#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
The upgradation of the UK’s computer crime laws is in progress and one of the new amendments proposed under the Computer Misuse Act is about making the creation and distribution of so called “Hacking Tools” a crime. There are strong criticisms coming from the security industry as many such tools that can be used by bad guys for breaking into a system are also used by good guys to test their systems for security. For example, a network sniffer can be used for eavesdropping as well as for trouble shooting a network. It depends on the context the tool is being used and marking any such tools as “hacking tools” and making them unavailable for distribution can hinder the work of system administrators and vulnerability researchers. These amendments are not in force at present and may be applied later this year.
After much concerns raised by the industry, the government is considering a few of the concerns and is recognizing the “dual use” status of a few such tools. It would need the prosecutor to prove that the author wrote the tool with malicious intend to prove him guilty, but the distribution of such tools may still be considered as crime. The Crown Prosecution Service will look for answers to the following questions for proving someone guilty or not:
- Has the article been developed primarily, deliberately and for the sole purpose of committing a CMA offence (i.e. unauthorized access to computer material)?
- Is the article available on a wide scale commercial basis and sold through legitimate channels?
- Is the article widely used for legitimate purposes?
- Does it have a substantial installation base?
- What was the context in which the article was used to commit the offense compared with its original intended purpose?
The following sources were used as my primary information source:
The Register, LightBlueTouchPaper and CPS.
IT laws can always be tricky to write and implement, and this law surely will raise many eyebrows. Thought it may help bring bad guys to justice, it will also make legitimate good guys nervous to create new tools and distribute them.
|
|
Submit your own comments / message for this post