ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Compliance Toolkit

It's time for the Government Misuse Act

Leader ZDNet.co.uk

Published: 22 May 2006 15:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The sooner parliament is dragged kicking and screaming out of the 19th century and into this one, the better for us all – Alan via ZDNet UK Talkback

If the law is an ass, then IT law must be an exceptionally short-sighted donkey. While it is laudable that lawmakers have finally woken up to the threat posed by Distributed Denial of Service (DDoS) attacks and are attempting to amend the Computer Misuse Act (CMA) accordingly, their response can best be described as "too much, too late".

The Police and Justice Bill passed by the House of Commons earlier this month and currently residing in the Lords contains an update to the CMA that lawmakers no doubt formulated in good faith. But vague wording together with a liberal sprinkling of technical ignorance means the amendment as it stands could well criminalise large portions of the IT community.

Section 41 of the bill includes a new offence of "making, supplying or obtaining articles for use in computer misuse offences" but is worded in such a vague way as to effectively make it illegal to make any tool available simply on the grounds that it could be used for hacking. It makes about as much sense as banning knives from kitchens and dinner tables, and going on to ban forges and all knife-producing machinery simply because their end product could be used to commit a crime. Some experts have even suggested that the definition of what is banned could be so broad as to criminalise the act of informing people about security vulnerabilities.

The feeling that IT professionals are being actively hampered by lawmakers, rather than empowered by them, was further exacerbated by the re-emergence of the Regulation of Investigatory Powers (RIP) Act. This, alongside other legislative gems such as the Anti-Terrorism Act, the Data Protection Act and the Human Rights Act, has added to the already hefty compliance burden facing IT professionals. Under the RIP Act, authorities will be able to order the disclosure of encryption keys, or force suspects to decrypt protected data. The problem, which was pointed out when the Act was first introduced, is what happens if you forget your password? Or, if you simply don't own the key for encrypted data that is found on your PC.

At a recent meeting of the IT trade body Intellect to discuss the development of the UK Information Economy, the consensus from the gathered experts was that while the government couldn't be expected to formulate that much policy to actually foster growth, it could do a lot to harm it if not properly informed. The update to the CMA and re-emergence of the RIP Act are brilliant examples of the kind of harm we should all be worried about and why it is incumbent on the IT industry to engage with government or suffer the consequences.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
38 out of 80 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Service Control Manager

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

Security/Quality Analyst-00055189

Ability to secure respect amongst senior IT security/risk management professionals. Quality Act as the primary point of contact to ensure that ...

IT Commercial Manager

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

Loading Video Player ....

Featured Talkback

There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment