Select Committee on Science and Technology Written Evidence


Memorandum by eBay and PayPal

  1.   We recommend that the Government establish a cross-departmental group, bringing in experts from industry and academia, to develop a more co-ordinated approach to data collection in future. This should include a classification scheme for the recording of all forms of e-crime.

  We support this recommendation and welcome the Government's commitment to set up "a small, high-level Government/industry working group to develop a more co-ordinated approach to tackling crime committed using computers as the medium". We would be delighted to be involved in such a working group.

  On the other hand we disagree with the Government's conclusion that there is no need to "devise a classification scheme for the recording of all forms of e-crimes". While we understand the Government's view that prosecution should be based on the offence rather than the tools used to commit that offence, it would be helpful to record, for example, the number of frauds perpetrated by means of spoof emails.

  We believe that the establishment of a framework to collect and classify data on e-crime would be beneficial in defining the scale of the problem, and could provide a helpful tool for companies actively fighting e-crime. Such a framework would also be helpful in shedding light on the real scale of the problem, and the threat it poses to the development of the Internet economy. Furthermore, common data and definitions will help the work of law enforcement and the judiciary.

THE NETWORK

  4.   It is time for Government to develop a more holistic understanding of the distributed responsibility for personal internet security.

  We agree that responsibility for personal Internet security needs to be shared among industry, law enforcement, government and users.

  While we appreciate the efforts led by the Cabinet Office and all other departments involved, we would welcome a coordinated strategy involving all Government departments, agencies and law enforcement.

  6.   We recommend that the "mere conduit" immunity should be removed once ISPs have detected or been notified of the fact that machines on their network are sending out spam or infected code.

  We agree with the Government's position on preserving the "mere conduit" principle for ISPs.

  However, we believe that Internet connectivity providers (generically referred to in the report as ISPs) can, and should, do more to detect bad traffic in a timely fashion, whilst being granted a safe harbour from legal liability, for the time necessary. Furthermore, web hosting providers—particularly those based overseas—could do more to reduce substantially the time taken to respond to spoof site shutdown requests—for example, by providing 24/7 support to deal with reports from recognized intellectual property owners or experts. This would make a huge difference in our ability to combat phishing and could substantially reduce the impact of fraudsters and e-criminals on consumers and companies alike.

USING THE INTERNET: BUSINESSES

  9.   The steps currently being taken by many businesses trading over the internet to protect their customer's personal information are inadequate. The refusal of the financial services sector in particular to accept responsibility for the security of personal information is disturbing, and is compounded by apparent indifference at Government level. Governments and legislators are not in a position to prescribe the security precautions that should be taken; however, they do have responsibility to ensure that the right incentives are in place to persuade businesses to take the necessary steps to act proportionately to protect data.

  We agree that security precautions should not be prescribed by legislation. We believe that a more useful approach would be to focus on defining a common set of standards which data custodians should follow. These standards should be set by relevant industry standard bodies, rather than through primary legislation, to ensure that the standards are updated in a timely fashion as technology and best practice evolve. The Data Security Standards developed by the Payment Card Industry Security Standards Council, which are now being rolled out globally, represent a best practice in this area and could be an example to other sectors.

  11.   We further believe that a data security breach notification law would be among the most important advances that the United Kingdom could make in promoting personal internet security. We recommend that the Government, without waiting for action at European Commission level, accept the principle of such a law and begin consultation on its scope as a matter or urgency.

  We agree with the Government that a data security breach notification law would not necessarily be the best solution. Our experience in the US has shown that these laws are not a cure-all remedy. On the one hand, these laws have been useful in bringing the risks of identity theft to the public attention and in shining a light on those organizations which fail to securely manage their customer data. On the other hand, the standard for which notification is required is often too low which has led users to disregard such warnings. To the extent that legislation is necessary, it should focus on notifying users when there is a reasonable likelihood of actual harm or identity theft that could result in financial loss—for example, it should take into account whether data is personally identifiable; and if so, whether it is encrypted or not.

  14.   We recommend that the Government provide more explicit high-level political support to the Get Safe Online initiative and make every effort to recruit additional private sponsors.

  We look forward to the outcome of the CSIA's "Work with Direct Gov and Business Links in rationalising the approach to providing internet safety information to customers." We believe the Government could do more to make available to "Get Safe Online" its multiple channels of communication to deliver messages of security awareness to internet consumers and small enterprises, and sponsorship opportunities to larger enterprises.

  The "Get Safe Online" message needs to be an integral part of all Internet security conversations at the highest levels of Government and not be limited to an annual speaking commitment.

  We therefore welcome the Committee's support of the "Get Safe Online" initiative and their calls for enhanced support from the Government and Ofcom. As a founding partner of Get Safe Online, eBay has played a key role in getting this initiative off the ground. However, we do not believe it is sustainable in the long run to expect a relatively small number of private sponsors to meet such a large share of the ongoing costs of this programme. We therefore fully support the Committee's recommendations to recruit new sponsors who are capable of funding the next phase of the "Get Safe Online" campaign or providing support in kind.

POLICING THE INTERNET

  19.   We recommend that the Government, in partnership with the Association of Chief Police Officers and the Serious Organised Crime Agency, develop a unified web-based reporting system for ecrime.

  We strongly support the creation of a unified, web-based reporting system for e-crime. We believe this would be beneficial to industry and users while facilitating the work of law enforcement.

  We therefore welcome the Government's commitment to consider this recommendation. We would argue that while there is an overlap between the Fraud Review National Fraud Reporting Centre (NFRC) proposal and the proposed ACPO national e-crime unit to tackle e-crimes, the two will serve different purposes. We look forward to concrete and immediate action from the Government to establish a national e-crime unit.

  However, any reporting system should not serve as a black box into which consumer complaints are effectively "dumped", with no clear follow up. Of equal importance to reporting mechanisms is an effective "triage" system which can direct consumers to the most appropriate source of help, whether that is industry, government or law enforcement.

  21.   We therefore recommend the establishment of a network of computer forensic laboratories, under the aegis of the proposed ACPO national e-crime unit, but with significant central funding. We further urge the Home Office, without delay, to provide the necessary funds to kick-start the establishment of the Police Central E-Crime Unit, without waiting for the private sector to come forward with funding.

  We strongly second calls for increased resource allocation to law enforcement. We actively co-operate with law enforcement on a regular basis, assisting them in their investigations and training them on how to work with eBay and PayPal. Despite our many successes, we are confident that even more could be achieved with the right resources and training. We therefore look forward to the establishment of an appropriately resourced national e-crime unit. We would also welcome the development of a SPOC process for e-crime within the Police.



 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008