Advertisement
Promo

Security threats Toolkit

Education, not legislation will reduce e-crimes

Munir Kotadia ZDNet.co.uk

Published: 11 Dec 2003 17:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Legislating against electronic crimes such as spam and ID fraud will not reduce the problem; instead, education for small businesses and consumers and cooperation between countries is the answer, according to two major industry groups, who launched a consultation paper on the subject on Thursday.

The paper, published by e-commerce lobby group EURIM, and think tank The Institute for Public Policy Research (IPPR), argues that although some legislation is required to fight Internet-based crimes, alone, it will make no difference unless backed up by corporation between international law enforcement agencies and education for computer users.

Philip Virgo, secretary general of EURIM, said that as long as people are so easily fooled by scammers, no amount of legislation will solve the problem of phishing, where fake emails are sent to online banking users asking them to "confirm" their password and username: "Under no circumstances are you supposed to reveal the whole password -- nobody at the bank will ask for more than a few random letters from it -- and yet people have been giving the complete phrase to the phishers," he said.

This was backed up by Brian White, MP for North East Milton Keynes, who said that legislation on its own can never solve problems. "You also need education, particularly of the users. There are lots of users of computers that are prime targets for open relays because they don't know they have left the gate open," he said.

White said that Internet crimes were quickly becoming a good source of revenue for organised crime gangs that have adopted the new technology to spread fear and generate income. He explained that traditionally, organised crime made money from extortion, by going to a shopkeeper and demanding money in return for protection. This type of crime has now been transferred to the virtual world: "Offering protection from denial of service attacks is making them [organised criminals] money. Organised crime is adapting to the Internet world and it is something we need to be quite serious about," he said.

Virgo added that there is already plenty of legislation to address many of the crimes committed using computers and the Internet: "The fraud scams come under the fraud laws, the vast bulk of pornography can be dealt with under the obscenity laws in the UK, the US and Canada -- and in each of those countries they are extraditable offences," he said.

Richard Starnes, director of incident response and managed security services at Cable and Wireless, argues that in e-crime, technology issues are only a small proportion of the problem. "User education and awareness is absolutely vital. This is definitely not a technology problem -- it is maybe 20 percent a technology issue but it is an 80 percent people issue," he said.

White added that although companies should be responsible in ensuring their technology "keeps ahead of the game," any single measure to tackle the e-crime problem would fail: "It is a combination of all those issues -- any one on its own will not achieve the result."

 

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
79 out of 135 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:














Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters