ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Peer loses cybercrime fight

Tom Espiner ZDNet.co.uk

Published: 14 Jul 2006 16:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Conservative peer's attempt to amend a law that could criminalise IT professionals has failed.

The Earl of Northesk's attempt to introduce amendments to the Computer Misuse Act 1990 (CMA) through the Police and Justice Bill 2006 did not pass committee stage discussions on Wednesday.

This proposed law has been heavily criticised by Lords and senior security experts, who say it could criminalise both the police and innocent IT professionals who build or make available programs which are then used for hacking.

The Earl of Northesk attempted to delete a section of the Act which he argued will make it illegal to create or distribute software tools that are likely to be used for hacking purposes. The clause, sub paragraph (b) of Section 41 of the Act, makes it an offence to release any application that is likely to be used for cybercrime purposes.

It is intended to address the rise of organised cybercrime. However, Northesk believes this could seriously backfire.

"Potentially, the police could fall foul of this law. This wasn't denied [in the discussion], which I find surprising," the Earl of Northesk told ZDNet UK.

The Earl of Northesk also said that ethical hacking and penetration testing could be made illegal by the law, as well as courses offering ethical hacking training.

"Increasingly universities are offering ethical hacking degrees, such as Aberdeen. Under sub paragraph (b), these would be illegal. Again, this wasn't countered," said Northesk.

The peer said it was unlikely that his amendment would now be carried into law.

"I don't hold out much hope for a parliamentary response — their minds are set," Northesk said.

As it stands, the current text of the amendment states:

After section 3 of the 1990 Act [CMA] there is inserted —

"3A Making, supplying or obtaining articles for use in offence under section 1 or 3

(1) A person is guilty of an offence if he makes, adapts, supplies or offers to supply any article —

(a) intending it to be used to commit, or to assist in the commission of, an offence under section 1 or 3; or

(b) believing that it is likely to be so used.

Dr Richard Clayton of Cambridge University warned in May that part (b) would catch a wide range of IT tools and activities that are not meant to be used in hacking, but potentially could be.

Clayton cited the Perl scripting language, created by Larry Wall in 1987, as an example of a useful technology that could fall foul of the law.

"Perl is almost universally used on a daily basis to permit the Internet to function," said Clayton. "I doubt if there is a sysadmin on the planet who hasn't written a Perl program at some time or another. Equally, almost every hacker who commits an offence under section 1 or section 3 of the CMA will use Perl as part of their toolkit. Unless Larry is especially stupid, and there is very little evidence for that, he will form the opinion that hackers are likely to use his Perl system. Locking Larry up is surely not desirable."

Part (b) has also been strongly criticised by security experts from the United Kingdom Education and Research Networking Association (UKERNA), the body responsible for the JANET educational network.

Andrew Cormack, chief security adviser for UKERNA, told ZDNet UK in May that the amendment would be likely to criminalise those who create or supply tools that have the potential for both legitimate and malicious use.

"A satisfactory law on making and supplying tools has to take account of the intention of the person making or supplying them. A person who clearly intends them to be used for good must not be at risk of prosecution," said Cormack.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
246 out of 317 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

SAP HCM Business Development Executive (Europe)

We are looking for experienced consultants with a strong background in HCM transformation who are viewed as subject matter experts in this area, with ...

Assistant Head of IT (Service, Design and Transition)

Essex Police Assistant Head of IT (Service, Design and Transition) 46,647 - 52,776 p.a. Essex Police is committed to providing the highest standard ...

ITIL Change Manager UK: Corporate IT - Corby, N. Hants

Overview: A new position has been created within Corus IT-Supply organisation for a Change Manager UK, whose primary focus is to act UK local ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment