Original URL: http://www.theregister.co.uk/2006/01/26/uk_computer_crime_revamp/
The UK Government plans to toughen up computer crime laws under proposals outlined in the Police and Justice Bill on Wednesday. The bill would double the maximum jail sentence for hacking into computer systems from five years to ten years, a provision that will classify hacking as a more serious offense and make it easier to extradite computer crime suspects from overseas. Denial of service attacks, something of a grey area under current regulations, would be clearly classified as a criminal offense under amendments to the 1990 Computer Misuse Act (CMA) proposed in the bill.
Industry pressed for changes along these lines even prior to the 2004 inquiry by MPs that recommended changes to the CMA to modernise UK computer crime law. Other provisions in the bill are likely to prove far more controversial. Clause 35 (http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.27-33.html#j383A) of the bill contains provisions to ban the development, ownership and distribution of so-called "hacker tools".
But the clause fails to draw adequate distinction between tools which might be used for legal as well as unlawful purposes. Reg readers have been quick to point out that the distinctions between, for example, a password cracker and a password recovery tool, or a utility designed to run DOS attacks and one designed to stress-test a network, are not properly covered in the proposed legislation. Taken as read, the law might even even make use of data recovery software to bypass file access permissions and gain access to deleted data, potentially illegal.
"As far as I can see, this looks a complete dog's breakfast of a clause as it fails to consider that many so-called 'hacker tools' have perfectly legitimate uses," writes (http://talkpolitics.users20.donhost.co.uk/index.php?title=another_fine_mess) Reg reader Dave Lambert, who runs the Talk Politics blog.
Spy Blog describes the bill as a "pathetic hodge podge" that's being prepared without proper consultation. It describes Home Office attempts to modify the CMA as "ineffectual and pathetic". "This bill extends the powers of the police, mucks around with existing policing structures, creating extra bureaucracy, and contains a portmanteau of ill-thought out miscellaneous measure," Spy Blog rants (http://www.spy.org.uk/spyblog/2006/01/police_and_justice_bill_2006_a.html).
Modifications in computer crime law make up a small, but important, section of the wide-ranging Police and Justice Bill. The bill is largely concerned with attempting to drive up standards across the police service via modifications to existing police structures and empowering communities to take an active role in tackling anti-social behavior.
Police will also get more powers, including the ability to demand passenger and crew data on journeys within the UK. Airlines and ferry companies would have to provide police with advance details of the name, date of birth and nationality of passengers in advance, The Guardian reports, adding that the measures could lead to delays at ports.
The Police and Justice Bill can be found here (http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.i-iv.html). ®
MS supplies cops with DIY forensics tool (30 April 2008)
http://www.theregister.co.uk/2008/04/30/ms_forensics_usb/
UK.gov delay means hacking laws are so last century (3 April 2008)
http://www.theregister.co.uk/2008/04/03/cma_update_confusion/
UK gov sets rules for hacker tool ban (2 January 2008)
http://www.theregister.co.uk/2008/01/02/hacker_toll_ban_guidance/
Germany enacts 'anti-hacker' law (13 August 2007)
http://www.theregister.co.uk/2007/08/13/german_anti-hacker_law/
Web designer-turned-hacker avoids jail (10 August 2007)
http://www.theregister.co.uk/2007/08/10/motorcycle_website_hack_sentencing/
Germany declares hacking tools 'verboten' (30 May 2007)
http://www.theregister.co.uk/2007/05/30/garmany_anti-hacking_law/
Dating site hacker avoids jail (8 November 2006)
http://www.theregister.co.uk/2006/11/08/dating_site_hacker_sentenced/
Germany proposes hacker law update (22 September 2006)
http://www.theregister.co.uk/2006/09/22/german_hacking_law_update/
Dating site hack suspect charged (25 May 2006)
http://www.theregister.co.uk/2006/05/25/hacking_charges/
Teen accused of 'email bombing' faces retrial (12 May 2006)
http://www.theregister.co.uk/2006/05/12/email_bomber_retrial/
Teen escapes email bombing charge (3 November 2005)
http://www.theregister.co.uk/2005/11/03/email_bomb_case_dismissed/
Hackers plot to create massive botnet (3 June 2005)
http://www.theregister.co.uk/2005/06/03/malware_blitz/
Enforcement is key to fighting cybercrime (2 July 2004)
http://www.theregister.co.uk/2004/07/02/cma_reform_analysis/
MPs demand big stick for hackers (30 June 2004)
http://www.theregister.co.uk/2004/06/30/apig_cybercrime_report/
© Copyright 2008