Feeds

EU cybercrime strategy backs law enforcement Trojan

Remote searches? Nein danke

The Power of One Infographic

Remote searches of suspects' computers could become a mainstay of cybercrime investigations under a new EU strategy announced last week.

The EU Council of Ministers also agreed closer cooperation between law enforcement agencies across Europe, including joint investigation teams. The five-year plan devised by the ministers also includes more information exchange on best practices, criminal trends and the like between law enforcement agencies and the private sector, and more cyber patrols.

The financial impact of cybercrime remains a bit of a mystery, not helped by the lack of well-organised reporting structures in Europe. As a short-term fix the EU has earmarked €300,000 for Europol to establish a clearing house (or perhaps desk, given the small sums involved) for crimes committed on the internet, such as the distribution of images of child abuse.

The EU cites computer viruses, spam, ID theft and child pornography as its main concerns. "Images of sexually abused children available online quadrupled in the last five years and half of all internet crime involves the production, distribution and sale of child pornography," a declaration from the meeting states.

Many of the measures agreed by the Council of Ministers continue with existing policies in areas such as closer European coordinating and cooperation in the fight against cybercrime. The increased use of remote searches stands out as a new, and controversial, direction in policy.

In practical terms, remote searches would involve planting law enforcement Trojans on suspects' PCs. Police in Germany are most enthusiastic about pushing this tactic, the sort of approach even Vic Mackey from The Shield might baulk at, despite its many potential drawbacks, highlighted by El Reg on numerous occasions.

For starters, infecting the PC of a target of an investigation is hit and miss. Malware is not a precision weapon, and that raises the possibility that samples of the malware might fall into the hands of cybercrooks.

Even if a target does get infected there's a good chance any security software they've installed will detect the malware. Any security vendor who agreed to turn a blind eye to state-sanctioned Trojans would risk compromising their reputation, as amply illustrated by the Magic Lantern controversy in the US a few years back.

Then there are the civil liberties implications of the approach and questions about whether evidence obtained using the tactic is admissable in court.

Despite all these problems the idea of a law enforcement Trojan continues to gain traction and could become mainstream within five years, if EU ministers get their way. ®

Boost IT visibility and business value

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
MPs wave through Blighty's 'EMERGENCY' surveillance laws
Only 49 politcos voted against DRIP bill
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.