Select Committee on Science and Technology Written Evidence


Memorandum by the Metropolitan Police Service (MPS)

INTRODUCTION

  The Government does not agree with the implication that "the public has lost confidence in using the internet".[2] The Government supports this position quoting substantial year-on-year growth in usage of the internet. We welcome and acknowledge this growth but would comment that both anecdotal evidence and survey evidence indicates growing concern over internet security. Interactive Retail in Media Group (IMRG) estimate that on-line trade is suppressed by 20 per cent through fears over internet security. The Demos survey conducted on behalf of the Post Office in December 2007, reveals that fear of fraud is the single biggest factor deterring the over 50 age group from engaging on-line.

  The following quote is from a letter to the Editor of the Metro Newspaper published on 14 March 2008 and is indicative of widespread public opinion. "It is not surprising that credit card fraud is booming when it is hardly ever investigated. When someone hacked into my online account the company treated it like a civil dispute and told me I'd have to serve a writ on them to obtain the identity of the thief. More recently, another online account of mine was hacked and money transferred to a gaming account ...  ...  ...Shoplifters who steal trivial sums are processed by the courts on a daily basis, while, it seems, people who steals thousands of pounds in online fraud are not even pursued".

  Since the publication of the Report and the Government response to it, the personal data of more than half the population of the United Kingdom has been compromised by government departments. As industry conducts a review of its own data handling and storage processes, more disclosures of compromised data have been made. It is reasonable to assume that many more identity compromises have not been disclosed. In less than six months public trust in the ability of government, and to a lesser extent the private sector, to protect the identity of the individual has been completely undermined. When coupled with the existing fears of internet use by large sections of society, it is no longer reasonable to assert that the public retains confidence in using the internet.

  The Government "refutes the suggestion that the public has lost confidence in the internet and that lawlessness is rife".[3] We, too, anticipate increased uptake of the internet by the personal user despite these fears of lawlessness. There exists no empirical evidence of the extent of criminality enabled by the internet, either within the UK or beyond. A recent Distributed Denial of Service (DDOS) investigation undertaken by the MPS, revealed that of 104 UK companies targeted in the attack, only one company reported the matter to police.

  The MPS has suggested that allegations of internet-enabled crime be uniformly categorised at the reporting stage, to provide a true and accurate picture of the extent of this "lawlessness". The MPS has begun the process in London and e-crime Wales has a similar initiative across the four Welsh police forces. The current Her Majesty's Inspectorate of Constabulary (HMIC) inspection of Forces, includes two questions relating to force response to e-crime. We hope that this will encourage other Forces to consider quantifying internet-enabled criminality and, thereby, provide an accurate overall picture of the problem in the future.

  In respect of new legislation the Government "does not consider that imposing additional burdens on business is the best way forward".[4] The MPS does not propose additional legislation in this field. However a robust enforcement policy, and the resources to undertake it, must be pursued by the Office of the Information Commissioner. The MPS is concerned that any Data Breach Notification legislation will result in additional referrals to police for investigation along with the responsibility for the crime prevention action necessary. The Government must consider in full, any impact assessment undertaken prior to such legislation.

  The Government has stated in its response that it "will consider the proposals to create a law enforcement unit to tackle crimes involving computers".[5] This proposal was formally submitted to the Government by the MPS on behalf of ACPO, in mid-October 2007. The Government raised a series of questions in relation to the Business Case for such a unit, which in turn were responded to in mid-December. At the time of writing we await a formal decision from the Government upon the proposal.

RECOMMENDATION ONE

  The Government proposes the creation of a "small, high level Government/Industry working group to develop a more co-ordinated approach to tackling crime committed using computers as a medium".[6] To some extent this forum exists in the National E-crime Strategy Group (NeSG) chaired by SOCA and on which the Home Office is represented. To promote the co-ordinated approach espoused, a broader representation is required than suggested. Law-enforcement, academia and civil society must play a part in the formulation of strategy. Such a "working group" must not replicate similar fora already in existence.

  The MPS experience is that high-level discussion groups will not deliver on-the-ground short-term solutions to the current problems of policing e-crime. These difficulties include increasing demands, increasing backlogs and decreasing resources.

RECOMMENDATION TWO

  The Government does not accept the view that Section 3A of the Computer Misuse Act 1990 places security researchers in jeopardy.[7] The MPS holds the same view. Before a successful prosecution could be undertaken the CPS would have to take the view that a prosecution was in the public interest and that mens rea was made out. This would not succeed in the case of honest research.

RECOMMENDATION FOUR

  The government is "actively pursuing ideas with the Internet Service providers as to how they might work even more closely with their customers to prevent harm ... "[8] The MPS holds the view that Internet Service Providers are uniquely positioned to play a key part in protecting society from the more damaging effects of internet abuse. The MPS supports a voluntary code of co-operation rather than a legislative approach. The MPS is keen to see results from these discussions with the ISPs and would welcome the opportunity to participate.

RECOMMENDATION SIX

  It is the experience of the MPS that the more responsible ISPs do actively assist with the closure of websites and email addresses that abuse the Network. It is also true to say that some ISPs exercise the "mere conduit" excuse to avoid any responsibility for content. We do not comment upon the legality of this position, however those that do decline to assist pose a particular problem for law-enforcement. Although Proceeds of Crime legislation and arguably Fraud Act offences may be identified, law enforcement possesses a particular problem in terms of volumes and jurisdiction when enforcing co-operation. The MPS supports a Voluntary Code of conduct for the ISPs before legislation is contemplated.

RECOMMENDATION NINE

  It is understood that the Government's response to this question was drafted prior to the series of data compromises that have captured headlines in recent months. Few would now agree with the statement that "we do not agree that the incidence of loss of personal data is on an upward path".[9] The benefit of these recent catastrophic losses may be to force industry to examine their own protection systems and processes. There is anecdotal evidence that this process has begun. The MPS disagrees with the Government view that the current data protection regime is robust enough to encourage business to take this issue seriously. Although the MPS would like to see firm enforcement of current legislation we do not favour the enactment of Data Breach Notification legislation as this would have considerable, and to some degree unknown, implications for police charged with pursuing allegations referred to it, either directly or by the Information Commissioner's Office.

  The MPS does not accept that the Government "cannot prescribe the technologies or processes that should be deployed to protect information".[10] The CESG CAP scheme already prescribes the use of certain products across government and those wishing to trade with government.

RECOMMENDATION EIGHTEEN

  The MPS would support this proposal for criminalizing the use of a BotNet, however it would be necessary to show that the computers that formed a BotNet were used without the consent or knowledge of the owner.

RECOMMENDATION NINETEEN

  The MPS does not support this recommendation for the creation a web-based reporting facility for e-crime. We concur that the NFRC will provide, to a large extent, such a facility in respect of allegations of fraud. The proposed Police Central e-crime Unit would, however, provide a web-based "notification" facility for e-crime. The MPS (as ACPO lead-force for e-crime) is engaged with the NFRC to ensure that the respective web-portals, currently under construction, are complimentary. The "notification", as opposed to a reporting facility, allows for the timely collation of actionable intelligence without the administrative burden of duplicating formal crime reporting.

RECOMMENDATION TWENTY-ONE

  The MPS welcomes the Government's commitment to "ensure that all efforts to combat crimes online are co-ordinated".[11] The MPS champions the concept of a co-ordinated police response to e-crime. Without a co-ordinated police effort the Government concept of multi-agency co-ordination is unrealistic. The creation of a centralised police e-crime coordination unit is essential to respond adequately to 21st Century criminality. This new threat is not simply "old crimes committed with new tools" but also comprises hitherto unrecognised risks to society. The House of Lords report recommends the initial funding of such a unit "without delay". These new threats do not fall within traditional "core policing" areas of responsibility and do not fit with our system of geographical policing delivery. We urge the Government to recognise this and to accept this recommendation.

RECOMMENDATION TWENTY-TWO

  It is the experience of the MPS that the Mutual Legal Assistance process is too slow to secure "real-time" and "short-lived" data evidence. The introduction of a European Evidence Warrant may assist the process but it is anticipated that the current practise of relying on the Interpol and G8 contact arrangement will continue. As almost all internet investigations require liaison with law enforcement partners abroad, the MPS supports this recommendation for a comprehensive review of the process.



2   Page One-paragraph 3. Back

3   Page One-paragraph 4. Back

4   Page One-paragraph 5. Back

5   Page One-paragraph 6. Back

6   Page Two-paragraph 3. Back

7   Page Four-paragraph 3. Back

8   Page Four-paragraph 3. Back

9   Page Six-paragraph 4. Back

10   Page Six-paragraph 4. Back

11   Page 11-paragraph 4. Back


 
previous page contents next page

House of Lords home page Parliament home page House of Commons home page search page enquiries index

© Parliamentary copyright 2008