Select Committee on Science and Technology Written Evidence


Memorandum by Nicholas Bohm

INTRODUCTION

  1.  I am a member of the Law Society's Electronic Law Committee; these comments are made in my personal capacity.

Recommendation 1—collection and classification of data about e-crime

  2.  The Government dismisses this recommendation on the ground that crimes are recorded according to the offence prosecuted, and not the tools used to commit them. This misses the point. What e-crimes have in common is that they require particular skills to investigate them, and that they lack an ordinary location because, they are often committed in large batches affecting victims in many different places at much the same time. The development by law enforcement bodies of the necessary skills, and the effectiveness of their work, and the priority it is given, are all liable to be affected adversely by the lack of clear information about the incidence of e-crime that results from its dispersal amongst information about other crimes which are legally similar. I find the Government's attitude regrettable.

Recommendation 2—the risk of criminalising the work of security researchers

  3.  The Government rejects the Committee's view that security researchers are at risk of being criminalised because of the recent amendment to the Computer Misuse Act. The provision at issue is one under which:

    A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under [other provisions of the Act].

  For this purpose "article" includes software. The problem is that most software security tools, and especially software itself, are inherently likely to be misused by someone sooner or later because if they are useful for testing security, they are useful for breaking it. The provision would be less alarming if it laid down that a supply or an offer was an offence only if the supplier or offeror believed that the thing supplied or offered was likely to be used by an identifiable recipient or offeree to commit an offence. It does not say that, and it is not clear that it has that meaning. The Government is therefore wrong to deny the existence of the risk created by the amendment.

  4.  The Government nevertheless acknowledges that legitimate security researchers should have confidence that the new offence will be used appropriately, and its response in October 2007 implied that guidance to be issued by the Crown Prosecution Service would provide the basis for that confidence. That guidance has since been issued, and signally fails to fulfill the expectations thus aroused. While it helpfully advises prosecutors that security tools have both lawful and unlawful uses, it lays down tests a prosecutor is advised to apply (in order to decide whether someone who supplies them can be shown to have believed they were likely to be used for misuse). These tests amplify the anxieties of security researchers rather than calm them. Prosecutors are advised to ask themselves the following questions:

    —  Has the article been developed primarily, deliberately, and for the sole purpose of committing a CMA offence (ie unauthorised access to computer material)?

    —  Is the article available on a wide scale commercial basis and sold through legitimate channels?

    —  Is the article widely used for legitimate purposes?

    —  Does it have a substantial installation base?

    —  What was the context in which the article was used to commit the offence compared with its original intended purpose?

  5.  The first of these questions will not of course trouble a legitimate researcher (and if it is answered in the affirmative, the remaining questions are irrelevant). The purpose of the second, third and fourth questions is presumably to help a prosecutor distinguish the usual behaviour of legitimate suppliers of security research tools from the behaviour of others. The questions are therefore clearly based on the author's assumptions of fact, about the usual operation of the world of security research. It is more than a little unfortunate that those assumptions are profoundly ignorant of reality.

  6.  The last 15 years have been marked by the rapidity with which new software is introduced and developed. Attacks on the security of computers and networks have been introduced and have evolved with equal rapidity, and so have defensive and testing tools. Of necessity, the world of computer security research is one in which security tools are developed rapidly by relatively informal collaborative networks of researchers, discussed at conferences or on Internet mailing lists, and published in the ordinary course of academic publishing as well as made available on websites which anyone can access. There are large numbers of such tools, evolving all the time, and available from large numbers of websites visited by large numbers of people. An example is http://nmap.org/, a site which appears to be outside the jurisdiction of the United Kingdom, and claims 40,000 subscribers to its mailing list. In the face of this reality, none of the second, third and fourth of the CPS questions serves the slightest use in distinguishing the legitimate provider of security tools from anyone else. (The final question cannot be answered at the time of supply or offer, since the offence will not yet have been committed, so that it can provide no comfort to a legitimate supplier to know that it will be asked, whatever its use may be to a prosecutor.) The CPS seems to think that security research tools are handled like dangerous pathogens or radioactive isotopes; or perhaps in truth it feels that they ought to be, and that the amended legislation can bring this about. Perhaps an analogy may be considered. Motor vehicles are dangerous things. About 30,000 people are killed or seriously injured in UK road accidents every year. But if it were made an offence to supply a motor vehicle, believing that it was likely to be used to commit a road traffic offence, then there would be a rapid end either to the motor trade or to the government that introduced the legislation.

  7.  The Government's reply regrettably fails to acknowledge the real risk created by the amendment, and the CPS guidance is a disaster. If security researchers are made to feel that they are at risk of prosecution unless they treat security tools like the smallpox virus, we shall all be the more insecure as a result.

Recommendation 6—removal of "mere conduit" immunity where ISP has been notified that it is serving a compromised machine which is sending out spam or infected code

  8.  The Government points out, quite rightly, that such a change cannot properly be made without a change to the Ecommerce Directive. It does not favour such a change, observing, "... we believe that the [ISP] industry can do more to identify and aspire to best practice in this area. We believe that this holds out more prospects for innovative solutions than impractical solutions about changing liability models". While I agree that in this case it is not appropriate to change the liability model, I take the view that what is needed is a regime of penalties for ISPs who fail to isolate compromised machines.

  9.  It is very unusual to make one person liable for the wrongs of another, even when that person is in a position to put an end to continuing wrongs by the other and refrains after notice from doing so. (The vicarious liability of an employer for the acts and neglects of an employee acting in the course of his employment, stands out as a special case. The employer takes the benefit of the employee's work, and must stand the risk; and it is for the benefit of third parties to give the employer an incentive both to manage employees properly and to maintain insurance.) In general, inaction cannot logically be the basis for liability unless there is a duty to act. Duties to act for the benefit of another are normally imposed by the law only where there are close ties between the parties. A parent's duty to nourish a child is an example. In the case in question, the relevant relationship is that between an ISP and the persons liable to suffer economic loss by reason of the ISP's failure to close an account from which spam or infected code are being distributed. This is very far indeed from being the sort of close relationship which would give rise to a duty to act, so that removal of the "mere conduit" exemption would by itself have no effect without a positive change in the law. That is not to say that the case for such a change could not be made, but I do not think it has been made convincingly. This is not a context in which imposing liability on an ISP for inaction would provide a satisfactory incentive. The damage which the ISP's action would be designed to avert, would fall on huge numbers of people in numerous jurisdictions. In most cases the damage would be small in amount, often less than the cost of quantifying it, tracing the person liable, giving notice, waiting for more loss to accrue, tracing that to the same source and then applying for compensation. The UK legal system does not encourage class actions, and the risk of the loser having to pay the winner's costs is discouraging. The pressure applied to ISPs would be capricious and slow.

  10.  In the result I agree with the Government's conclusion, though for a reason very different from the one it gives. The Government's reasoning is indeed a matter for considerable concern, if it implies that in principle exhortation is preferable to the incentive effects of suitable liability models. Perverse incentives arise wherever the creators of security risks do not suffer the consequences that flow from them. Changing the applicable liability model where appropriate, so as to make the polluter pay, is an important part of the strategy necessary to improve the security of the Internet. While agreeing with the Government's conclusion, I would reject its reasoning.

  11.  The Government and the Committee are at one in thinking that the worst ISPs need to behave more like the best in their treatment of rogue machines on their networks. This seems to me a case where the application of a regime of regulatory penalties might be appropriate. The Financial Services Authority has been notably willing to impose substantial penalties on financial institutions for security failures, and if experience does not show these to be dissuasive, there is no reason to doubt the willingness of the FSA to increase them until they are. There seems to be no policy objection to the imposition of such a regime; the Government has announced its willingness to compel ISPs to disconnect the amateur copyright-infringers whose activities so aggrieve the music industry; the isolation by ISPs of machines sending out spam and infected code seems at least as deserving an object of compulsion, and as an endeavour it has the advantage of being both technically feasible and supported by most ISPs, provided that it is aimed precisely at the target I have described, and is not subverted into a scheme for the general regulation of ISPs.

Recommendation 8—exploring the introduction of vendor liability at European level

  12.  I found the Committee's arguments in support of its recommendation convincing. (My own caution when giving evidence to the Committee on this question was due principally to the dangers of producing unintended consequences by legislative intervention in a complex multi-jurisdictional field.) The Government accepts no more than that there is scope for further discussion at the European level, and claims that this is already taking place as part of the ongoing Review of the Consumer Acquis. As one of the expert stakeholders accredited to the European Commission in connection with the review of the consumer acquis (and the related endeavour to prepare a "common frame of reference"), I have observed and participated in discussions on legal issues in this field. I have not noticed any discussion about any change to the liability model applying to vendors in the present context; nor has the topic arisen at any of the helpful meetings between the UK stakeholders and the Ministry of Justice to deal with the progress of the review. No change will occur without active efforts by the Government to promote it, and the Committee is right to press the Government to make those efforts.

Recommendation 9—the need for Government to ensure businesses have adequate incentives to protect customers' personal data

  13.  The Committee's concerns have turned out to be well-founded; and the Government's denials that losses of personal data were increasing, or that it was indifferent to them have been cast into the awkward light of reality by the deluge of reported data losses that began to emerge in such quantity not long after its reply was published. One might hope that the Government would reconsider its response.

Recommendation 10—making banks effectively liable for losses by electronic fraud

  14.  The Government's reply is that no change is necessary, because the Banking Code ensures that the banks reimburse fraudulent losses unless the customer colluded in the fraud or caused it by negligence. This merely repeats the position taken by the banks, and evades the essential point without addressing it at all. That point is that the banks' "proof" that the customer colluded in the fraud or caused it by negligence is a proof by assertion not based on evidence openly produced for testing. In practice the banks assert that their systems have operated without error and show that the customer's card was used with his PIN, and from that they infer that the customer "must have" colluded in the fraud or caused it by negligence, because they say there is no other plausible explanation. They decline to produce the internal system evidence on which they claim to rely, on the ground that it must be withheld to protect the security of other customers. The Financial Ombudsman Service accepts all this without challenge. The few customers who have brought claims in the courts have not had adequate legal and technical support. The courts (normally the County Court) have been unduly impressed by the banks' claims about the need for secrecy, and have had significant difficulty with highly technical evidence. In effect, the banks have deployed systems which have enabled them to decide which customers are innocent victims of fraud and which of them "must have" colluded in the fraud or caused it by negligence. The issues are discussed in some detail at www.fipr.org/080116huntreview.pdf, a submission to Lord Hunt's review of the Financial Ombudsman Service made by Professor Ross Anderson (another witness to the Committee) and me.

  15.  The banks protest that if they cannot rely on their present way of "proving" that a customer must bear a disputed loss, they would have to pay the claims of careless or fraudulent customers. But they are the authors of the systems which have led to this dilemma, and have derived huge financial benefit from using them. If they were forced to meet claims that they could not disprove by open evidence, they could decide whether to stand the losses or to improve security, whichever they preferred. Among the simple improvements would be the deployment of cameras to photograph users of cash machines, and among the more complex would be the development of genuinely trustworthy authentication devices on the basis of the European Committee for Standardization's FINREAD standards published some years ago.

  16.  The Government's evasive dismissal of the recommendation is regrettable. It is to be hoped that when the Treasury undertakes a consultation on the implementation of the Payment Services Directive there may be an opportunity to address these issues again.

Recommendation 11—a data security breach notification law

  17.  The Government's reply, to the effect that laws of this kind were of doubtful value and only brought into force in the United States because of its lack of a European approach to data protection, can now be seen to be smug and overconfident. Indeed, the Government has been forced by events to undertake extensive data breach notification on its own account. I can do no more than express the hope that the same events will bring about a change in the Government's view of the recommendation.

Recommendation 20—need to review reporting of fraud to banks rather than the police

  18.  The Government continues to argue for the desirability of arrangements under which customers report a fraud to their bank, and the police will only treat it as a crime if the bank reimburses the customer and itself reports the fraud to the police. The Government claims that where customers are not refunded they retain the ability to report these matters directly to the police, where crimes should be recorded. I am sceptical of this latter claim, and suspect that where the bank refuses to report a fraud, the police may well refuse to accept the customer's claim that there was one. There ought to be an early check that the system really works as described.

  19.  A system which depends on a decision by a bank on whether or not a customer has been defrauded is flawed by the fact that the bank has a direct financial interest in denying the customer's claim. Moreover, there is not the slightest need for reliance on such a decision. If a customer's account has been charged with a transaction for which the customer denies responsibility, there are only three material possibilities:

    —  the transaction was carried out by a third party in circumstances where the customer is not responsible—the bank has been defrauded by the third party;

    —  the transaction was carried out by a third party relying on carelessness by the customer such that the customer and not the bank is responsible—the customer has been defrauded by the third party (the carelessness does not excuse the fraud); or

    —  the transaction was carried out by the customer or by someone in collusion with him—the customer has attempted to defraud the bank.

  (I leave out of account cases of mistakes by the customer or the bank which are resolved between them.) It follows that all such cases should be reported to the police, whether or not the bank reimburses the customer.

GENERALLY

  20.  Events since the publication of the Government's reply to the Committee's Report, have revealed to the public the existence of serious flaws in the Government's understanding and implementation of data security. Its reply demonstrates that those flaws are characteristic of a much deeper failure by many ministers and officials to adapt to the impact of technological change, or indeed to grasp its implications adequately or at all. Whitehall has become a cloister, sheltering its inhabitants from contact with many painful realities. As a result, much of its response to the Committee's blast of fresh air has been lamentably defensive. I hope that the Committee will not let its sword sleep in its hand.

9 March 2008



 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008