-612.
The reasons of the judge are likewise mainly given over to the
question of whether the appellant intended to participate in the attack. He also
dealt briefly with the question of construction. He said of paragraph (a) of section
59(1A) “obviously, over 500,000 ‘requests’ within 11 minutes would not be the
established way of functioning of the computer under attack”. As to paragraph
(c), he said that the requests had added data “even when they were of such minute
amount”.
Paragraph (a)
13.
I do not think that it is sufficient to say that the computer functioned
as it had been established to do because it dealt with the attackers’ requests in
accordance with what it had been programmed to do. Generally speaking,
computers can only do what they have been programmed to do and such a narrow
construction would deprive paragraph (a) of any effect. This conclusion is
reinforced by the words “notwithstanding that the misuse may not impair the
operation of the computer or a program held in the computer or the reliability of
data held in the computer”. Mr Shek was hard put to offer an example of an act
which came within his construction of “other than as it has been established to
function by … its owner” which was not excluded by the following words. In my
opinion the functions for which the computer is established to do are not so much
concerned with the way it works (or fails to work) but what it was intended to do.
The way it works depends upon how it was constructed by its manufacturer. But
the statute is concerned with what the owner has set it up to do. The website and
its server were established to provide banking services, not to deal with a
multitude of requests made for no purpose except to inconvenience the bank and
its customers and generate publicity for the attackers.