Select Committee on Science and Technology Written Evidence


Memorandum by Professor Ross Anderson

  Colleagues and I supported your report's recommendations and found the Government's response to be deeply disappointing. I would like, however, to add a few points of detail.

  First, during the last quarter of 2007, three colleagues and I wrote a report for the European Network and Information Security Agency entitled "Security Economics and the Internal Market" which I incorporate herein by reference. (It may be accessed from their website or from mine.) This report was based on intensive study of the available statistics relating to online crime and security, coupled with extensive consultation with stakeholders to determine what policy options were helpful and practical. It also built on your committee's work.

  We came up with 15 recommendations for action by the European Commission, and these push very much in the same direction as your committee's findings. I would like to suggest that committee members read at least the first six pages of our report, which summarises our work. Among other things, we recommend a comprehensive security-breach disclosure law, the collection of better statistics on online fraud and crime, the better alignment of incentives through liability, and standards for network-connected equipment to be secure by default. There are some differences of detail, because of our study's different scope and audience, but no substantive points of conflict.

  Second, we remain unimpressed by Government efforts on information security, and hope that the complacency expressed in its response of October 2007 has been shaken by the HM Revenue & Customs (HMRC) scandal. The problem is of course many-faceted, involving a wide range of government functions from operations through regulation to enforcement.

  On the research funding side, I note that the National Science Foundation (NSF) is allocating a nine-figure sum to the Global Environment for Network Innovations (GENI) project, whose aim is to develop options for a next-generation Internet that would give security and quality-of-service guarantees; I see nothing comparable from the UK funding agencies.

  On consumer protection, the government is being disingenuous in claiming that the banking industry's practices provide adequate protection. I would like to point you to a submission that Foundation for Information Policy Research (FIPR) colleagues and I made to the Hunt Review of the Financial Ombudsman Service, in which we show the contrary.[1] The banking code also provides scant protection; where a password or PIN has been used, the bank often simply claims that the customer must have been negligent or complicit. Given the large variety of technical means by which passwords and PINs can be harvested without customers being aware, this argument is very shaky—yet the Ombudsman routinely backs the banks against customers who complain, and customers have little effective redress in the courts because of the rules on costs and because of their lack of access to technical information and expertise. Dozens of victims approach me every year out of desperation, because of my research papers on card security; I'd estimate that between 1,000 and 10,000 people each year are denied compensation after being the victims of third-party fraud (what's more, these victims are overwhelmingly poor, female or black. I can't recall a middle-class white man coming to me with a tale of woe).

  It is also noteworthy that the Treasury lobbied alongside the Association for Payment Clearing Services (APACS) and Barclays to get the European Union to restrict consumer protection in last year's Payment Services Directive. The Government has not been a passive observer of this tussle but has actively helped the banking industry to decrease their own liability at their customers' expense. In this context, it is somewhat breathtaking for the Government to say that "Imposing legislation on banks to be held liable for losses incurred as a result of electronic fraud does not seem to be the appropriate approach in ensuring that banks maintain their customer information securely". Such legislation exists in the USA (Regulation E) and has had precisely that effect.

  On the question of kitemarks, we recommended to the European Network and Information Security Agency (ENISA) that their scope should extend to all network-connected equipment. As computing becomes pervasive, large numbers of devices that at present have at most standalone computing capability will be online. Thus, in future, the spammers and phishermen might not be building their botnets out of PCs but rather out of network-attached TVs, air conditioners or even cars. Internet service providers and others who suffer financial losses should clearly be able to recover them from negligent vendors, else the vendors will have insufficient incentive to engineer their products properly. Our proposal was that vendors should have to certify that their products were secure by default—and where this turned out to be untrue, they would be liable for damages. This seems to be a minimal, light-touch way to align incentives.

  Finally, your last recommendation was on guidance to the judicial system about the dangers of relying on unsupported credit and debit card evidence. Last month, a "Newsnight" investigation described the case of Jane Badger who was prosecuted for attempted fraud after complaining of phantom withdrawals from her account with Egg. The prosecution collapsed once the defence obtained expert help and the right questions were asked. It's not just the policy folks who need to catch up with the technology of electronic crime, but police and prosecutors too. So I urge you to keep on pushing for better court guidance and judicial education.

19 March 2008



1   www.fipr.org Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008