Memorandum by the Metropolitan Police
Service (MPS)
INTRODUCTION
The Government does not agree with the implication
that "the public has lost confidence in using the internet".[2]
The Government supports this position quoting substantial year-on-year
growth in usage of the internet. We welcome and acknowledge this
growth but would comment that both anecdotal evidence and survey
evidence indicates growing concern over internet security. Interactive
Retail in Media Group (IMRG) estimate that on-line trade is suppressed
by 20 per cent through fears over internet security. The Demos
survey conducted on behalf of the Post Office in December 2007,
reveals that fear of fraud is the single biggest factor deterring
the over 50 age group from engaging on-line.
The following quote is from a letter to the
Editor of the Metro Newspaper published on 14 March 2008
and is indicative of widespread public opinion. "It is
not surprising that credit card fraud is booming when it is hardly
ever investigated. When someone hacked into my online account
the company treated it like a civil dispute and told me I'd have
to serve a writ on them to obtain the identity of the thief. More
recently, another online account of mine was hacked and money
transferred to a gaming account ... ... ...Shoplifters
who steal trivial sums are processed by the courts on a daily
basis, while, it seems, people who steals thousands of pounds
in online fraud are not even pursued".
Since the publication of the Report and the
Government response to it, the personal data of more than half
the population of the United Kingdom has been compromised by government
departments. As industry conducts a review of its own data handling
and storage processes, more disclosures of compromised data have
been made. It is reasonable to assume that many more identity
compromises have not been disclosed. In less than six months public
trust in the ability of government, and to a lesser extent the
private sector, to protect the identity of the individual has
been completely undermined. When coupled with the existing fears
of internet use by large sections of society, it is no longer
reasonable to assert that the public retains confidence in using
the internet.
The Government "refutes the suggestion
that the public has lost confidence in the internet and that lawlessness
is rife".[3]
We, too, anticipate increased uptake of the internet by the personal
user despite these fears of lawlessness. There exists no empirical
evidence of the extent of criminality enabled by the internet,
either within the UK or beyond. A recent Distributed Denial of
Service (DDOS) investigation undertaken by the MPS, revealed that
of 104 UK companies targeted in the attack, only one company reported
the matter to police.
The MPS has suggested that allegations of internet-enabled
crime be uniformly categorised at the reporting stage, to provide
a true and accurate picture of the extent of this "lawlessness".
The MPS has begun the process in London and e-crime Wales has
a similar initiative across the four Welsh police forces. The
current Her Majesty's Inspectorate of Constabulary (HMIC) inspection
of Forces, includes two questions relating to force response to
e-crime. We hope that this will encourage other Forces to consider
quantifying internet-enabled criminality and, thereby, provide
an accurate overall picture of the problem in the future.
In respect of new legislation the Government
"does not consider that imposing additional burdens on
business is the best way forward".[4]
The MPS does not propose additional legislation in this field.
However a robust enforcement policy, and the resources to undertake
it, must be pursued by the Office of the Information Commissioner.
The MPS is concerned that any Data Breach Notification legislation
will result in additional referrals to police for investigation
along with the responsibility for the crime prevention action
necessary. The Government must consider in full, any impact assessment
undertaken prior to such legislation.
The Government has stated in its response that
it "will consider the proposals to create a law enforcement
unit to tackle crimes involving computers".[5]
This proposal was formally submitted to the Government by the
MPS on behalf of ACPO, in mid-October 2007. The Government raised
a series of questions in relation to the Business Case for such
a unit, which in turn were responded to in mid-December. At the
time of writing we await a formal decision from the Government
upon the proposal.
RECOMMENDATION ONE
The Government proposes the creation of a "small,
high level Government/Industry working group to develop a more
co-ordinated approach to tackling crime committed using computers
as a medium".[6]
To some extent this forum exists in the National E-crime Strategy
Group (NeSG) chaired by SOCA and on which the Home Office is represented.
To promote the co-ordinated approach espoused, a broader representation
is required than suggested. Law-enforcement, academia and civil
society must play a part in the formulation of strategy. Such
a "working group" must not replicate similar fora already
in existence.
The MPS experience is that high-level discussion
groups will not deliver on-the-ground short-term solutions to
the current problems of policing e-crime. These difficulties include
increasing demands, increasing backlogs and decreasing resources.
RECOMMENDATION TWO
The Government does not accept the view that
Section 3A of the Computer Misuse Act 1990 places security researchers
in jeopardy.[7]
The MPS holds the same view. Before a successful prosecution could
be undertaken the CPS would have to take the view that a prosecution
was in the public interest and that mens rea was made out.
This would not succeed in the case of honest research.
RECOMMENDATION FOUR
The government is "actively pursuing
ideas with the Internet Service providers as to how they might
work even more closely with their customers to prevent harm ...
"[8]
The MPS holds the view that Internet Service Providers are uniquely
positioned to play a key part in protecting society from the more
damaging effects of internet abuse. The MPS supports a voluntary
code of co-operation rather than a legislative approach. The MPS
is keen to see results from these discussions with the ISPs and
would welcome the opportunity to participate.
RECOMMENDATION SIX
It is the experience of the MPS that the more
responsible ISPs do actively assist with the closure of websites
and email addresses that abuse the Network. It is also true to
say that some ISPs exercise the "mere conduit" excuse
to avoid any responsibility for content. We do not comment upon
the legality of this position, however those that do decline to
assist pose a particular problem for law-enforcement. Although
Proceeds of Crime legislation and arguably Fraud Act offences
may be identified, law enforcement possesses a particular problem
in terms of volumes and jurisdiction when enforcing co-operation.
The MPS supports a Voluntary Code of conduct for the ISPs before
legislation is contemplated.
RECOMMENDATION NINE
It is understood that the Government's response
to this question was drafted prior to the series of data compromises
that have captured headlines in recent months. Few would now agree
with the statement that "we do not agree that the incidence
of loss of personal data is on an upward path".[9]
The benefit of these recent catastrophic losses may be to force
industry to examine their own protection systems and processes.
There is anecdotal evidence that this process has begun. The MPS
disagrees with the Government view that the current data protection
regime is robust enough to encourage business to take this issue
seriously. Although the MPS would like to see firm enforcement
of current legislation we do not favour the enactment of Data
Breach Notification legislation as this would have considerable,
and to some degree unknown, implications for police charged with
pursuing allegations referred to it, either directly or by the
Information Commissioner's Office.
The MPS does not accept that the Government
"cannot prescribe the technologies or processes that should
be deployed to protect information".[10]
The CESG CAP scheme already prescribes the use of certain products
across government and those wishing to trade with government.
RECOMMENDATION EIGHTEEN
The MPS would support this proposal for criminalizing
the use of a BotNet, however it would be necessary to show that
the computers that formed a BotNet were used without the consent
or knowledge of the owner.
RECOMMENDATION NINETEEN
The MPS does not support this recommendation
for the creation a web-based reporting facility for e-crime. We
concur that the NFRC will provide, to a large extent, such a facility
in respect of allegations of fraud. The proposed Police Central
e-crime Unit would, however, provide a web-based "notification"
facility for e-crime. The MPS (as ACPO lead-force for e-crime)
is engaged with the NFRC to ensure that the respective web-portals,
currently under construction, are complimentary. The "notification",
as opposed to a reporting facility, allows for the timely collation
of actionable intelligence without the administrative burden of
duplicating formal crime reporting.
RECOMMENDATION TWENTY-ONE
The MPS welcomes the Government's commitment
to "ensure that all efforts to combat crimes online are
co-ordinated".[11]
The MPS champions the concept of a co-ordinated police response
to e-crime. Without a co-ordinated police effort the Government
concept of multi-agency co-ordination is unrealistic. The creation
of a centralised police e-crime coordination unit is essential
to respond adequately to 21st Century criminality. This new threat
is not simply "old crimes committed with new tools"
but also comprises hitherto unrecognised risks to society. The
House of Lords report recommends the initial funding of such a
unit "without delay". These new threats do not fall
within traditional "core policing" areas of responsibility
and do not fit with our system of geographical policing delivery.
We urge the Government to recognise this and to accept this recommendation.
RECOMMENDATION TWENTY-TWO
It is the experience of the MPS that the Mutual
Legal Assistance process is too slow to secure "real-time"
and "short-lived" data evidence. The introduction of
a European Evidence Warrant may assist the process but it is anticipated
that the current practise of relying on the Interpol and G8 contact
arrangement will continue. As almost all internet investigations
require liaison with law enforcement partners abroad, the MPS
supports this recommendation for a comprehensive review of the
process.
2 Page One-paragraph 3. Back
3
Page One-paragraph 4. Back
4
Page One-paragraph 5. Back
5
Page One-paragraph 6. Back
6
Page Two-paragraph 3. Back
7
Page Four-paragraph 3. Back
8
Page Four-paragraph 3. Back
9
Page Six-paragraph 4. Back
10
Page Six-paragraph 4. Back
11
Page 11-paragraph 4. Back
|