Examination of Witnesses (Questions 40
- 59)
WEDNESDAY 29 NOVEMBER 2006
MR DAVID
HENDON CBE, MR
GEOFF SMITH,
MR TIM
WRIGHT AND
MR STEPHEN
WEBB
Q40 Lord Patel:
Do you think the Police Forces have enough staff with the necessary
skills to carry out a forensic examination of IT crime?
Mr Wright: Police Forces can always use extra
staff for any discipline. As I said earlier, every force has a
forensics unit. They have grown significantly over the last three
or four years. ACPO are currently surveying the capability and
the capacity of those units to see whether they are up to strength.
My guess is that they could easily absorb quite a lot of extra
investment.
Q41 Lord Patel:
Do they have targets for the policing of e-crime?
Mr Webb: No, there are no such targets, and
I think that relates back to the sort of discussion we were having
earlier about defining ecrime. If you do not have any clear agreed
definition, it would be quite hard to do targets. In addition,
we are generally in an environment where the Police Forces and
the police authorities are looking to reduce the number of central
targets we impose as part of releasing bureaucracy and freeing
themselves up to dedicate themselves and dedicate the resources
in the way which seems best for them for national and local priorities.
So there are no targets because, as Tim was saying earlier, generally
we see this as another way of carrying out similar crimes, many
of which are obviously covered by PSA targets for crime reduction.
Mr Wright: That said, we are working with ACPO
and HMIC to develop measures specific to that capability, to go
into every force's baseline inspection. We will know more clearly
in the future.
Q42 Lord Patel:
So the police would investigate any reported e-crimes?
Mr Wright: When people report crime, it is the
job of the police to investigate. What I am saying is that we
are working with HMIC to set inspection measures so that when
HMIC inspect forces they will be able to say, "How big is
your forensics unit? Is it keeping up or is it not keeping up?"
Q43 Lord Patel:
So is the Government putting in extra resources?
Mr Webb: Generally this is an area where what
we have done over recent years is to provide a certain amount
of pump priming funding, but broadly speaking because it is a
crime like any other we would expect it to be covered by the police
grant. There has been a very substantial 45 per cent real increase
in overall funding over recent years, so we would expect it to
be covered by the standard police grant and precept.
Mr Wright: Ministers announced yesterday a seven
per cent[22]
increase from this year to next year in police funding as well.
Lord Patel: Thank you.
Q44 Lord Young of Graffham:
Looking internationally for a moment, what are the main black
spots around the world for e-crime, assuming we can define e-crime
sufficiently? If you do define such areasand I will take
one example only because it is fairly well public, Nigeria and
the things which emanate from therewhat sanctions do we
have, or could we have, or should we have to reduce that, not
just a virus but all the sorts of things which come, virus attacks,
phishing, and everything else?
Mr Wright: There are specific nationalitiesand
I think we often talk about nationalities rather than countries
because people move aroundmore strongly associated with
e-crime than others. The ones which come up a lot are the Chinese,
Brazilian, Russian and the former Eastern Bloc. As you say, we
are identifying Nigeria as well now. Our response has been to
engage with local law enforcement in those countries, either to
run joint operations or to help by providing either assistance
or support in being able to tackle some of these people on their
own patch. On the question about sanctions, we do not have sanctions
we can apply to countries at that kind of level.
Q45 Lord Young of Graffham:
Should we have some form of international agreement in which we
can make some nations look after their own people better, or restrain
them more?
Mr Wright: I think the only big international
agreement in this field is the Council of Europe Cybercrime Convention,
which requires all partiesand they go way beyond Europeto
have robust legislation procedurally, which means extracting data
and being able to extradite people, as well as offences, but that
does not go as far as one country being able to act against another.
I think that would be an enormous step in international law for
us.
Q46 Lord Young of Graffham:
So whatever in effect we can do about e-crime in this country,
since the Internet is global we are not going to do anything powerful.
We do not have the tools to do anything to stop it emanating from
other parts of the world?
Mr Wright: I think it is working, particularly
law enforcement but also with government and industry in other
countries, and we work closely with the agencies in those countries.
I am not sure it is appropriate for the UK to do directly things
in other countries, but what we do is we work with the institutions
available in those countries, mainly law enforcement, often with
governments and with the agencies. I think there are some signs
of success in this, but it is trying to fit national jurisdictions
and frameworks on an international crime problem and that is never
going to be entirely straightforward, and it applies to all crime,
not just to e-crime. Obviously, it is more a factor in e-crime
than it is in most crimes and there is a lot of international
crime. A lot of crime is cross-border, drug trafficking for one.
Q47 Lord Young of Graffham:
Yes, but if you are running drugs you have to deliver them from
one place to another and there are physical ways in which you
can stop this. Here it is almost impossible, is it not?
Mr Webb: It really has brought international
co-operation to a whole new level of importance in a crime area
which previously would have been probably within the jurisdiction
and has now suddenly become international, even with frauds and
crimes which are relatively small in value, and it is one of our
big challenges.
Q48 Lord Young of Graffham:
Are there any recommendations we should be making about looking
at this particular area, because it always does seem to me of
considerable concern because you can get small jurisdictions which
can inflict considerable damage and you have very few sanctions
against them?
Mr Wright: Yes, and I think there is a risk
that the brighter criminals will move some of their criminal operations
to the jurisdiction in which they perceive the risk to be lowest.
In terms of recommendations, I am not sure there is anything beyond
our current approach that we would encourage you to recommend,
but I am not sure it is for us to recommend what you recommend
to us.
Mr Webb: We want to work closely with SOCA and
other law enforcement agencies to get a feel for where the problems
are with international co-operation. Ministerially we have certain
levers, we have international organisations where these matters
can be raised, and we really want to work with our law enforcement
colleagues and get them to identify the problems they are having.
At the moment we have not got a feel for anything specific, but
it is something we are very keenly aware of.
Mr Wright: There is more we can do in terms
of working with industry. Many chunks of this industry are multi-national
anyway and I think there is more we can do in working with industry.
Q49 Lord Young of Graffham:
The problem is, if we are going to rely on the other jurisdictions
to control themselvesI mean, it is alleged in some parts
of the world that the drug interests have taken over the governments
of small nations and you could see organised crime taking over
small jurisdictions and they are finding it very difficult to
deal with this since the Internet gives you total access everywhere?
Mr Hendon: I think one of the problems is that
it can be very much easier to move your source of crime to another
jurisdiction. It is very much quicker to do that than it would
be to set up a new collaboration with that jurisdiction to get
rid of it. So basically we have to solve these things here, I
think.
Lord Young of Graffham: Yes, that is
right.
Q50 Lord Howie of Troon:
You mentioned the Council of Europe. Would you remind me, as I
have clearly forgotten, are pronouncements and recommendations
from the Council of Europe mandatory?
Mr Wright: Yes, I think that is right.
Mr Webb: For those who sign up to the Convention
they commit themselves to implementing them, yes.
Q51 Lord Howie of Troon:
Do they really?
Mr Webb: We may be stretching our Constitutional
knowledge!
Q52 Lord Sutherland of Houndwood:
The question is, do they really commit themselves?
Mr Wright: That is right, and we have not ratified
the Council of Europe Convention on Cyber Crime from 2001 yet.
We are close to having implemented it, but the UK has not ratified
it yet, so we are not in a strong position to comment on other
people.
Q53 Lord Howie of Troon:
I think that really is a virtue!
Mr Webb: What these conventions generally require
you to do is to change the law but what they do not necessarily
tell you is how much effort is then being put into tackling the
problem.
Q54 Baroness Sharp of Guildford:
I take it from what you are saying that if all the main players
in this signed up then safe havens of one sort or another would
appear?
Mr Wright: I think it is always a risk and it
is not just legislation, it is really enforcement.
Q55 Chairman:
It strikes me that the one thing which could be done is to insist
somehow internationally that email addresses, et cetera, were
identified with their physical location. That is not the case
at the moment because if you get an AOL account or anything then
it becomes invisible as to where you come from. Regulations could
be set, I would have thought, on the Internet to insist upon it,
so if you saw it coming from a certain country where you knew
you had no interest whatever, nor expecting anything, then you
could reject it. The thing which personally annoys me is that
you have absolutely no idea where this email is coming from.
Mr Smith: That is true, and I think there have
been discussions over several years in the Internet Engineering
Task Force and elsewhere about the possibility of identifying
the source of email traffic. Those discussions are ongoing. I
think it has been driven largely by the problem of spam, where
I think the solution would be greatly alleviated by having a system
whereby you can identify the origin of the email. There are other
solutions being discussed. I think this is a very relevant point.
It is not something which the UK Government could in any way mandate
by itself, I think it actually needs the industry to come together
to find a common solution. So we are looking at multilateral organisations
like the Internet Engineering Task Force to come up with solutions,
or for large companies to come up with solutions.
Q56 Chairman:
But if this happened we would be advocates for something being
done, would we?
Mr Smith: Absolutely. I think the whole problem
of identity on the Internet, knowing who you are dealing with,
is a key issue not only for preventing e-crime but also promoting
e-government and e-commerce. I think one of the big areas of debate
which is taking off at the moment is identity as the Internet
becomes more ubiquitous, how we are going to identify ourselves
to other individuals, indeed to other machines. I think we are
at the start of the debate.
Mr Hendon: But it also requires that the identity
is real, and so you get into the whole question of how you can
be sure that people are who they say they are and that they are
related to the place or the organisation, or whatever it is, which
is leading you to think they are someone you want to talk to.
So I think it is quite complicated to see how to make it work.
Q57 Chairman:
Let me go on and ask you a question about Europe. What interaction
is there between the UK and the European Network and Information
Security Agency (ENISA) and when will the UK ratify the Council
of Europe Convention on Cybercrime which was signed in 2001?
Mr Smith: Shall I take the ENISA question first?
I cannot really talk for the UK but I can talk for myself. I am
the UK's board member on the European Network and Information
Security Agency, so I have been playing a very active role in
getting the agency off the ground and getting the first two work
programmes completed. The UK also participates at the level of
national liaison officers where the agency has created contact
points with each Member State. I think we have been very fortunate
in having a strong contribution on the Permanent Stakeholder Group,
who are stakeholders who have an interest in the work of the agency.
We have got the largest single number of members and some very
good people are working with the agency to try and give the work
programme focus. So I think the UK has been a key player and I
think in the work that we have seen the agency doing on Computer
Emergency Response Teams (that is a way of dealing with real-time
issues) and risk management, the UK has made a major contribution,
but particularly, I think in this context awareness raising, getting
the message across to all stakeholders about the importance of
taking the right actions. There has been some useful dialogue
at the European level and the UK has made a significant contribution
to that dialogue, drawing on its experience with Get Safe Online
and other consumer campaigns. So I think we are actually one of
the leading Member States contributing to the agency. You have
to remember it is a very small agency, so we have very limited
expectations of it, but I think it can make a useful contribution
in creating networks and disseminating best practice amongst administrations.
Mr Wright: In terms of the Council of Europe
Cybercrime Convention, we cannot ratify until we have implemented
all the provisions, which touch on a number of pieces of legislation,
pretty much the last two of which are the Fraud Act and the changes
to the Computer Misuse Act in the Police and Justice Act, both
of which got Royal Assent this month. Once we implement those
provisions, we should be very close to being able to ratify.
Chairman: Thank you.
Q58 Baroness Sharp of Guildford:
What is your assessment of the current level and impact of email
spam on individual users and the economy as a whole, and what
is the Government doing about this particular problem?
Mr Hendon: Perhaps I can take that question.
It is extremely difficult to assess the current level and impact
of spam. It is clear there is an enormous amount of email traffic
which is spam. I hear figures for big organisations that perhaps
half of the emails which come into their files are spam. When
you try to pin down the impact in numbers, then no one seems to
agree and it is very hard to find any number which is more convincing
than another. I thought it is quite interesting that the EU has
just put out a communication on spam, spyware and malicious software
just last week and in there they say that the impact on the UK
is 1.9 billion in 2005, which sounds like quite a big number,
and when you look to see where they got that information from,
it says "various sources," which I think really makes
the point that actually they are not going to pin it down either.
So I think it is extremely difficult to assess. Obviously spam
which is simply suggesting you might like to buy drugs, Viagra
or something, or to buy shares in some start-up in the US which
no one has ever heard of are not particularly damaging if they
simply get deleted at the point they happen, but if they include
a link to a phishing site and it leads you to lose money, then
of course the impact is very much greater. So it is very hard
to pin it down and I think we simply do not know the answer. It
is clear it is a big problem and something needs to happen, but
it is very unclear exactly the level of the impact. What are we
doing about it? We have actually had quite a sort of leadership
role, I think, internationally from the DTI and one of my officials
in particular over the last few years has been very active in
bringing together international co-operation around spam. The
London Action Plan, so called, is an international grouping of
a number of different countries and organisations within the countries,
all working to a set of agreed rules and procedures. The sorts
of things which were going on there led to work which was done
in the context of the OECD and there is an anti-spam toolkit.
This toolkit, if you look at it, has a whole set of things which
a country needs to do in order to get itself into a better position
in relation to spam. If they follow all the rules in the 100 or
so pages of the toolkit then they will sort the problem out for
themselves. Then most recently at the Internet Governance Forum
in Athens last month the Stop Spam Alliance was formed, which
brought together about six of these international groupings and
I am glad to say that my official was chairing the workshop which
made that happen. So we really feel that although in some ways
it is a small amount of money to pay for one official to do this
part time, nevertheless it shows what you can achieve if you actually
focus it in the right place.
Q59 Baroness Sharp of Guildford:
Yes. Sometimes it is suggested that it is illegal to actually
block spam or for the ISPs to scan customer machines for insecurities.
Is that actually so, and if so are there any plans to change the
law in that area?
Mr Smith: There have been discussions amongst
lawyers in the Internet Service Provider community about that
and I would say it has not been tested in court. Our experience
is that nearly every Internet Service Provider is filtering spam
at the network level, and indeed I think the much reduced impact
of spam on individuals in boxes is as a result of that network
filtering. As I say, it is not tested in court. You can see analogies
with tampering with the mail, but I certainly do not think anyone
believes they are taking a risk in doing this. So they must have
fairly strong legal advice that they are on the right side of
the law.
Mr Webb: If any spammer identified himself and
wanted to take his case, some other people might have something
to say to him in return!
Baroness Sharp of Guildford: Yes. Thank
you very much.
22 6.9 per cent. Back
|