Feeds

UK cybercrime overhaul finally comes into effect

DDoS doubly illegal from 1 October

SANS - Survey on application security programs

Updates to the ageing Computer Misuse Act (CMA) finally come into force in England and Wales on Wednesday (1 October).

Modifications to the CMA - which was enacted in 1990 before the advent of the interweb - were included in the Police and Justice Act 2006. These changes were then themselves amended by the Serious Crime Act 2007. In order to avoid confusion the government decided to apply these changes all at once, through a (delayed) legislative order that comes into effect on 1 October.

Scotland has devolved authority in areas such as computer crime law, so measures such as the clear criminalisation of denial of service attacks entered the statue books north of the border a year ago in October 2007.

The amendments cover three main provisions. Though there was widespread agreement that the UK's existing computing law was outdated, each of the changes has attracted criticism to a greater or lesser degree.

First up, the maximum penalty for unauthorised access to a computer system (the least serious of three hacking offences covered in the original act) has been raised from six months to two years in prison, making the offence serious enough that an extradition request can be filed.

Denial of service attacks, previously something of a legal grey area, are now clearly criminal, with a maximum penalty of up to ten years behind bars. Requests to introduce changes along these lines were made repeatedly by industry representatives during parliamentary hearings on UK computer crime laws, but are nonetheless controversial in some circles.

Spyblog describes the changes as "ill-defined" and duplicated in the Identity Cards Act 2006 as far as attacks on the planned National Identity Register centralised database are concerned. The site suggests that industrial action by computer consultants and the like working on the database would become a criminal offence.

Thirdly the amended act makes it an offence to distribute hacking tools for criminal purposes. Politicians initially suggested an outright ban on so-called hacking tools, which would have made possession of dual-use software package such as Nmap a criminal offence. The technically illiterate measure would have turned white hat penetration testers into cybercrooks. Following industry lobbying the measures were modified but still include provisions that criminalise the distribution or creation of "hacking tools" where criminal intent can be established, modifications that have failed to satisfy security experts.

Spyblog's withering critique of the changes is well worth a read and can be found here. Security researcher Clive Feather has published colour-coded excerpts of the Computer Misuse Act highlighting the amendments here. ®

Bootnote

UK cybercrime laws derive from those covering the tort of trespass whereas equivalent US law laws are based on older legislation covering fraud, hence the need in US law to prove that victims of cybercrime suffered damages.

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.