Feeds

DEC 'hacker' questions McKinnon political bandwagon

Boris didn't big me up - what gives?

Using blade systems to cut costs and sharpen efficiencies

Boris Johnson's outspoken defence of Gary McKinnon in his extradition fight has been criticised by a former security consultant, who complains he was denied such support when he himself was charged with hacking offences.

Daniel Cuthbert was convicted in October 2005 of breaking the Computer Misuse Act by "hacking" into a tsunami appeal website in December 2004, and fined £400 plus £600 in costs. He was subsequently forced to change career after the prosecution, which was widely seen by his peers as misguided. Cuthbert now wants to know why he wasn't shown any support from politicians of the kind lent to McKinnon by Johnson.

The London mayor wrote a barbed critique of attempts by US authorities to drag McKinnon over to the US to answer for charges of hacking into US military systems, rather than be tried in the UK for his admitted offences, in an opinion piece in The Daily Telegraph on Monday. Johnson argues that treating McKinnon as a "cyberterrorist" rather than a hacker with out-there beliefs is itself lunacy.

McKinnon is far from the first Brit to face high-profile computer charges, but the degree of political support he's received - a motion on his behalf was signed by 80 MPs, to say nothing of the lampooning of extradition proceedings by the London mayor - is unprecedented, and a tribute to the long-running campaign fought by McKinnon's lawyers and supporters.

Cuthbert's woes began when he made a donation through the DEC (Disasters Emergency Committee) site. After failing to get a confirmation email, he became suspicious and carried out two tests to check its security. These actions triggered a warning on the intrusion detection system behind the site, maintained by BT, who reported the matter to police. This ultimately led to Cuthbert's arrest, conviction and inability to continue his career as an IT security consultant.

After a spell in Thailand, Cuthbert is back in the UK and studying for an MA in documentary and photojournalism at the London College of Communication. Cuthbert - who has repeatedly spoken out against the extradition proceedings against McKinnon in the past - ruefully notes that he didn't enjoy the benefit of support from political figures, such as the London mayor.

"Whilst it would be lovely if Boris could talk about my conviction, the chance of that happening is slim," Cuthbert told El Reg.

Cuthbert criticised Johnson's argument that McKinnon ought to be given special consideration because of his motives.

"Gary committed a crime, end of story," Cuthbert said. "The issue has always been where he would be tried for that crime. In all honesty, the fact he was searching for UFOs doesn't make what he did right, he did break into computers and the intent was always to break in to find information. What Boris is saying is that he should be given special consideration, and I don't believe in that at all.

"I personally think he should be tried in the UK. The UK is wrong to bow down to the whims of the US, especially since the extradition treaty between the two countries is hardly fair and equal."

Cuthbert's sense of injustice is supported in a response to Johnson's original piece by Ira Winkler, president of the Internet Security Advisors Group and an ex-NSA officer who's become a cybercrime guru. Winkler argues that McKinnon caused real damage, so arguments that he was only rooting around systems looking for evidence of UFOs are neither here nor there. He goes on to say that Johnson would do better to look into cases of injusice closer to home, such as the Cuthbert case.

Why doesn't Johnson turn to the case of Daniel Cuthbert? In that case prosecuted in London, a real security expert and security community volunteer was prosecuted and convicted for what essentially amounted to typing "cd ..". The Cuthbert case demonstrates absurdity of at least one computer crime prosecution in London. Until Johnson speaks out on Cuthbert, he shouldn't have the gall to waste any time on a person who actually caused significant damage to a government system.

We've dropped the Mayor an email asking what position he might have on the Cuthbert case. We've received an automated reply confirming the safe delivery of this message and saying that, while busy, "the Mayor is committed to responding to all appropriate correspondence and everything is being done to reply to your query as quickly as possible". We await further correspondence with interest.

Meanwhile, a former US prosecutor involved at the start of the McKinnon prosecution has defended the US handling of the case. Scott Christie, an assistant US attorney in New Jersey in 2002 at the time McKinnon was first indicted in the case, criticised Johnson's critique as badly misinformed.

"[McKinnon] has created this cause celebre status in order to appeal to folks who will beat the drum on his behalf and they conveniently ignore the facts of the situation and the entire nature of his conduct," Christie said, Computerworld reports. Christie, who heads the IT group at attorneys McCarter & English LLP, added that Johnson's public support "lends some credence to the individuals who are painting McKinnon as a victim" rather than a criminal hacker. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.