-4The prosecution says that the bank, as owner, established its server to receive and
respond to genuine requests for its services. Causing the computer to respond to
requests which were sent only for the purpose of using up its bandwith was
causing it to function other than as the bank had established it to function. The
appellant, on the other hand, said that the computer was established to receive
and respond to requests. During the attack it responded to the appellant’s and
other requests exactly as it had been programmed to do. The attack caused no
difference to the way it functioned.
The 1993 Ordinance
8.
The Computer Crimes Ordinance 1993 created a number of crimes
under various Ordinances in relation to computers. The simplest was the offence
of unauthorised access to a computer by telecommunications (“hacking”),
punishable by a fine and inserted into the Telecommunications Ordinance
Cap 106 as section 27A. The offence is committed by a person who (1) by
telecommunications (2) knowingly causes a computer to perform any function
(3) to obtain unauthorised access to any program or data held in a computer. The
offence is committed simply by obtaining unauthorised access through the
internet (“by telecommunications”), whether on account of curiosity, malice or
dishonest intent. It protects the privacy of ordinary computers. Websites, on the
other hand, invite the public to access them. There may of course still be
unauthorised access to a particular “program or data” on the websites contrary to
section 27A but websites also require a different form of protection.
9.
The new section 161 of the Crimes Ordinance dealt with obtaining
access with intent to commit an offence, with a dishonest intent to deceive or with
a view to dishonest gain or with a dishonest intent to cause loss.