Memorandum by eBay and PayPal
1. We recommend that the Government
establish a cross-departmental group, bringing in experts from
industry and academia, to develop a more co-ordinated approach
to data collection in future. This should include a classification
scheme for the recording of all forms of e-crime.
We support this recommendation and welcome the
Government's commitment to set up "a small, high-level Government/industry
working group to develop a more co-ordinated approach to tackling
crime committed using computers as the medium". We would
be delighted to be involved in such a working group.
On the other hand we disagree with the Government's
conclusion that there is no need to "devise a classification
scheme for the recording of all forms of e-crimes". While
we understand the Government's view that prosecution should be
based on the offence rather than the tools used to commit that
offence, it would be helpful to record, for example, the number
of frauds perpetrated by means of spoof emails.
We believe that the establishment of a framework
to collect and classify data on e-crime would be beneficial in
defining the scale of the problem, and could provide a helpful
tool for companies actively fighting e-crime. Such a framework
would also be helpful in shedding light on the real scale of the
problem, and the threat it poses to the development of the Internet
economy. Furthermore, common data and definitions will help the
work of law enforcement and the judiciary.
THE NETWORK
4. It is time for Government to develop
a more holistic understanding of the distributed responsibility
for personal internet security.
We agree that responsibility for personal Internet
security needs to be shared among industry, law enforcement, government
and users.
While we appreciate the efforts led by the Cabinet
Office and all other departments involved, we would welcome a
coordinated strategy involving all Government departments, agencies
and law enforcement.
6. We recommend that the "mere
conduit" immunity should be removed once ISPs have detected
or been notified of the fact that machines on their network are
sending out spam or infected code.
We agree with the Government's position on preserving
the "mere conduit" principle for ISPs.
However, we believe that Internet connectivity
providers (generically referred to in the report as ISPs) can,
and should, do more to detect bad traffic in a timely fashion,
whilst being granted a safe harbour from legal liability, for
the time necessary. Furthermore, web hosting providersparticularly
those based overseascould do more to reduce substantially
the time taken to respond to spoof site shutdown requestsfor
example, by providing 24/7 support to deal with reports from recognized
intellectual property owners or experts. This would make a huge
difference in our ability to combat phishing and could substantially
reduce the impact of fraudsters and e-criminals on consumers and
companies alike.
USING THE
INTERNET: BUSINESSES
9. The steps currently being taken by
many businesses trading over the internet to protect their customer's
personal information are inadequate. The refusal of the financial
services sector in particular to accept responsibility for the
security of personal information is disturbing, and is compounded
by apparent indifference at Government level. Governments and
legislators are not in a position to prescribe the security precautions
that should be taken; however, they do have responsibility to
ensure that the right incentives are in place to persuade businesses
to take the necessary steps to act proportionately to protect
data.
We agree that security precautions should not
be prescribed by legislation. We believe that a more useful approach
would be to focus on defining a common set of standards which
data custodians should follow. These standards should be set by
relevant industry standard bodies, rather than through primary
legislation, to ensure that the standards are updated in a timely
fashion as technology and best practice evolve. The Data Security
Standards developed by the Payment Card Industry Security Standards
Council, which are now being rolled out globally, represent a
best practice in this area and could be an example to other sectors.
11. We further believe that a data security
breach notification law would be among the most important advances
that the United Kingdom could make in promoting personal internet
security. We recommend that the Government, without waiting for
action at European Commission level, accept the principle of such
a law and begin consultation on its scope as a matter or urgency.
We agree with the Government that a data security
breach notification law would not necessarily be the best solution.
Our experience in the US has shown that these laws are not a cure-all
remedy. On the one hand, these laws have been useful in bringing
the risks of identity theft to the public attention and in shining
a light on those organizations which fail to securely manage their
customer data. On the other hand, the standard for which notification
is required is often too low which has led users to disregard
such warnings. To the extent that legislation is necessary, it
should focus on notifying users when there is a reasonable likelihood
of actual harm or identity theft that could result in financial
lossfor example, it should take into account whether data
is personally identifiable; and if so, whether it is encrypted
or not.
14. We recommend that the Government
provide more explicit high-level political support to the Get
Safe Online initiative and make every effort to recruit additional
private sponsors.
We look forward to the outcome of the CSIA's
"Work with Direct Gov and Business Links in rationalising
the approach to providing internet safety information to customers."
We believe the Government could do more to make available to "Get
Safe Online" its multiple channels of communication to deliver
messages of security awareness to internet consumers and small
enterprises, and sponsorship opportunities to larger enterprises.
The "Get Safe Online" message needs
to be an integral part of all Internet security conversations
at the highest levels of Government and not be limited to an annual
speaking commitment.
We therefore welcome the Committee's support
of the "Get Safe Online" initiative and their calls
for enhanced support from the Government and Ofcom. As a founding
partner of Get Safe Online, eBay has played a key role in getting
this initiative off the ground. However, we do not believe it
is sustainable in the long run to expect a relatively small number
of private sponsors to meet such a large share of the ongoing
costs of this programme. We therefore fully support the Committee's
recommendations to recruit new sponsors who are capable of funding
the next phase of the "Get Safe Online" campaign or
providing support in kind.
POLICING THE
INTERNET
19. We recommend that the Government,
in partnership with the Association of Chief Police Officers and
the Serious Organised Crime Agency, develop a unified web-based
reporting system for ecrime.
We strongly support the creation of a unified,
web-based reporting system for e-crime. We believe this would
be beneficial to industry and users while facilitating the work
of law enforcement.
We therefore welcome the Government's commitment
to consider this recommendation. We would argue that while there
is an overlap between the Fraud Review National Fraud Reporting
Centre (NFRC) proposal and the proposed ACPO national e-crime
unit to tackle e-crimes, the two will serve different purposes.
We look forward to concrete and immediate action from the Government
to establish a national e-crime unit.
However, any reporting system should not serve
as a black box into which consumer complaints are effectively
"dumped", with no clear follow up. Of equal importance
to reporting mechanisms is an effective "triage" system
which can direct consumers to the most appropriate source of help,
whether that is industry, government or law enforcement.
21. We therefore recommend the establishment
of a network of computer forensic laboratories, under the aegis
of the proposed ACPO national e-crime unit, but with significant
central funding. We further urge the Home Office, without delay,
to provide the necessary funds to kick-start the establishment
of the Police Central E-Crime Unit, without waiting for the private
sector to come forward with funding.
We strongly second calls for increased resource
allocation to law enforcement. We actively co-operate with law
enforcement on a regular basis, assisting them in their investigations
and training them on how to work with eBay and PayPal. Despite
our many successes, we are confident that even more could be achieved
with the right resources and training. We therefore look forward
to the establishment of an appropriately resourced national e-crime
unit. We would also welcome the development of a SPOC process
for e-crime within the Police.
|