ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

High-tech vigilantes face legal threat

Madeline Bennett ZDNet.co.uk

Published: 08 May 2001 14:41 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies should be wary of carrying our counter attacks against hackers, even despite the fact that they still cannot rely on police for help

Companies cannot rely on the police to protect them from computer crime, but they should be wary of carrying out counter attacks against hackers because this could raise legal problems, say experts.

Speaking at the recent Infosecurity Europe conference, Peter Sommer, a lawyer specialising in Internet law, said the police do not have enough resources to tackle Internet crimes, with little prospect of much improvement in the next few years.

"Firms cannot expect police to routinely solve cybercrime, and businesses must bear the responsibility to protect themselves," said Sommer.

He said problems faced by the police include limited resources, a lack of adequate legislation and a reluctance by firms to spend time and money on collecting evidence.

In the US, firms are increasingly using hacking tools to attack the systems of hackers. Thirty-two percent of Fortune 500 companies have installed counter-offensive software, according to a survey by security consultancy WarRoom Research. Tactics include launching Trojan horse attacks to damage and disable a hacker's computer, and automated scripts that can erase an attacker's hard drive or hijack email.

However, Sommer pointed out that such measures could cause companies to break the law. "There is no clear line between cyber defence and attack," he said. If a company launches a counter-attack after detecting a hacker, it could inflict damage on a third party ­ because hackers often launch attacks via other companies' systems. This raises issues of legal liability for any damage caused, though the law in this area is still unclear.

To improve protection for UK firms, Sommer argued that legislation should be brought up to date, because the Computer Misuse Act 1990, which details laws for the prosecution of computer crime, takes no account of the Internet, and has not yet been updated to cover offences such as denial of service (DOS) attacks.

The extent of the problem faced by companies and the police is illustrated by the fact that the Love Letter virus is estimated to have cost firms $10bn (£7bn) worldwide, while the high-profile teenage hacker Mafia Boy caused $1.7bn (£1.3bn) of damage globally, according to research by security specialist Para-Protect.

Bob Ayers, vice president of Para-Protect Europe, said, "Police can't cope with the volume of cybercrime, prosecution can't match the rate of offences, and penalties are out of proportion with the damage caused, so firms are becoming cyber vigilantes."

The UK's recently launched National Hi-Tech Crime Unit did not attend the conference and said that its members were still in training. Ayers said the unit's decision not to attend was a mistake for a government body that was trying to forge close relationships with UK technology companies.

Take me to ZDNet's Net Crime Special

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
18 out of 73 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SENIOR HR MANAGER INNOVATIVE FORWARD THINKING LAW FIRM

My client, a prestigious International law firm, is seeking a Senior HR Manager to join the team within their London offices. The purpose of this ...

Senior IT Support Specialist/ Law Firm/ W. London/ 45k / MCSE/

Senior IT Support Specialist/ Law Firm/ W. London/ 45k / MCSE/ Windows Server2003/ Active Directory/ Exchange/ TCP/IP/ DNS/DHCP/ LAN/ WAN/ Server/ ...

LAW IT TRAINER ROLE temptoperm / perm LONDON

I am currently looking for an IT trainer with Law experience to design, deliver and give after support for all aspects of IT. You will be responsible ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment