Select Committee on Science and Technology Minutes of Evidence


Examination of Witnesses (Questions 40 - 59)

WEDNESDAY 29 NOVEMBER 2006

MR DAVID HENDON CBE, MR GEOFF SMITH, MR TIM WRIGHT AND MR STEPHEN WEBB

  Q40  Lord Patel: Do you think the Police Forces have enough staff with the necessary skills to carry out a forensic examination of IT crime?

  Mr Wright: Police Forces can always use extra staff for any discipline. As I said earlier, every force has a forensics unit. They have grown significantly over the last three or four years. ACPO are currently surveying the capability and the capacity of those units to see whether they are up to strength. My guess is that they could easily absorb quite a lot of extra investment.

  Q41  Lord Patel: Do they have targets for the policing of e-crime?

  Mr Webb: No, there are no such targets, and I think that relates back to the sort of discussion we were having earlier about defining ecrime. If you do not have any clear agreed definition, it would be quite hard to do targets. In addition, we are generally in an environment where the Police Forces and the police authorities are looking to reduce the number of central targets we impose as part of releasing bureaucracy and freeing themselves up to dedicate themselves and dedicate the resources in the way which seems best for them for national and local priorities. So there are no targets because, as Tim was saying earlier, generally we see this as another way of carrying out similar crimes, many of which are obviously covered by PSA targets for crime reduction.

  Mr Wright: That said, we are working with ACPO and HMIC to develop measures specific to that capability, to go into every force's baseline inspection. We will know more clearly in the future.

  Q42  Lord Patel: So the police would investigate any reported e-crimes?

  Mr Wright: When people report crime, it is the job of the police to investigate. What I am saying is that we are working with HMIC to set inspection measures so that when HMIC inspect forces they will be able to say, "How big is your forensics unit? Is it keeping up or is it not keeping up?"

  Q43  Lord Patel: So is the Government putting in extra resources?

  Mr Webb: Generally this is an area where what we have done over recent years is to provide a certain amount of pump priming funding, but broadly speaking because it is a crime like any other we would expect it to be covered by the police grant. There has been a very substantial 45 per cent real increase in overall funding over recent years, so we would expect it to be covered by the standard police grant and precept.

  Mr Wright: Ministers announced yesterday a seven per cent[22] increase from this year to next year in police funding as well.

  Lord Patel: Thank you.

  Q44  Lord Young of Graffham: Looking internationally for a moment, what are the main black spots around the world for e-crime, assuming we can define e-crime sufficiently? If you do define such areas—and I will take one example only because it is fairly well public, Nigeria and the things which emanate from there—what sanctions do we have, or could we have, or should we have to reduce that, not just a virus but all the sorts of things which come, virus attacks, phishing, and everything else?

  Mr Wright: There are specific nationalities—and I think we often talk about nationalities rather than countries because people move around—more strongly associated with e-crime than others. The ones which come up a lot are the Chinese, Brazilian, Russian and the former Eastern Bloc. As you say, we are identifying Nigeria as well now. Our response has been to engage with local law enforcement in those countries, either to run joint operations or to help by providing either assistance or support in being able to tackle some of these people on their own patch. On the question about sanctions, we do not have sanctions we can apply to countries at that kind of level.

  Q45  Lord Young of Graffham: Should we have some form of international agreement in which we can make some nations look after their own people better, or restrain them more?

  Mr Wright: I think the only big international agreement in this field is the Council of Europe Cybercrime Convention, which requires all parties—and they go way beyond Europe—to have robust legislation procedurally, which means extracting data and being able to extradite people, as well as offences, but that does not go as far as one country being able to act against another. I think that would be an enormous step in international law for us.

  Q46  Lord Young of Graffham: So whatever in effect we can do about e-crime in this country, since the Internet is global we are not going to do anything powerful. We do not have the tools to do anything to stop it emanating from other parts of the world?

  Mr Wright: I think it is working, particularly law enforcement but also with government and industry in other countries, and we work closely with the agencies in those countries. I am not sure it is appropriate for the UK to do directly things in other countries, but what we do is we work with the institutions available in those countries, mainly law enforcement, often with governments and with the agencies. I think there are some signs of success in this, but it is trying to fit national jurisdictions and frameworks on an international crime problem and that is never going to be entirely straightforward, and it applies to all crime, not just to e-crime. Obviously, it is more a factor in e-crime than it is in most crimes and there is a lot of international crime. A lot of crime is cross-border, drug trafficking for one.

  Q47  Lord Young of Graffham: Yes, but if you are running drugs you have to deliver them from one place to another and there are physical ways in which you can stop this. Here it is almost impossible, is it not?

  Mr Webb: It really has brought international co-operation to a whole new level of importance in a crime area which previously would have been probably within the jurisdiction and has now suddenly become international, even with frauds and crimes which are relatively small in value, and it is one of our big challenges.

  Q48  Lord Young of Graffham: Are there any recommendations we should be making about looking at this particular area, because it always does seem to me of considerable concern because you can get small jurisdictions which can inflict considerable damage and you have very few sanctions against them?

  Mr Wright: Yes, and I think there is a risk that the brighter criminals will move some of their criminal operations to the jurisdiction in which they perceive the risk to be lowest. In terms of recommendations, I am not sure there is anything beyond our current approach that we would encourage you to recommend, but I am not sure it is for us to recommend what you recommend to us.

  Mr Webb: We want to work closely with SOCA and other law enforcement agencies to get a feel for where the problems are with international co-operation. Ministerially we have certain levers, we have international organisations where these matters can be raised, and we really want to work with our law enforcement colleagues and get them to identify the problems they are having. At the moment we have not got a feel for anything specific, but it is something we are very keenly aware of.

  Mr Wright: There is more we can do in terms of working with industry. Many chunks of this industry are multi-national anyway and I think there is more we can do in working with industry.

  Q49  Lord Young of Graffham: The problem is, if we are going to rely on the other jurisdictions to control themselves—I mean, it is alleged in some parts of the world that the drug interests have taken over the governments of small nations and you could see organised crime taking over small jurisdictions and they are finding it very difficult to deal with this since the Internet gives you total access everywhere?

  Mr Hendon: I think one of the problems is that it can be very much easier to move your source of crime to another jurisdiction. It is very much quicker to do that than it would be to set up a new collaboration with that jurisdiction to get rid of it. So basically we have to solve these things here, I think.

  Lord Young of Graffham: Yes, that is right.

  Q50  Lord Howie of Troon: You mentioned the Council of Europe. Would you remind me, as I have clearly forgotten, are pronouncements and recommendations from the Council of Europe mandatory?

  Mr Wright: Yes, I think that is right.

  Mr Webb: For those who sign up to the Convention they commit themselves to implementing them, yes.

  Q51  Lord Howie of Troon: Do they really?

  Mr Webb: We may be stretching our Constitutional knowledge!

  Q52  Lord Sutherland of Houndwood: The question is, do they really commit themselves?

  Mr Wright: That is right, and we have not ratified the Council of Europe Convention on Cyber Crime from 2001 yet. We are close to having implemented it, but the UK has not ratified it yet, so we are not in a strong position to comment on other people.

  Q53  Lord Howie of Troon: I think that really is a virtue!

  Mr Webb: What these conventions generally require you to do is to change the law but what they do not necessarily tell you is how much effort is then being put into tackling the problem.

  Q54  Baroness Sharp of Guildford: I take it from what you are saying that if all the main players in this signed up then safe havens of one sort or another would appear?

  Mr Wright: I think it is always a risk and it is not just legislation, it is really enforcement.

  Q55  Chairman: It strikes me that the one thing which could be done is to insist somehow internationally that email addresses, et cetera, were identified with their physical location. That is not the case at the moment because if you get an AOL account or anything then it becomes invisible as to where you come from. Regulations could be set, I would have thought, on the Internet to insist upon it, so if you saw it coming from a certain country where you knew you had no interest whatever, nor expecting anything, then you could reject it. The thing which personally annoys me is that you have absolutely no idea where this email is coming from.

  Mr Smith: That is true, and I think there have been discussions over several years in the Internet Engineering Task Force and elsewhere about the possibility of identifying the source of email traffic. Those discussions are ongoing. I think it has been driven largely by the problem of spam, where I think the solution would be greatly alleviated by having a system whereby you can identify the origin of the email. There are other solutions being discussed. I think this is a very relevant point. It is not something which the UK Government could in any way mandate by itself, I think it actually needs the industry to come together to find a common solution. So we are looking at multilateral organisations like the Internet Engineering Task Force to come up with solutions, or for large companies to come up with solutions.

  Q56  Chairman: But if this happened we would be advocates for something being done, would we?

  Mr Smith: Absolutely. I think the whole problem of identity on the Internet, knowing who you are dealing with, is a key issue not only for preventing e-crime but also promoting e-government and e-commerce. I think one of the big areas of debate which is taking off at the moment is identity as the Internet becomes more ubiquitous, how we are going to identify ourselves to other individuals, indeed to other machines. I think we are at the start of the debate.

  Mr Hendon: But it also requires that the identity is real, and so you get into the whole question of how you can be sure that people are who they say they are and that they are related to the place or the organisation, or whatever it is, which is leading you to think they are someone you want to talk to. So I think it is quite complicated to see how to make it work.

  Q57  Chairman: Let me go on and ask you a question about Europe. What interaction is there between the UK and the European Network and Information Security Agency (ENISA) and when will the UK ratify the Council of Europe Convention on Cybercrime which was signed in 2001?

  Mr Smith: Shall I take the ENISA question first? I cannot really talk for the UK but I can talk for myself. I am the UK's board member on the European Network and Information Security Agency, so I have been playing a very active role in getting the agency off the ground and getting the first two work programmes completed. The UK also participates at the level of national liaison officers where the agency has created contact points with each Member State. I think we have been very fortunate in having a strong contribution on the Permanent Stakeholder Group, who are stakeholders who have an interest in the work of the agency. We have got the largest single number of members and some very good people are working with the agency to try and give the work programme focus. So I think the UK has been a key player and I think in the work that we have seen the agency doing on Computer Emergency Response Teams (that is a way of dealing with real-time issues) and risk management, the UK has made a major contribution, but particularly, I think in this context awareness raising, getting the message across to all stakeholders about the importance of taking the right actions. There has been some useful dialogue at the European level and the UK has made a significant contribution to that dialogue, drawing on its experience with Get Safe Online and other consumer campaigns. So I think we are actually one of the leading Member States contributing to the agency. You have to remember it is a very small agency, so we have very limited expectations of it, but I think it can make a useful contribution in creating networks and disseminating best practice amongst administrations.

  Mr Wright: In terms of the Council of Europe Cybercrime Convention, we cannot ratify until we have implemented all the provisions, which touch on a number of pieces of legislation, pretty much the last two of which are the Fraud Act and the changes to the Computer Misuse Act in the Police and Justice Act, both of which got Royal Assent this month. Once we implement those provisions, we should be very close to being able to ratify.

  Chairman: Thank you.

  Q58  Baroness Sharp of Guildford: What is your assessment of the current level and impact of email spam on individual users and the economy as a whole, and what is the Government doing about this particular problem?

  Mr Hendon: Perhaps I can take that question. It is extremely difficult to assess the current level and impact of spam. It is clear there is an enormous amount of email traffic which is spam. I hear figures for big organisations that perhaps half of the emails which come into their files are spam. When you try to pin down the impact in numbers, then no one seems to agree and it is very hard to find any number which is more convincing than another. I thought it is quite interesting that the EU has just put out a communication on spam, spyware and malicious software just last week and in there they say that the impact on the UK is €1.9 billion in 2005, which sounds like quite a big number, and when you look to see where they got that information from, it says "various sources," which I think really makes the point that actually they are not going to pin it down either. So I think it is extremely difficult to assess. Obviously spam which is simply suggesting you might like to buy drugs, Viagra or something, or to buy shares in some start-up in the US which no one has ever heard of are not particularly damaging if they simply get deleted at the point they happen, but if they include a link to a phishing site and it leads you to lose money, then of course the impact is very much greater. So it is very hard to pin it down and I think we simply do not know the answer. It is clear it is a big problem and something needs to happen, but it is very unclear exactly the level of the impact. What are we doing about it? We have actually had quite a sort of leadership role, I think, internationally from the DTI and one of my officials in particular over the last few years has been very active in bringing together international co-operation around spam. The London Action Plan, so called, is an international grouping of a number of different countries and organisations within the countries, all working to a set of agreed rules and procedures. The sorts of things which were going on there led to work which was done in the context of the OECD and there is an anti-spam toolkit. This toolkit, if you look at it, has a whole set of things which a country needs to do in order to get itself into a better position in relation to spam. If they follow all the rules in the 100 or so pages of the toolkit then they will sort the problem out for themselves. Then most recently at the Internet Governance Forum in Athens last month the Stop Spam Alliance was formed, which brought together about six of these international groupings and I am glad to say that my official was chairing the workshop which made that happen. So we really feel that although in some ways it is a small amount of money to pay for one official to do this part time, nevertheless it shows what you can achieve if you actually focus it in the right place.

  Q59  Baroness Sharp of Guildford: Yes. Sometimes it is suggested that it is illegal to actually block spam or for the ISPs to scan customer machines for insecurities. Is that actually so, and if so are there any plans to change the law in that area?

  Mr Smith: There have been discussions amongst lawyers in the Internet Service Provider community about that and I would say it has not been tested in court. Our experience is that nearly every Internet Service Provider is filtering spam at the network level, and indeed I think the much reduced impact of spam on individuals in boxes is as a result of that network filtering. As I say, it is not tested in court. You can see analogies with tampering with the mail, but I certainly do not think anyone believes they are taking a risk in doing this. So they must have fairly strong legal advice that they are on the right side of the law.

  Mr Webb: If any spammer identified himself and wanted to take his case, some other people might have something to say to him in return!

  Baroness Sharp of Guildford: Yes. Thank you very much.


22   6.9 per cent. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2007