HKSAR v. Tse Man Lai
|
CACC 455/2012 IN THE HIGH COURT OF THE HONG KONG SPECIAL ADMINISTRATIVE REGION COURT OF APPEAL CRIMINAL APPEAL NO. 455 OF 2012 (ON APPEAL FROM DCCC 1318 OF 2011) ____________ BETWEEN
____________
____________ J U D G M E N T ____________ Hon Lunn JA (giving the judgment of the court): 1.The applicant seeks leave to appeal against his convictions by Deputy District Court Judge Longley on 24 October 2012 of two charges of obtaining access to a computer with a view to a dishonest gain for himself or another, contrary to section 161(1)(c) of the Crimes Ordinance, Cap. 200. The applicant’s application for leave to appeal against the sentences of 9 months’ imprisonment imposed in respect of each charge was dismissed on 28 December 2012, after the applicant had filed a Notice of Abandonment in respect of that application. THE CHARGES 2.The ‘Particulars of Offence’ of the two charges alleged that, on 12 and 13 of August 2011 respectively, the applicant:
THE TRIAL The prosecution case 3.The prosecution case was that on 12 and 13 August 2011 respectively the applicant had directed ‘Denial of Service’ attacks from his computer to the web server of the ‘HKExnews’, a website set up by the Hong Kong Exchanges and Clearing Limited for disseminating information to the public in respect of stock transactions. It was an admitted fact that the two Internet Protocol (IP) addresses from which those attacks were launched were assigned to the applicant’s mother at the address stipulated in the Particulars of Offence. The attack began about 13:17:09 on 12 August 2011 and was 390 seconds in duration. It used 48% of bandwidth of the HKExnews website. The attack on 13 August 2011 began at 03:25:06 and was 70 seconds in duration. It used 54% of the bandwidth of the HKExnews website. On each occasion, the remaining bandwidth was unimpaired and access was possible to the website by members of the public. 4.The context in which the conduct occurred was that on 10 August 2011 the Hong Kong Stock Exchange had been forced to suspend trading in the shares of seven listed companies, each of which was to make a public announcement on the HKExnews website, after the website was attacked by a ‘Distributed Denial of Service Attack’, which prevented the general public accessing the website during the two separate attacks, the latter being for a duration of 24 hours. 5.It was the prosecution case that the dishonest gain that the applicant sought from mounting the two attacks on the HKExnews website was to obtain images from the computer reflecting the attack, in the case of the first attack (charge 1) three still images and in the case of the second attack (charge 2) video footage. The prosecution contended that the applicant obtained those images in order to promote the business of his company, Pacswitch Globe Telecom Limited (‘Pacswitch), in particular so that it could be suggested that Pacswitch could provide protection against such attacks. 6.There was no dispute that those still images and the video footage, together with other material relevant to the prosecution case, had been located by police officers in the desktop computer used by the applicant. Among that material was a UDP Flooder programme, which the applicant had used to attack the HKExnews website. The defence case 7.The applicant did not dispute the prosecution case that he was the person who caused the two attacks on the HKExnews website on 12 and 13 August 2011 by activating the UDP Flooder programme. Similarly, there was no issue that he created the still and video images depicting those attacks. At issue, was his intention in doing so. He contended that he had no intention to affect the HKExnews website nor any dishonest intention to gain any benefit. 8.As an investor on the Hong Kong Stock Exchange, the applicant said that he was shocked to learn of the successful attack on the website on 10 August 2011. In particular, he was shocked that there was no protective screen in place to prevent a ‘Distributed Denial of Service’ attack. As a result, he posted a comment on Yahoo News and decided to write a tutorial article to inform others about the nature of such an attack. In order to create the images to illustrate that article he downloaded a UDP Flooder programme and a Watchmouse programme. Then, he logged into the HKExnews website and activated the programme, capturing the images with screen capture software. Having done that, he used Photoshop software to alter the image, so as to indicate that the website was inaccessible as a result of the attack. 9.Although the applicant thought that he had disconnected his computer from the Internet, he had not done so and when he logged on to the HKExnews website again another image was created indicating that access was denied to the website. He captured that image as well, intending to use it in his tutorial article. The applicant posted a half finished article on his blog together with the still images he had captured depicting the results of the first attack. The article posted the still video images and the applicant wrote:
10.The applicant explained the second attack as having resulted from his wishing to add to his unfinished article a video demonstrating that notwithstanding the attack the HKExnews website had been unaffected. However, when he activated the UDP Flooder, the resulting image indicated that the website was inaccessible. REASONS FOR VERDICT 11.In his reasons for verdict the judge rejected the applicant’s evidence of how it was that his attacks on the HKExnews website came about. Also, he rejected the applicant’s explanation as to his purpose in creating the three still images and the video image as being “implausible”. 12.In respect of the first attack (charge 1), the judge said that he did not believe the applicant’s account of how he had failed to ensure that his computer was disconnected from the Internet before activating the UDP Flooder programme. The Judge found that the wording of the applicant’s blog suggested that the HKExnews website was vulnerable to a DDoS attack as he illustrated from an attack from one computer. In the result, the judge determined that the two attacks were launched deliberately by the applicant and that he had done so to promote the services of his company, Pacswitch. The judge said that much was apparent from the amended version of the defendant’s blog:
The judge said that was an invitation to the reader to contact the applicant’s company to order a means of preventing such attacks. The judge rejected the applicant’s testimony that he had nothing to do with the insertion of the verb “order” in the amended version of the blog. He found that the amended version conveyed the meaning that the applicant had intended to convey in the original version. Section 161 (i) Obtaining access to a computer 13.Noting that the access to a computer by the applicant was to his own computer, the judge determined that the operation of section 161 of the Crimes Ordinance was not restricted to accessing computers belonging to another. That access could be authorised or unauthorised. Of the time that the computer was switched on, the judge said that there was nothing to contradict the applicant’s evidence that having bought the computer in August 2010, “he kept the computer continuously switched on”. 14.Having observed that the offence-creating provision required proof that the applicant obtained access to the computer with a view to gain for himself or another, the judge addressed the question of when it was that the applicant had obtained access to the computer. He acknowledged that there was uncontradicted evidence that the computer had been used on 12 August 2011 to visit other websites prior to the activating of the UDP Flooder programme and prior to the attack on the HKExnews website. 15.The judge noted that it was submitted on behalf of the applicant that he obtained access to the computer either when it was first switched on in August 2010, or earlier in the day of August 2011 when he visited other websites prior to the attack on the HKExnews website, in which case there was no evidence that he did so with a view to dishonest gain. However, the judge rejected the submission and found:
(ii) Dishonest gain 16.The judge found that the applicant had obtained access to the computer with a view to obtaining the three still computer images (charge 1) and the video recording of the computer image (charge 2). Noting that it was common ground between the parties that, in light of the definition of “gain” in section 161(2) of the Ordinance, that conduct constituted a gain for purposes of section 161(c) of the Ordinance, the judge determined that the applicant had obtained access to his computer, “with a view to a gain for himself or others”. 17.Applying the test stipulated in the judgment of the Court of Appeal of England and Wales in R v Ghosh [1982] QB 1053 the judge determined that the gain sought by the applicant on both occasions was dishonest according to the ordinary standards of reasonable and honest people and that the applicant knew that his conduct was dishonest by those standards. In the result, the judge said that he was satisfied that the applicant had accessed his computer on each of 12 and 13 August 2011 with a view to dishonest gain for himself. Accordingly, the judge found the applicant guilty of both charges. GROUNDS OF APPEAL AGAINST CONVICTION Ground 1 18.By ground 1, it was submitted that the judge had erred in finding that there was no, “practical distinction between obtaining access and accessing a computer for the purposes of this section”. Further, it was contended that the judge erred in determining that the applicant had obtained access to his computer at the time that he launched the two attacks on the HKExnews website as stipulated in the two charges. 19.In support of this ground, Mr David Iu drew the court’s attention to the judgment of the court in R v Hung Hak Sing [1995] 3 HKC 327. In the judgment of the court Mortimer JA, as he was then, said of the ingredients of the offence (page 330 A):
20.In addition, Mr Iu relies on the judgment of Chan CJHC, as he was then, in a magisterial appeal in HKSAR v Tsun Shui Lun [1999] 2 HKC 547 in which he analysed the ingredients of the offence, noting that subsections (a) to (d) of section 161 provided four separate circumstances of mens rea and said (page 554 A-B):
Ground 2 21.By ground 2 it was submitted that, in determining that the applicant had conducted himself with a view to dishonest gain for himself or another, the judge erred in determining that the applicant was dishonest having failed to take into account evidence that militated against that finding, in particular that he had not sought to conceal his identity, either in respect of his IP address or his name, Ernest, on his blog. A CONSIDERATION OF THE SUBMISSIONS 22.It is to be noted that in Hung Hak Sing and Tsun Shui Lun the courts were concerned with allegations of access by the respective defendants of computers belonging to others, in the former case that of the Immigration Department and in the latter case Queen Mary Hospital. Whilst they were authorised generally to access the respective computers their access on the occasions the subject of the charges was unauthorised, given that it was for personal purposes and for reasons other than those for which they were authorised to access the computers. 23.In Hung Hak Sing the defendant accessed the Immigration Department’s computer to ascertain whether certain persons were on the ‘watch list’. However, the judge rejected the prosecution case that he did so with a view to monetary gain. Rather, he found that he did so out of friendship. It was in that context that Mortimer JA made his observation that the act was complete once access is obtained. He said:
24.In Tsun Shui Lun the defendant was charged with having access to the Queen Mary Hospital computer on 3 April 1998 with a view to gaining information in respect of the state of the health of the then Secretary for Justice with the purpose of disclosing that information to a newspaper. Chan CJHC noted that the defendant had accessed the computer the previous day and obtained information as to her health. Of that, he observed:
25.By contrast, Chan CJHC was satisfied that the defendant’s conduct on 3 April was dishonest since the access of the computer on that day was done in order to obtain the information for the purpose of releasing it to the media. It is in that context, that his observation that the crucial point in time is “the intent or purpose of the offender at the time of the access” is to be viewed. 26.Neither case was concerned with the access by defendant of his own computer nor with the situation faced by the judge in this case of a computer that had been switched on and left on for many months. 27.There is no reason why the section should be construed in a restrictive way in which obtaining access to a computer is to be regarded as a singular event, for example when it is first turned on or first used. A purposive construction of the section is in accordance with the approach of the judge, in particular, that a person can obtain access to a computer on multiple occasions in one single session. Accordingly, such a person is to be regarded as obtaining access to a computer in respect of each separate discrete use of the computer. Read in that way, the section operates to catch a person who obtains access to a computer with a view to a dishonest gain, even in circumstances where the earlier access by the person to the computer had been entirely innocent. However, it is necessary that there be a coincidence of the actus reus, namely obtaining access to a computer, with the mens rea, namely with a view to a dishonest gain for himself or another. 28.In those circumstances, we are satisfied that the judge was correct in determining that there was no practical distinction between “obtaining access and accessing a computer for purposes of this section.” Dishonesty 29.In his consideration of whether or not the prosecution had proved that the applicant had conducted himself in the way that he did with a view to a dishonest gain the judge addressed both the objective and subjective limbs of the test in Ghosh. Of the former, the judge found that reasonable and honest people would realise the importance of preserving the accessibility of the HKExnews website and that sending a huge quantity of UDP packets at the same time gave rise to risk as to that accessibility, so that they would regard that conduct as dishonest. Of the latter, the judge said that he disbelieved the applicant’s evidence that he was confident that his attacks would have no effect whatsoever on the website. He said that he was satisfied that the applicant wanted to demonstrate that the website was “still vulnerable to attack”. In those circumstances he said that the applicant “would have been aware that there was a risk of it affecting the accessibility of the website”. 30.There is no dispute that in his closing speech counsel for the applicant invited the judge to have regard to features of the evidence which he submitted were indicia that militated against dishonesty in the applicant at the time that he obtained access to the computer. The judge had been asked to note that the applicant had not used all the bandwidth available to him when he launched the attack using the UDP Flooder. Further, he had not sought to hide his identity which was detectable from his IP address, the reference to the website of Pacswitch posted on his blog and his name ‘Ernest’ displayed on that blog. 31.It is true that the judge did not deal with those factors specifically in his Reasons for Verdict. On the other hand, he did find that the purpose behind the applicant’s conduct was to solicit for business for Pacswitch as being able to provide protection from a DDoS attack, for which purpose he had obtained and then posted the three still images and the video footage of the attack. Obviously, soliciting business in that way necessitated revealing one’s identity. Clearly, the judge’s positive finding in that regard is to be taken as traversing the force of the points made on behalf of the applicant, namely that he did not seek to hide his identity. Conclusion 32.In the result we are satisfied that there is no merit in the proposed grounds of appeal against conviction. Accordingly, the application for leave to appeal against conviction is refused.
Ms Vinci Lam, SADPP (Ag), of the Department of Justice, for the Respondent Mr David Iu, instructed by Cheung & Liu, for the Applicant |
Cases cited in this judgment