ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

EU pact criminalising security research? Pt II

Bob Sullivan, MSNBC ZDNet.co.uk

Published: 26 Oct 2000 09:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Hacking software poses special challenges because most of the tools have two equal uses, Granick said. For example, a popular hacking tool called nMap connects to a remote computer and tells the user if that computer has any open ports that can be used to establish a connection. Finding such a port is often the first step in a computer attack, making nMap popular among attackers. But the program is equally popular with network administrators who want to check their own systems for open ports.

The Council of Europe has promised to provide a list of exceptions to the treaty, and professional network administrators will likely end up exempt. But hackers at the Amsterdam conference were still worried about the plight of the thousands of hobbyists who currently research vulnerabilities in their spare time and in good faith. And software writers -- such as the author of nMap -- would likely be offered no legal protection.

The wide-ranging draft treaty also includes extradition agreements and other controversial elements, such as requirements for Internet service providers and network administrators to help police by maintaining detailed logs of all network activity.

European police agencies say they desperately need some kind of help to stem a tidal wave of this new, borderless cybercrime. Stuart Hyde, chief superintendent of police in West Yorkshire, England and a British cybercrime expert, told the hackers that European nations need new laws to deal with complicated issues like jurisdiction and evidence transportation.

"In part because of the ingenuity of lawyers and the ingenuity of [computer criminals] to get around the laws we've got, the laws we've got aren't sufficient," Hyde said. "The draft convention... will make it much easier for people to investigate. It will have an immense impact."

Not every hacker found the law offensive. One system administrator compared the discussion to the gun control debate familiar to US residents.

"It's like arms control," said a German-based hacker, who requested anonymity. "Saying you can't walk around with a loaded gun produces safety. You can compare an exploit to a fully loaded weapon. Making exploits illegal could decrease the number of hacked boxes."

But others openly questioned the existence of a massive cybercrime outbreak requiring bold legislation.

"Cybercrime just doesn't pay," said one hacker who requested anonymity.

"Other forms of criminal activity are much more lucrative. And if you are a hacker, you are smart enough to know that any crime which would pay you'd have to deal with people who could hurt you. All the hackers who could do this have good paying jobs they wouldn't want to lose."

Instead, another hacker suggested, the "cybercrime outbreak" is nothing more than noisy teenagers committing high-profile, low-impact Web site hacks. But those crimes are being used as rationale by governments and law enforcement agencies to pass highly restrictive laws.

"There is a certain hysteria about cybercrime," the hacker said. "But I don't think anyone has stolen money from a bank using the Internet yet."

Granick fears the Council of Europe, in an effort to create consensus, has rushed forward and created a legal document "with far-reaching ramifications, but without far-reaching insight".

Go back to Pt I/ Criminalising security research?

Take me to Hackers

To have your say online click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 78 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

ITIL Systems Administrator

You will be based at Police Headquarters in Chelmsford, but may be required on occasions to travel Countywide for which you must have access to a ...

Internet Operations Analysts

In this growing area, youll have every opportunity to use your technical skills at the sharp end of our operations supporting intelligence and ...

Assistant Head of IT (Service, Design and Transition)

Essex Police Assistant Head of IT (Service, Design and Transition) 46,647 - 52,776 p.a. Essex Police is committed to providing the highest standard ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment