pm on 13 August that the reader who wanted to counter a DDoS attack was invited to contact Pacswitch Globe Telecom whose website was given and order a means of preventing such attacks known to the defendant.  I disbelieved the defendant’s evidence that although he had written the words, “Of course (you) can also” (missing verb) “the means that I studied” in his draft, P28, he had nothing to do with the insertion of the verb “order” and the website address of Pacswitch in P11. The defendant’s explanation of what he intended to say in P28 is inconsistent with what he wrote in P28.  I am satisfied that the sentences that appears in P11 demonstrates the defendant’s intention when he wrote P28.  On the evidence before me, I do not believe anyone would have altered P28 and published it as P11 without the defendant’s authority.

28.I would add that the email that the defendant sent to somebody called Mark at 02:51 am on 13 August, Exhibit P32(2) just before he launched his second attack in which he spoke of his interest in developing inter alia “anti-DDoS solution for the customer” while not evidence in itself that he wanted to sell such a system to customers bearing in mind that he was conducting a web hosting business, was evidence of a desire to acquire such anti-DDoS solutions which if he had already not done so would be necessary if he was to market such solutions through Pacswitch. 

29.After reaching these findings of fact, I have gone on to consider whether on those findings I can be satisfied that the defendant is guilty of each of the charges under section 161(1)(c) of the Crimes Ordinance he faces.  I have considered each charge separately.

30.The allegation in each charge is that he obtained access to a computer with a view to dishonest gain to himself.  In this case there is no dispute that the computer that he accessed was his own. I am satisfied there is nothing in section 161 which restricts the offence to accessing a computer belonging to another person.

31.Before a person can be guilty of an offence under section 161(1)(c), he or she must have obtained access to a computer and that at the time of obtaining such access have done so “with a view to dishonest gain for himself or another”.  I have therefore had to consider the time that the defendant obtained access to the computer.  In this case there is nothing to contradict the defendant’s statement in his cautioned interview, Exhibit P2, that he had bought the computer in August 2010 nor is there anything to cast any doubt on his evidence in court that he kept the computer continuously switched on. 

32.The defence have pointed out from MFI-1 which is a printout extracted from Exhibit P10A that the defendant appears to have been visiting other unrelated websites before he activated the UDP Flooder to launch each of the attacks which form the subject matter of the charge.  In such circumstances I have had to consider what is meant by the term “obtains access” in this section.  Neither the prosecution nor the defence have sought to argue that access is confined to unauthorised access.  I find that section 161 is equally applicable to both authorised and unauthorised access. 

33.While Ms Tsang for the prosecution alleges that the times that the defendant obtained access to his computer for the purpose of this prosecution were the times he opened the UDP Flooder programme on his computer and activated the programmes against the website of HKExnews on 12 and 13 August, Mr Chung argues that on the evidence, the time that the defendant obtained access to his computer was much earlier, if not when he purchased the computer then when he started to use the computer in the middle of the day on 12 August insofar as charge 1 is concerned and in the early morning of 13 August insofar as charge 2 is concerned.  He argues that there is a difference between obtaining access to a computer and accessing it. 

34.I find that a purpose obtains access to a computer for the purpose of section 161 not simply when he purchases a computer or switches it on or indeed in a particular session when he first sits down and visits a particular website.  I am satisfied that a person can obtain access to a computer on multiple occasions, even during a single session sitting in front of his own computer.  I do not find there is any practical distinction between obtaining access and accessing a computer for the purposes of this section.  In the circumstances of this case, I am satisfied that even if he had been visiting unrelated websites beforehand, the defendant can be said to have obtained access to his computer again when he opened the UDP Flooder programme and then activated it against the HKExnews website both on 12 August, charge 1, and 13 August, charge 2.

35.It is common ground between the prosecution and the defence that both the images, Exhibits P3, P4, P5, and the video footage, Video 230, would constitute gain for the purpose of the 161(1)(c) in light of the definition of gain in section 161(2).  I therefore find that both in relation to the attack on 12 August, charge 1, and 13 August, charge 2, the defendant obtained access to the desktop computer referred to in the charge with a view to gain for himself or others.

36.It finally falls for me to consider whether he did so with a view to dishonest gain.  The test to be applied in determining this issue is that laid down in R v Ghosh [1982] QB 1053.  Firstly, therefore I can have to consider whether the gain sought by the defendant was dishonest according to the ordinary standards of reasonable and honest people. I am satisfied that the gain sought by the defendant both on 12 August, the still images on 13 August, the video footage, was in the circumstances dishonest by those standards. 

37.Bearing in mind the significance of the webpage of HKExnews to investors, reasonable and honest people would realise the importance of preserving its security and accessibility.  For someone without seeking permission or giving warning deliberately to send a huge quantity of UDP packets at the same time to HKExnews, aware as I am sure the defendant was that there was at least a risk that it would affect the accessibility of the HKExnews website, with a view to obtaining still images or video footage of the attacks would be regarded as dishonest by the standards of reasonable and honest people.  I am satisfied that that would even more so be the case if they knew that the defendant was seeking the still and video images in order to promote his business. 

38.I have then to consider whether the defendant knew or must have realised on each occasion that the gain he was seeking was dishonest by those standards.  I have no doubt that he did.  I disbelieved his evidence that he was confident that his attacks would have no effect whatsoever on the HKExnews website.  His own account of the reasons he attempted to disconnect his computer during the first attack itself shows that.  I am satisfied he wanted to demonstrate that the website was still vulnerable to attack.  At the very least when he launched the attack he would have been aware that there was a risk of it affecting the accessibility of the website and bearing in mind his knowledge of computers would have anticipated that staff of HKExnews would take steps to block his IP address. 

39.I find that both on 12 and 13 August he accessed his computer with a view to dishonest gain for himself.  I find him guilty of both charges.

  P.K.M. Longley
  District Court Judge

Please refer to CACC455/2012 for the relevant appeal(s) to the Court of Appeal.

Other Judgments in This Case

Further hearings and rulings under DCCC 1318/2011