With a vested interest as I am chairing stream 9 of the Critical Legal Conference 2010 @ Utrecht in September 2010 : The WWW: great expectations or great disenchantments?
To see all the streams of the Conference on Modernities, click here
Showing posts with label General - Legal/non legal responses to cybercrime. Show all posts
Showing posts with label General - Legal/non legal responses to cybercrime. Show all posts
Tuesday, 18 May 2010
Thursday, 23 July 2009
Views on regulation on the net
Axel Pawlik, managing director of the Ripe NCC, writes about regulation on the net. He considers that ISPs should not take an active role in regulation, notably in relation to piracy. THey should be treated like telecom companies which list calls and that's all.
The article is definitely not a cybercrime perspective as such: there is piracy, but I think the issue of piracy is first of all an issue about what we want with copyrights; domain names attribution is looked at and again there is no incidence in criminal law for that.
However there is an interesting parallel with telephone companies when it comes to surveillance. We all know that surveillance of contents on phone conversation requires preliminary investigation: governments are not allowed to wiretap telephone conversations just to find out about illegal contents (or let's put it that way: in democracies, they are not supposed to do random wiretapping without warrant). Why should the net be treated different? Apart from the non feasibility of spying on all contents, it's nothing different and privacy is key.
Politicians should stay out of internet policing (ZDnet.co.uk, 22 July 2009)
which is obviously not what the UK Government does as it poured 10 millions pounds on monitoring.
"Gov't boosts spending on web monitoring" (ZDnet.co.uk, 13 July 2009)
whereas in France, Mr. Alain Bravo for the Assemblee Nationale (Parliament), published his report on security and digital economy to explain six scenarios, from no control apart from big firms' to too much control... http://www.assemblee-nationale.fr/13/rap-info/i1670.asp
The article is definitely not a cybercrime perspective as such: there is piracy, but I think the issue of piracy is first of all an issue about what we want with copyrights; domain names attribution is looked at and again there is no incidence in criminal law for that.
However there is an interesting parallel with telephone companies when it comes to surveillance. We all know that surveillance of contents on phone conversation requires preliminary investigation: governments are not allowed to wiretap telephone conversations just to find out about illegal contents (or let's put it that way: in democracies, they are not supposed to do random wiretapping without warrant). Why should the net be treated different? Apart from the non feasibility of spying on all contents, it's nothing different and privacy is key.
Politicians should stay out of internet policing (ZDnet.co.uk, 22 July 2009)
which is obviously not what the UK Government does as it poured 10 millions pounds on monitoring.
"Gov't boosts spending on web monitoring" (ZDnet.co.uk, 13 July 2009)
whereas in France, Mr. Alain Bravo for the Assemblee Nationale (Parliament), published his report on security and digital economy to explain six scenarios, from no control apart from big firms' to too much control... http://www.assemblee-nationale.fr/13/rap-info/i1670.asp
Thursday, 25 June 2009
Best protection: technical vs legal
Nothing protects better against crime than testing one's vulnerabilities and strengths. A non legal response understood by Governments:
UK launches dedicated cyberattack agency (ZDnet.co.uk, 25 June 2009)
Pentagon moves to protect military networks (ZDnet.co.uk, 24 June 2009)
UK launches dedicated cyberattack agency (ZDnet.co.uk, 25 June 2009)
Pentagon moves to protect military networks (ZDnet.co.uk, 24 June 2009)
Wednesday, 3 June 2009
DDOS practice by security firms
In order to shut down those sending spam and scams (particularly phishing), security firms can identify the original server and then send e-mails to shut down the site
Sébastien Darnault (MarkMonitor)"Nous bombardons les serveurs de mails frauduleux jusqu'à les faire tomber" (JDN 2 June 2009)
Sébastien Darnault (MarkMonitor)"Nous bombardons les serveurs de mails frauduleux jusqu'à les faire tomber" (JDN 2 June 2009)
Tuesday, 19 May 2009
House of COmmons' control on Government's policy and EU
The House of COmmons' European Scrutiny Committee delivered its 8th report (may 2009) and analyse, in particular, the UK Government's implementation of EU policy on cyber attacks. Pages 19 to 21, after having summarised the EU policy, the Committee analyses the Government's responses and note the lack of clarity of the Minister's reply.
http://www.publications.parliament.uk/pa/cm200809/cmselect/cmeuleg/19-xvi/19-xvi.pdf
http://www.publications.parliament.uk/pa/cm200809/cmselect/cmeuleg/19-xvi/19-xvi.pdf
Fight against fraud
"Soca puts a clamp on cybercrime" (ZDnet.co.uk, 15 May 2009)
"The Rise Of Corporate Identity Fraud" (TechDirt, 11 May 2009)
"The Rise Of Corporate Identity Fraud" (TechDirt, 11 May 2009)
Wednesday, 6 May 2009
Cybercrime policy - US, EU, France and the world
All but one in French, but I haven't finished going through my English newsletters, so should be able to complement later on with English language articles:
"International experts launch anti-cybercrime plan" (ZDnet.co.uk, 29 April 2009): not so international as it may appear as it involves primarily the US and the UK, but at least the Cyber Security Knowledge Transfer Network (KTN), a UK government-funded organisation, is supposed to "liaise[...] between agencies around the world, co-ordinated the formulation of the roadmap". A plan by N. Jones from KTN was published that argues that businesses should be more proactive and important partners in security.
"Building in… Information Security, Privacy and Assurance - A high-level roadmap" on KTN website
Viviane Reding is the European commissioner on new technologies; she suggests to create a European post/job of "internet police/policing officer" so as to coordinate European responses to cyberattacks and develop a strategy to increase cybersecurity
"Un Monsieur sécurité pour défendre l'Europe contre les cyber-attaques ?" (JDN, 27 April 2009)
This very much echoes what has already started in the US, with a change of policy under Obama new presidency, where Melissa Hathaway has already highlighted the new trends in cybersecurity the US will focus on, with notably a multi agencies and institutions cooperation "La cybercriminalité dans le collimateur de l'administration Obama" (JDN, 24 March 2009)
And for France, this interesting article decrypting the French President's promises during the election campaign and their outcomes in 2009. "Sécurité et libertés : les données personnelles en danger ?" (JDN, 5 May 2009). On security, what has been delivered so far is a Report (Livre blanc/White Book) on Defence and Security in June 2008 which highlighted the policies up to 2020 notably in terms of warfare.
In terms of right to privacy, the biometic passport has been launched despite the CNIL (a quango) opposition to it; the obligation for ISPs to block paedophilia websites, and the three strikes law on copyrights infringement. Generally, the CNIL tends to be sidelined as none of its advices has been followed by the Government.
"International experts launch anti-cybercrime plan" (ZDnet.co.uk, 29 April 2009): not so international as it may appear as it involves primarily the US and the UK, but at least the Cyber Security Knowledge Transfer Network (KTN), a UK government-funded organisation, is supposed to "liaise[...] between agencies around the world, co-ordinated the formulation of the roadmap". A plan by N. Jones from KTN was published that argues that businesses should be more proactive and important partners in security.
"Building in… Information Security, Privacy and Assurance - A high-level roadmap" on KTN website
Viviane Reding is the European commissioner on new technologies; she suggests to create a European post/job of "internet police/policing officer" so as to coordinate European responses to cyberattacks and develop a strategy to increase cybersecurity
"Un Monsieur sécurité pour défendre l'Europe contre les cyber-attaques ?" (JDN, 27 April 2009)
This very much echoes what has already started in the US, with a change of policy under Obama new presidency, where Melissa Hathaway has already highlighted the new trends in cybersecurity the US will focus on, with notably a multi agencies and institutions cooperation "La cybercriminalité dans le collimateur de l'administration Obama" (JDN, 24 March 2009)
And for France, this interesting article decrypting the French President's promises during the election campaign and their outcomes in 2009. "Sécurité et libertés : les données personnelles en danger ?" (JDN, 5 May 2009). On security, what has been delivered so far is a Report (Livre blanc/White Book) on Defence and Security in June 2008 which highlighted the policies up to 2020 notably in terms of warfare.
In terms of right to privacy, the biometic passport has been launched despite the CNIL (a quango) opposition to it; the obligation for ISPs to block paedophilia websites, and the three strikes law on copyrights infringement. Generally, the CNIL tends to be sidelined as none of its advices has been followed by the Government.
Wednesday, 11 March 2009
US cybersecurity agency and spy agency
Strangely enough, I saw that information first in the French newspaper, rather than English speaking newsletters! Rod Beckström , the head of the National Cybersecurity Center in the US and responsible for protection against cyberattacks, resigned after the Center being attached to the National Security Agency which more or less spies on the web, rather than improving the security of the network. Looking at his reasoning, he is probably right. The NSA has different objectives than the NCSC; that they should collaborate, it's obvious; but they should remain different in the way they function. Merging them is potentially a source of human rights infringement.
"Le patron de la cyber-sécurité américaine claque la porte" (JDN, 9 March 2009)
For a related article (this time in English), "Is FEMA The Best Group To Model A Cybersecurity Agency After?" (TechDirt, 20 February 2009)
and for the other aspect of the US policy on new technologies "Barack Obama nomme un CTO pour l'Amérique" (JDN 6 mars 2009)
"Le patron de la cyber-sécurité américaine claque la porte" (JDN, 9 March 2009)
For a related article (this time in English), "Is FEMA The Best Group To Model A Cybersecurity Agency After?" (TechDirt, 20 February 2009)
and for the other aspect of the US policy on new technologies "Barack Obama nomme un CTO pour l'Amérique" (JDN 6 mars 2009)
Sunday, 1 February 2009
A reminder that cybercrime is not always about law
A reminder that sometimes the best response to cybercrime is the use of technology rather than the enactment of legislation. Be aware though that no technology is flawless, so security is never 100% guaranteed.
India IT sector boosts (ZDnet.co.uk, 27 January 2009)
India IT sector boosts (ZDnet.co.uk, 27 January 2009)
Friday, 12 December 2008
Tuesday, 25 November 2008
Better educated children, less victims?
So many conflicting reports about the influence of internet on children and adults that I do not know if this one must be trusted either. I disagree with the idea that the internet cannot have a negative impact. No later than a week ago, a teenage girl escaped from home and met a man met through msn, paedophile presenting himself as a 16 years old...
on the other hand, the message that on the net you cannot know who the other person is really and that one should be more wary about one's privacy, may start to come through?
"As Internet Usage Grows, Sexual Offenses Against Kids Have Decreased" (21 Novembre 2008)
on the other hand, the message that on the net you cannot know who the other person is really and that one should be more wary about one's privacy, may start to come through?
"As Internet Usage Grows, Sexual Offenses Against Kids Have Decreased" (21 Novembre 2008)
Thursday, 9 October 2008
Responses to cybercrime - Debate at HL
Friday 10 October 2008, House of Lords will start the debate again, following their earlier reports. What is interesting is the proposal for software companies to be responsible for insecure code. If companies were responsible like Microsoft, they would be a bit more careful in their release and would save a bit of money to everyone. After all, if you release a toy or a TV which explodes or has default, the manufacturer is liable, at least for one year in the UK; why not software companies?
"Lords to debate gov't progress on internet security" (6 October 2008)
"Lords to debate gov't progress on internet security" (6 October 2008)
Friday, 3 October 2008
New e-crime police - a welcomed addition?
Fraud being one of the most common crimes in cyberspace, it's good to see the National Fraud squad welcoming the creation of the e-crime police in the UK "National anti-fraud centre ready for action" (3 October 2008)
Meanwhile the City of London decided to take action "City of London pilots cybercrime scheme" (ZDNet.uk, 6 June 2008)
and Government hesitates "E-crime unit 'on track' despite funding delay" (ZDNet.uk, 16 June 2008)
Meanwhile the City of London decided to take action "City of London pilots cybercrime scheme" (ZDNet.uk, 6 June 2008)
and Government hesitates "E-crime unit 'on track' despite funding delay" (ZDNet.uk, 16 June 2008)
Thursday, 2 October 2008
New UK e-crime police training
They want to recruit from the technology industry. Providing they have enough money to pay the persons! See "Fears over funding for police e-crime unit " (2 October 2008)
No problem with that, but training in law and criminal law should not be forgotten ..."Police e-crime unit seeks industry recruits" (2 October 2008).
And in the US, it's the Homeland Security which helps out the businesses (1 October 2008)
No problem with that, but training in law and criminal law should not be forgotten ..."Police e-crime unit seeks industry recruits" (2 October 2008).
And in the US, it's the Homeland Security which helps out the businesses (1 October 2008)
Wednesday, 17 September 2008
Hackers and their skills for policing purposes
A recurrent theme, this time in New Zealand,
"New Zealand Hacker Released As Police, Judge, Prosecutors All Praise His Mad Hacking Skillz"(16 July 2008)
as the charge was dropped "NZ teenage hacker charges dropped " (BBC, 16 July 2008)
see also my post of 14 March 2008
"New Zealand Hacker Released As Police, Judge, Prosecutors All Praise His Mad Hacking Skillz"(16 July 2008)
as the charge was dropped "NZ teenage hacker charges dropped " (BBC, 16 July 2008)
see also my post of 14 March 2008
Tuesday, 15 July 2008
Cybercrime and the EU
The COuncil of Europe created the Convention of Cybercrime. Time for the EU, despite the drawback about the treaty of Lisbon, to look at cybercrime a bit more seriously than it has done so up to now.
A study is expected: http://www.crime-research.org/news/02.05.2008/3344/ (2 May 2008)
and the Commission recently took a Framework Decision about cyber attacks in order to clarify legal issues to facilitate responses to crime http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2008:0448:FIN:EN:PDF (14 July 2008)
A study is expected: http://www.crime-research.org/news/02.05.2008/3344/ (2 May 2008)
and the Commission recently took a Framework Decision about cyber attacks in order to clarify legal issues to facilitate responses to crime http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2008:0448:FIN:EN:PDF (14 July 2008)
Friday, 14 March 2008
Response to cybercrime: hackers as security guards?
Security is best; law is second-best. Great, but how to enhance security? Debate was launched about whether or not to hire hackers. See the responses or comments to TechDirt's post "Does It Make Sense To Hire A Convicted Cracker For Security Work?" (12 March 2008) http://www.techdirt.com/articles/20080311/113836498.shtml
the reality is that most famous hackers ended up as security men and some earn a fortune!
the reality is that most famous hackers ended up as security men and some earn a fortune!
Wednesday, 12 March 2008
Fighting cybercrime in the UK: Government's policy questioned
It's the turn of the Tories to question Government's policy in fighting cybercrime. Nothing new, but it is striking that the article stresses how cybercrime is a profitable business and not simply a gimmick used by hackers for fun purposes. Although one could argue it's quite fun to earn millions of pounds! (7 March 2008) http://news.zdnet.co.uk/security/0,1000000189,39363895,00.htm
Government's earlier move seems at odd with the international approach of Nato... although Nato is probably more concerned with cyberterrorism than with fraud (6 March 2008) "Nato bolsters cyber defences" http://news.zdnet.co.uk/security/0,1000000189,39363084,00.htm
Government's earlier move seems at odd with the international approach of Nato... although Nato is probably more concerned with cyberterrorism than with fraud (6 March 2008) "Nato bolsters cyber defences" http://news.zdnet.co.uk/security/0,1000000189,39363084,00.htm
Wednesday, 27 February 2008
the law and cybercrime: an illusory pursuit?
Not a new debate I am afraid. Yes the law is behind technology, but has not law always been behind innovation? The question is more likely: can the law adapt to innovations or can it not requiring then new legislation to be enacted? The question is particularly crucial for criminal law as the key principle is that of non-retroactivity.
"Australian High Court Judge Recognizes That Technology Outpaces The Law" (22 February 2008)http://www.techdirt.com/articles/20080222/153544324.shtml
"Australian High Court Judge Recognizes That Technology Outpaces The Law" (22 February 2008)http://www.techdirt.com/articles/20080222/153544324.shtml
Friday, 22 February 2008
Tackling cybercrime in the UK and in the US
Need of ressources
The House of Lords tries to put pressure on UK Government, with limited success though. Nothing serious has been done since August 2007, and to wait until next August, knowing the timing of legislation, just means more delays... "Lords inquiry looks again at internet security "(21 February 2008) http://news.zdnet.co.uk/security/0,1000000189,39327039,00.htm
Use of ressources: charging for the right crime!!
use of insider trading laws in the US instead of computer fraud! (18 February 2008)http://www.techdirt.com/articles/20080217/190615270.shtml
The House of Lords tries to put pressure on UK Government, with limited success though. Nothing serious has been done since August 2007, and to wait until next August, knowing the timing of legislation, just means more delays... "Lords inquiry looks again at internet security "(21 February 2008) http://news.zdnet.co.uk/security/0,1000000189,39327039,00.htm
Use of ressources: charging for the right crime!!
use of insider trading laws in the US instead of computer fraud! (18 February 2008)http://www.techdirt.com/articles/20080217/190615270.shtml
Subscribe to:
Posts (Atom)