The Register® — Biting the hand that feeds IT

Feeds

Keep your PC clean - or we'll shut you down

UK and US users reject Oz supernanny model

  • print
  • alert

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Analysis When it comes to protecting our personal and financial data online, the Australian solution – of cutting off users who fail to maintain their PC security - may have a lot of appeal.

But in the week when UK consumers are asked to turn their minds to questions of online safety, the real focus may need to be not so much on technological fixes, as on the underlying legal framework – and the lack of trust that most people have for financial institutions.

First up is that Australian solution. From December, ISPs will be encouraged to alert customers when their computers are taken over by hackers. So far, so good. The sting in the tail, however, is a parallel proposal that means ISPs may – or may even be encouraged to – limit access to the net if users fail to take prompt action.

The advantages of such a scheme are obvious: early and strict intervention would go a long way to disrupting botnets, which in turn are a major source for DDOS attacks elsewhere on the net. Since the Australian government has, itself, been the target of such attacks in the last year – most notably in protest over its internet filtering plans – it is clear that many would consider this scheme to be worth pursuing.

Other governments are also expressing an interest in this approach. Yahoo reports that Obama administration officials have been meeting with industry leaders and experts to address the issue of increasing online safety and securing the internet while balancing off individual privacy and civil liberties.

White House cyber-coordinator Howard Schmidt told the Associated Press that the US is looking at a number of voluntary ways to help the public and small businesses better protect themselves online. He told AP: "Without security you have no privacy. And many of us that (sic) care deeply about our privacy look to make sure our systems are secure".

Nonetheless, the Australian model is likely to run into fierce opposition from US critics, who continue to prefer a vision of the internet much closer to the Wild West than the tame shopping mall environment favoured by much US business.

A slightly different take on this issue is likely to emerge in the UK. Consumers want protection. However, in a report (pdf) released in support of the sixth National Identity Fraud Prevention Week, which started yesterday, the somewhat depressing finding for business is that less than 10 per cent of British citizens completely trust how companies handle their sensitive data.

There is also a deep-seated suspicion that "solutions" in this area are more about protecting the backs (and bottom lines) of corporate finance, than looking after consumer interests.

Consumers may have a point. One of the earliest instances of browser hijacking occurred in the years before broadband became widespread. A virus would download on to a user’s machine, log them off – and instantly re-log them to the internet through a premium rate call service.

Although a BT spokesman told us yesterday that BT eventually refunded some customers, the line at the time was one of strong resistance: customers were responsible for what happened on their home equipment – and therefore failure to block such an attack meant they were liable for any additional charges. This led to the ludicrous situation where BT was threatening to take court action against OAPs in the UK for failing to hand over money that was destined to fill the coffers of organised crime elsewhere in the world.

Similar issues arose with unauthorised cash machine withdrawals. According to the Banking Code of Practice, customers are indemnified against unauthorised use of their cards – providing they have not been negligent (by, for instance, writing down their PIN). In theory, it was up to banks to prove negligence: many simply took the view that a breach of their cash machine security was prima facie evidence of negligence – because their security was unbreakable! – and in some instances even prosecuted the victims for fraud.

Have matters improved? The BBC reports today that an increasing number of banks and retailers are obliging or requesting their customers to sign up for online security systems Verified by Visa or Mastercard SecureCode with customers on the grounds these will offer extra protection against fraud.

However, online security experts at Cambridge University criticise these systems on the ground that they encourage individuals to key confidential information into pages that they cannot be sure are genuine - and customers could end up liable for the loss.

Once again, there is evidence of individuals who have been defrauded by this route finding that banks are as likely to treat them as suspects as potential victims.

In the end, cutting off internet users and blaming victims for their plight may be a useful stick with which to beat the population into vigilance. But if ISPs and financial institutions rely only on the stick, they may find themselves running into increasing resistance from consumers who feel that responsibility should be shared – and not downloaded on to them. ®

Agentless Backup is Not a Myth

So you're forcing me to run Windows

just to prove my anti-virus is up-to-date ?

Sorry, mate, I've just spent the first half of my life under a regime telling me what to do, how to behave and even how to address people around me (I was told by law to call them comrade, it was against the law to call them Mr / Mrs.).

8
0

Personally,

I don't do business with companies that treat me as if I were a criminal.

And I vote against any politician who makes the same assumption.

Yeah, I know, I'm probably tilting at windmills again ... The GreatUnwashed[tm] are not only incapable of, but have no interest in maintaining their own personal freedoms. That's why Western politics and Eastern dogma cow their respective populations as easily as they do.

7
0

Canada

We already have this happening in Canada. At least one major ISP that I know of (Cogeco) freezes the connections of compromised accounts on a regular basis. I have seen this in person on several business and consumer accounts of people I know. The company is apparently monitoring traffic enough to recognize spam bots, trojans and DDOS attacks originating from their customers. And so far, they seem to be pretty good at it. Each time I've been called to help out someone who has lost their connection, I have found the problem that the ISP said they had.

4
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence