Advertisement
Promo

Compliance Toolkit

It's time for the Government Misuse Act

Leader ZDNet.co.uk

Published: 22 May 2006 15:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The sooner parliament is dragged kicking and screaming out of the 19th century and into this one, the better for us all – Alan via ZDNet UK Talkback

If the law is an ass, then IT law must be an exceptionally short-sighted donkey. While it is laudable that lawmakers have finally woken up to the threat posed by Distributed Denial of Service (DDoS) attacks and are attempting to amend the Computer Misuse Act (CMA) accordingly, their response can best be described as "too much, too late".

The Police and Justice Bill passed by the House of Commons earlier this month and currently residing in the Lords contains an update to the CMA that lawmakers no doubt formulated in good faith. But vague wording together with a liberal sprinkling of technical ignorance means the amendment as it stands could well criminalise large portions of the IT community.

Section 41 of the bill includes a new offence of "making, supplying or obtaining articles for use in computer misuse offences" but is worded in such a vague way as to effectively make it illegal to make any tool available simply on the grounds that it could be used for hacking. It makes about as much sense as banning knives from kitchens and dinner tables, and going on to ban forges and all knife-producing machinery simply because their end product could be used to commit a crime. Some experts have even suggested that the definition of what is banned could be so broad as to criminalise the act of informing people about security vulnerabilities.

The feeling that IT professionals are being actively hampered by lawmakers, rather than empowered by them, was further exacerbated by the re-emergence of the Regulation of Investigatory Powers (RIP) Act. This, alongside other legislative gems such as the Anti-Terrorism Act, the Data Protection Act and the Human Rights Act, has added to the already hefty compliance burden facing IT professionals. Under the RIP Act, authorities will be able to order the disclosure of encryption keys, or force suspects to decrypt protected data. The problem, which was pointed out when the Act was first introduced, is what happens if you forget your password? Or, if you simply don't own the key for encrypted data that is found on your PC.

At a recent meeting of the IT trade body Intellect to discuss the development of the UK Information Economy, the consensus from the gathered experts was that while the government couldn't be expected to formulate that much policy to actually foster growth, it could do a lot to harm it if not properly informed. The update to the CMA and re-emergence of the RIP Act are brilliant examples of the kind of harm we should all be worried about and why it is incumbent on the IT industry to engage with government or suffer the consequences.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 80 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Cloud Watch Special Report

Five cloud computing myths exploded

Five cloud computing myths exploded

Analysis The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud

More Special Reports

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters