Memorandum by Nicholas Bohm
INTRODUCTION
1. I am a member of the Law Society's Electronic
Law Committee; these comments are made in my personal capacity.
Recommendation 1collection and classification
of data about e-crime
2. The Government dismisses this recommendation
on the ground that crimes are recorded according to the offence
prosecuted, and not the tools used to commit them. This misses
the point. What e-crimes have in common is that they require particular
skills to investigate them, and that they lack an ordinary location
because, they are often committed in large batches affecting victims
in many different places at much the same time. The development
by law enforcement bodies of the necessary skills, and the effectiveness
of their work, and the priority it is given, are all liable to
be affected adversely by the lack of clear information about the
incidence of e-crime that results from its dispersal amongst information
about other crimes which are legally similar. I find the Government's
attitude regrettable.
Recommendation 2the risk of criminalising
the work of security researchers
3. The Government rejects the Committee's
view that security researchers are at risk of being criminalised
because of the recent amendment to the Computer Misuse Act. The
provision at issue is one under which:
A person is guilty of an offence if he supplies
or offers to supply any article believing that it is likely to
be used to commit, or to assist in the commission of, an offence
under [other provisions of the Act].
For this purpose "article" includes
software. The problem is that most software security tools, and
especially software itself, are inherently likely to be misused
by someone sooner or later because if they are useful for testing
security, they are useful for breaking it. The provision would
be less alarming if it laid down that a supply or an offer was
an offence only if the supplier or offeror believed that the thing
supplied or offered was likely to be used by an identifiable
recipient or offeree to commit an offence. It does not say
that, and it is not clear that it has that meaning. The Government
is therefore wrong to deny the existence of the risk created by
the amendment.
4. The Government nevertheless acknowledges
that legitimate security researchers should have confidence that
the new offence will be used appropriately, and its response in
October 2007 implied that guidance to be issued by the Crown Prosecution
Service would provide the basis for that confidence. That guidance
has since been issued, and signally fails to fulfill the expectations
thus aroused. While it helpfully advises prosecutors that security
tools have both lawful and unlawful uses, it lays down tests a
prosecutor is advised to apply (in order to decide whether someone
who supplies them can be shown to have believed they were likely
to be used for misuse). These tests amplify the anxieties of security
researchers rather than calm them. Prosecutors are advised to
ask themselves the following questions:
Has the article been developed primarily,
deliberately, and for the sole purpose of committing a CMA offence
(ie unauthorised access to computer material)?
Is the article available on a wide
scale commercial basis and sold through legitimate channels?
Is the article widely used for legitimate
purposes?
Does it have a substantial installation
base?
What was the context in which the
article was used to commit the offence compared with its original
intended purpose?
5. The first of these questions will not
of course trouble a legitimate researcher (and if it is answered
in the affirmative, the remaining questions are irrelevant). The
purpose of the second, third and fourth questions is presumably
to help a prosecutor distinguish the usual behaviour of legitimate
suppliers of security research tools from the behaviour of others.
The questions are therefore clearly based on the author's assumptions
of fact, about the usual operation of the world of security research.
It is more than a little unfortunate that those assumptions are
profoundly ignorant of reality.
6. The last 15 years have been marked by
the rapidity with which new software is introduced and developed.
Attacks on the security of computers and networks have been introduced
and have evolved with equal rapidity, and so have defensive and
testing tools. Of necessity, the world of computer security research
is one in which security tools are developed rapidly by relatively
informal collaborative networks of researchers, discussed at conferences
or on Internet mailing lists, and published in the ordinary course
of academic publishing as well as made available on websites which
anyone can access. There are large numbers of such tools, evolving
all the time, and available from large numbers of websites visited
by large numbers of people. An example is http://nmap.org/, a
site which appears to be outside the jurisdiction of the United
Kingdom, and claims 40,000 subscribers to its mailing list. In
the face of this reality, none of the second, third and fourth
of the CPS questions serves the slightest use in distinguishing
the legitimate provider of security tools from anyone else. (The
final question cannot be answered at the time of supply or offer,
since the offence will not yet have been committed, so that it
can provide no comfort to a legitimate supplier to know that it
will be asked, whatever its use may be to a prosecutor.) The CPS
seems to think that security research tools are handled like dangerous
pathogens or radioactive isotopes; or perhaps in truth it feels
that they ought to be, and that the amended legislation can bring
this about. Perhaps an analogy may be considered. Motor vehicles
are dangerous things. About 30,000 people are killed or seriously
injured in UK road accidents every year. But if it were made an
offence to supply a motor vehicle, believing that it was likely
to be used to commit a road traffic offence, then there would
be a rapid end either to the motor trade or to the government
that introduced the legislation.
7. The Government's reply regrettably fails
to acknowledge the real risk created by the amendment, and the
CPS guidance is a disaster. If security researchers are made to
feel that they are at risk of prosecution unless they treat security
tools like the smallpox virus, we shall all be the more insecure
as a result.
Recommendation 6removal of "mere conduit"
immunity where ISP has been notified that it is serving a compromised
machine which is sending out spam or infected code
8. The Government points out, quite rightly,
that such a change cannot properly be made without a change to
the Ecommerce Directive. It does not favour such a change, observing,
"... we believe that the [ISP] industry can do more to identify
and aspire to best practice in this area. We believe that this
holds out more prospects for innovative solutions than impractical
solutions about changing liability models". While I agree
that in this case it is not appropriate to change the liability
model, I take the view that what is needed is a regime of penalties
for ISPs who fail to isolate compromised machines.
9. It is very unusual to make one person
liable for the wrongs of another, even when that person is in
a position to put an end to continuing wrongs by the other and
refrains after notice from doing so. (The vicarious liability
of an employer for the acts and neglects of an employee acting
in the course of his employment, stands out as a special case.
The employer takes the benefit of the employee's work, and must
stand the risk; and it is for the benefit of third parties to
give the employer an incentive both to manage employees properly
and to maintain insurance.) In general, inaction cannot logically
be the basis for liability unless there is a duty to act. Duties
to act for the benefit of another are normally imposed by the
law only where there are close ties between the parties. A parent's
duty to nourish a child is an example. In the case in question,
the relevant relationship is that between an ISP and the persons
liable to suffer economic loss by reason of the ISP's failure
to close an account from which spam or infected code are being
distributed. This is very far indeed from being the sort of close
relationship which would give rise to a duty to act, so that removal
of the "mere conduit" exemption would by itself have
no effect without a positive change in the law. That is not to
say that the case for such a change could not be made, but I do
not think it has been made convincingly. This is not a context
in which imposing liability on an ISP for inaction would provide
a satisfactory incentive. The damage which the ISP's action would
be designed to avert, would fall on huge numbers of people in
numerous jurisdictions. In most cases the damage would be small
in amount, often less than the cost of quantifying it, tracing
the person liable, giving notice, waiting for more loss to accrue,
tracing that to the same source and then applying for compensation.
The UK legal system does not encourage class actions, and the
risk of the loser having to pay the winner's costs is discouraging.
The pressure applied to ISPs would be capricious and slow.
10. In the result I agree with the Government's
conclusion, though for a reason very different from the one it
gives. The Government's reasoning is indeed a matter for considerable
concern, if it implies that in principle exhortation is preferable
to the incentive effects of suitable liability models. Perverse
incentives arise wherever the creators of security risks do not
suffer the consequences that flow from them. Changing the applicable
liability model where appropriate, so as to make the polluter
pay, is an important part of the strategy necessary to improve
the security of the Internet. While agreeing with the Government's
conclusion, I would reject its reasoning.
11. The Government and the Committee are
at one in thinking that the worst ISPs need to behave more like
the best in their treatment of rogue machines on their networks.
This seems to me a case where the application of a regime of regulatory
penalties might be appropriate. The Financial Services Authority
has been notably willing to impose substantial penalties on financial
institutions for security failures, and if experience does not
show these to be dissuasive, there is no reason to doubt the willingness
of the FSA to increase them until they are. There seems to be
no policy objection to the imposition of such a regime; the Government
has announced its willingness to compel ISPs to disconnect the
amateur copyright-infringers whose activities so aggrieve the
music industry; the isolation by ISPs of machines sending out
spam and infected code seems at least as deserving an object of
compulsion, and as an endeavour it has the advantage of being
both technically feasible and supported by most ISPs, provided
that it is aimed precisely at the target I have described, and
is not subverted into a scheme for the general regulation of ISPs.
Recommendation 8exploring the introduction
of vendor liability at European level
12. I found the Committee's arguments in
support of its recommendation convincing. (My own caution when
giving evidence to the Committee on this question was due principally
to the dangers of producing unintended consequences by legislative
intervention in a complex multi-jurisdictional field.) The Government
accepts no more than that there is scope for further discussion
at the European level, and claims that this is already taking
place as part of the ongoing Review of the Consumer Acquis. As
one of the expert stakeholders accredited to the European Commission
in connection with the review of the consumer acquis (and the
related endeavour to prepare a "common frame of reference"),
I have observed and participated in discussions on legal issues
in this field. I have not noticed any discussion about any change
to the liability model applying to vendors in the present context;
nor has the topic arisen at any of the helpful meetings between
the UK stakeholders and the Ministry of Justice to deal with the
progress of the review. No change will occur without active efforts
by the Government to promote it, and the Committee is right to
press the Government to make those efforts.
Recommendation 9the need for Government
to ensure businesses have adequate incentives to protect customers'
personal data
13. The Committee's concerns have turned
out to be well-founded; and the Government's denials that losses
of personal data were increasing, or that it was indifferent to
them have been cast into the awkward light of reality by the deluge
of reported data losses that began to emerge in such quantity
not long after its reply was published. One might hope that the
Government would reconsider its response.
Recommendation 10making banks effectively
liable for losses by electronic fraud
14. The Government's reply is that no change
is necessary, because the Banking Code ensures that the banks
reimburse fraudulent losses unless the customer colluded in the
fraud or caused it by negligence. This merely repeats the position
taken by the banks, and evades the essential point without addressing
it at all. That point is that the banks' "proof" that
the customer colluded in the fraud or caused it by negligence
is a proof by assertion not based on evidence openly produced
for testing. In practice the banks assert that their systems have
operated without error and show that the customer's card was used
with his PIN, and from that they infer that the customer "must
have" colluded in the fraud or caused it by negligence, because
they say there is no other plausible explanation. They decline
to produce the internal system evidence on which they claim to
rely, on the ground that it must be withheld to protect the security
of other customers. The Financial Ombudsman Service accepts all
this without challenge. The few customers who have brought claims
in the courts have not had adequate legal and technical support.
The courts (normally the County Court) have been unduly impressed
by the banks' claims about the need for secrecy, and have had
significant difficulty with highly technical evidence. In effect,
the banks have deployed systems which have enabled them to decide
which customers are innocent victims of fraud and which of them
"must have" colluded in the fraud or caused it by negligence.
The issues are discussed in some detail at www.fipr.org/080116huntreview.pdf,
a submission to Lord Hunt's review of the Financial Ombudsman
Service made by Professor Ross Anderson (another witness to the
Committee) and me.
15. The banks protest that if they cannot
rely on their present way of "proving" that a customer
must bear a disputed loss, they would have to pay the claims of
careless or fraudulent customers. But they are the authors of
the systems which have led to this dilemma, and have derived huge
financial benefit from using them. If they were forced to meet
claims that they could not disprove by open evidence, they could
decide whether to stand the losses or to improve security, whichever
they preferred. Among the simple improvements would be the deployment
of cameras to photograph users of cash machines, and among the
more complex would be the development of genuinely trustworthy
authentication devices on the basis of the European Committee
for Standardization's FINREAD standards published some years ago.
16. The Government's evasive dismissal of
the recommendation is regrettable. It is to be hoped that when
the Treasury undertakes a consultation on the implementation of
the Payment Services Directive there may be an opportunity to
address these issues again.
Recommendation 11a data security breach
notification law
17. The Government's reply, to the effect
that laws of this kind were of doubtful value and only brought
into force in the United States because of its lack of a European
approach to data protection, can now be seen to be smug and overconfident.
Indeed, the Government has been forced by events to undertake
extensive data breach notification on its own account. I can do
no more than express the hope that the same events will bring
about a change in the Government's view of the recommendation.
Recommendation 20need to review reporting
of fraud to banks rather than the police
18. The Government continues to argue for
the desirability of arrangements under which customers report
a fraud to their bank, and the police will only treat it as a
crime if the bank reimburses the customer and itself reports the
fraud to the police. The Government claims that where customers
are not refunded they retain the ability to report these matters
directly to the police, where crimes should be recorded. I am
sceptical of this latter claim, and suspect that where the bank
refuses to report a fraud, the police may well refuse to accept
the customer's claim that there was one. There ought to be an
early check that the system really works as described.
19. A system which depends on a decision
by a bank on whether or not a customer has been defrauded is flawed
by the fact that the bank has a direct financial interest in denying
the customer's claim. Moreover, there is not the slightest need
for reliance on such a decision. If a customer's account has been
charged with a transaction for which the customer denies responsibility,
there are only three material possibilities:
the transaction was carried out by
a third party in circumstances where the customer is not responsiblethe
bank has been defrauded by the third party;
the transaction was carried out by
a third party relying on carelessness by the customer such that
the customer and not the bank is responsiblethe customer
has been defrauded by the third party (the carelessness does not
excuse the fraud); or
the transaction was carried out by
the customer or by someone in collusion with himthe customer
has attempted to defraud the bank.
(I leave out of account cases of mistakes by
the customer or the bank which are resolved between them.) It
follows that all such cases should be reported to the police,
whether or not the bank reimburses the customer.
GENERALLY
20. Events since the publication of the
Government's reply to the Committee's Report, have revealed to
the public the existence of serious flaws in the Government's
understanding and implementation of data security. Its reply demonstrates
that those flaws are characteristic of a much deeper failure by
many ministers and officials to adapt to the impact of technological
change, or indeed to grasp its implications adequately or at all.
Whitehall has become a cloister, sheltering its inhabitants from
contact with many painful realities. As a result, much of its
response to the Committee's blast of fresh air has been lamentably
defensive. I hope that the Committee will not let its sword sleep
in its hand.
9 March 2008
|