Memorandum by Professor Ross Anderson
Colleagues and I supported your report's recommendations
and found the Government's response to be deeply disappointing.
I would like, however, to add a few points of detail.
First, during the last quarter of 2007, three
colleagues and I wrote a report for the European Network and Information
Security Agency entitled "Security Economics and the Internal
Market" which I incorporate herein by reference. (It may
be accessed from their website or from mine.) This report was
based on intensive study of the available statistics relating
to online crime and security, coupled with extensive consultation
with stakeholders to determine what policy options were helpful
and practical. It also built on your committee's work.
We came up with 15 recommendations for action
by the European Commission, and these push very much in the same
direction as your committee's findings. I would like to suggest
that committee members read at least the first six pages of our
report, which summarises our work. Among other things, we recommend
a comprehensive security-breach disclosure law, the collection
of better statistics on online fraud and crime, the better alignment
of incentives through liability, and standards for network-connected
equipment to be secure by default. There are some differences
of detail, because of our study's different scope and audience,
but no substantive points of conflict.
Second, we remain unimpressed by Government
efforts on information security, and hope that the complacency
expressed in its response of October 2007 has been shaken by the
HM Revenue & Customs (HMRC) scandal. The problem is of course
many-faceted, involving a wide range of government functions from
operations through regulation to enforcement.
On the research funding side, I note that the
National Science Foundation (NSF) is allocating a nine-figure
sum to the Global Environment for Network Innovations (GENI) project,
whose aim is to develop options for a next-generation Internet
that would give security and quality-of-service guarantees; I
see nothing comparable from the UK funding agencies.
On consumer protection, the government is being
disingenuous in claiming that the banking industry's practices
provide adequate protection. I would like to point you to a submission
that Foundation for Information Policy Research (FIPR) colleagues
and I made to the Hunt Review of the Financial Ombudsman Service,
in which we show the contrary.[1]
The banking code also provides scant protection; where a password
or PIN has been used, the bank often simply claims that the customer
must have been negligent or complicit. Given the large variety
of technical means by which passwords and PINs can be harvested
without customers being aware, this argument is very shakyyet
the Ombudsman routinely backs the banks against customers who
complain, and customers have little effective redress in the courts
because of the rules on costs and because of their lack of access
to technical information and expertise. Dozens of victims approach
me every year out of desperation, because of my research papers
on card security; I'd estimate that between 1,000 and 10,000 people
each year are denied compensation after being the victims of third-party
fraud (what's more, these victims are overwhelmingly poor, female
or black. I can't recall a middle-class white man coming to me
with a tale of woe).
It is also noteworthy that the Treasury lobbied
alongside the Association for Payment Clearing Services (APACS)
and Barclays to get the European Union to restrict consumer protection
in last year's Payment Services Directive. The Government has
not been a passive observer of this tussle but has actively helped
the banking industry to decrease their own liability at their
customers' expense. In this context, it is somewhat breathtaking
for the Government to say that "Imposing legislation on
banks to be held liable for losses incurred as a result of electronic
fraud does not seem to be the appropriate approach in ensuring
that banks maintain their customer information securely".
Such legislation exists in the USA (Regulation E) and has had
precisely that effect.
On the question of kitemarks, we recommended
to the European Network and Information Security Agency (ENISA)
that their scope should extend to all network-connected equipment.
As computing becomes pervasive, large numbers of devices that
at present have at most standalone computing capability will be
online. Thus, in future, the spammers and phishermen might not
be building their botnets out of PCs but rather out of network-attached
TVs, air conditioners or even cars. Internet service providers
and others who suffer financial losses should clearly be able
to recover them from negligent vendors, else the vendors will
have insufficient incentive to engineer their products properly.
Our proposal was that vendors should have to certify that their
products were secure by defaultand where this turned out
to be untrue, they would be liable for damages. This seems to
be a minimal, light-touch way to align incentives.
Finally, your last recommendation was on guidance
to the judicial system about the dangers of relying on unsupported
credit and debit card evidence. Last month, a "Newsnight"
investigation described the case of Jane Badger who was prosecuted
for attempted fraud after complaining of phantom withdrawals from
her account with Egg. The prosecution collapsed once the defence
obtained expert help and the right questions were asked. It's
not just the policy folks who need to catch up with the technology
of electronic crime, but police and prosecutors too. So I urge
you to keep on pushing for better court guidance and judicial
education.
19 March 2008
1 www.fipr.org Back
|