Feeds

DEC 'hacker' questions McKinnon political bandwagon

Boris didn't big me up - what gives?

SANS - Survey on application security programs

Boris Johnson's outspoken defence of Gary McKinnon in his extradition fight has been criticised by a former security consultant, who complains he was denied such support when he himself was charged with hacking offences.

Daniel Cuthbert was convicted in October 2005 of breaking the Computer Misuse Act by "hacking" into a tsunami appeal website in December 2004, and fined £400 plus £600 in costs. He was subsequently forced to change career after the prosecution, which was widely seen by his peers as misguided. Cuthbert now wants to know why he wasn't shown any support from politicians of the kind lent to McKinnon by Johnson.

The London mayor wrote a barbed critique of attempts by US authorities to drag McKinnon over to the US to answer for charges of hacking into US military systems, rather than be tried in the UK for his admitted offences, in an opinion piece in The Daily Telegraph on Monday. Johnson argues that treating McKinnon as a "cyberterrorist" rather than a hacker with out-there beliefs is itself lunacy.

McKinnon is far from the first Brit to face high-profile computer charges, but the degree of political support he's received - a motion on his behalf was signed by 80 MPs, to say nothing of the lampooning of extradition proceedings by the London mayor - is unprecedented, and a tribute to the long-running campaign fought by McKinnon's lawyers and supporters.

Cuthbert's woes began when he made a donation through the DEC (Disasters Emergency Committee) site. After failing to get a confirmation email, he became suspicious and carried out two tests to check its security. These actions triggered a warning on the intrusion detection system behind the site, maintained by BT, who reported the matter to police. This ultimately led to Cuthbert's arrest, conviction and inability to continue his career as an IT security consultant.

After a spell in Thailand, Cuthbert is back in the UK and studying for an MA in documentary and photojournalism at the London College of Communication. Cuthbert - who has repeatedly spoken out against the extradition proceedings against McKinnon in the past - ruefully notes that he didn't enjoy the benefit of support from political figures, such as the London mayor.

"Whilst it would be lovely if Boris could talk about my conviction, the chance of that happening is slim," Cuthbert told El Reg.

Cuthbert criticised Johnson's argument that McKinnon ought to be given special consideration because of his motives.

"Gary committed a crime, end of story," Cuthbert said. "The issue has always been where he would be tried for that crime. In all honesty, the fact he was searching for UFOs doesn't make what he did right, he did break into computers and the intent was always to break in to find information. What Boris is saying is that he should be given special consideration, and I don't believe in that at all.

"I personally think he should be tried in the UK. The UK is wrong to bow down to the whims of the US, especially since the extradition treaty between the two countries is hardly fair and equal."

Cuthbert's sense of injustice is supported in a response to Johnson's original piece by Ira Winkler, president of the Internet Security Advisors Group and an ex-NSA officer who's become a cybercrime guru. Winkler argues that McKinnon caused real damage, so arguments that he was only rooting around systems looking for evidence of UFOs are neither here nor there. He goes on to say that Johnson would do better to look into cases of injusice closer to home, such as the Cuthbert case.

Why doesn't Johnson turn to the case of Daniel Cuthbert? In that case prosecuted in London, a real security expert and security community volunteer was prosecuted and convicted for what essentially amounted to typing "cd ..". The Cuthbert case demonstrates absurdity of at least one computer crime prosecution in London. Until Johnson speaks out on Cuthbert, he shouldn't have the gall to waste any time on a person who actually caused significant damage to a government system.

We've dropped the Mayor an email asking what position he might have on the Cuthbert case. We've received an automated reply confirming the safe delivery of this message and saying that, while busy, "the Mayor is committed to responding to all appropriate correspondence and everything is being done to reply to your query as quickly as possible". We await further correspondence with interest.

Meanwhile, a former US prosecutor involved at the start of the McKinnon prosecution has defended the US handling of the case. Scott Christie, an assistant US attorney in New Jersey in 2002 at the time McKinnon was first indicted in the case, criticised Johnson's critique as badly misinformed.

"[McKinnon] has created this cause celebre status in order to appeal to folks who will beat the drum on his behalf and they conveniently ignore the facts of the situation and the entire nature of his conduct," Christie said, Computerworld reports. Christie, who heads the IT group at attorneys McCarter & English LLP, added that Johnson's public support "lends some credence to the individuals who are painting McKinnon as a victim" rather than a criminal hacker. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.