UK's Computer Misuse Act to be reviewed, says Home Secretary as she condemns ransomware payoffs
- Reference: 1620748811
- News link: https://www.theregister.co.uk/2021/05/11/computer_misuse_act_review_priti_patel/
- Source link:
The Home Secretary pledged the legal review in a [1]speech at the CyberUK conference this afternoon, organised by the National Cyber Security Centre (NCSC).
"As part of ensuring that we have the right tools and mechanisms to detect, disrupt and deter our adversaries, I believe now is the right time to undertake a formal review of the Computer Misuse Act," said Patel.
[2]
[3]
[4]
Passed in 1990, the Computer Misuse Act (CMA) was [5]last majorly amended in 2008 , lengthening prison sentences available and clearly criminalising DDoS attacks, something that was felt by government to be unclear at the time.
"Today I am announcing we are launching a [6]call for information on the Act this year," continued Patel. "I urge you all to provide your open and honest views on ensuring that our legislation and powers continue to meet the challenges posed by threats to cyberspace."
Patel's promise represents victory for the [7]CyberUp campaign , which has leaned on government over the past couple of years to amend the CMA and bring it up to date for the modern era. Originally passed as a not-quite-kneejerk response to [8]the Prince Philip Prestel hack in the late 1980s , the act is not a popular option for police or prosecutors, despite, on the face of it, criminalising most modern computer-enabled mischief.
[9]
Ed Parsons, exec veep of consulting at F-Secure, which supports the CyberUp campaign to reform the CMA, told The Register : "I would welcome an official review of the Computer Misuse Act and encourage the Home Secretary to consider the proposed reforms set out [10]in the Criminal Law Reform Now Network's report last year .
"The review should consider broadly how to combat cybercrime including helping UK cyber security companies to defend people and organisations and address the industry skills shortage."
[11]Prince Philip, inadvertent father of the Computer Misuse Act, dies aged 99
[12]Lord joins campaign urging UK government to reform ye olde Computer Misuse Act
[13]Average convicted British computer criminal is young, male, not highly skilled, researcher finds
[14]Cyberup campaign: 80% of infosec pros fear they might fall foul of UK's outdated Computer Misuse Act
Everyone's afraid of breaching it when doing their jobs - even the police
The Law Commission, a government law reform body, published a report on search warrants in October 2020 that highlighted police fears about breaching the CMA while investigating online crimes. That report
[15]PDF
recommended reform of the act for three reasons:The first reason accords with the observation made by the Law Society and which we have endorsed elsewhere: it would be beneficial to both the individual subject to a warrant and investigators, to have clarity on the powers available and the extent of them.
The second reason is that the limits on the use of the power could then be made explicit in its statutory formulation.
A third and more specific reason is that without lawful authority, an investigator may be committing an offence under the Computer Misuse Act 1990 by searching an electronic device.
Patel also pledged to tackle "online child sexual abuse", revealing that 800 arrests had taken place in the last year for this despicable crime alone. Notably, however, she did not [16]repeat her previous attacks on end-to-end encryption , something that was widely expected given the British government's hostility to the technology.
Ransomware is bad and you shouldn't pay off criminals
The Home Secretary also delivered a direct attack on companies that pay off ransomware criminals in the hope of decrypting their data and preventing publication of trade secrets, staffers' personal data and more.
"Government has a strong position against paying ransoms to criminals, including when targeted by ransomware," said Patel today.
Paying a ransom in response to ransomware does not guarantee a successful outcome. You will not protect networks from future attacks, nor will it prevent the possibility of future data loss. In fact paying a ransom is likely to encourage further criminality.
Patel's condemnation comes shortly after the multinational Ransomware Taskforce, a public-private offshoot of the US-based Institute for Security and Technology, pointed out in a report
[17]PDF
that ransom funds "may be used for the proliferation of weapons of mass destruction, human trafficking, and other virulent global criminal activity". Yet the taskforce notably stopped short of recommending a global ban on ransom payments.The topic is a hot one: many businesses, fearful of regulatory action and negative publicity, quietly pay up and hope nobody notices – as well as praying that the crims don't come back for a second bite of the cherry.
Former NCSC chief Ciaran Martin praised Patel's condemnation of ransomware payments as "significant and welcome".
[18]
A Russian ransomware gang caused the operators of [19]a major US oil pipeline to shut it down last week as a precautionary measure . Infosec firm Secureworks told The Register it had tracked 81 so-called "name and shame" attacks by the Russia-based criminal gang, which has made some waves in the wider infosec world for publishing a public relations website. Among other things, the group that calls itself DarkSide [20]used the site to say today that its aim was "to make money, and not creat[e] problems for society."
"If threat actors realize that pure extortion based on stolen data is as profitable as encrypted ransomware is today – then that is a game changer. The flash to bang between initial compromise and operational success (for the threat actor) collapses from days to hours or even minutes," mused a gloomy Barry Hensley, chief threat intel officer of Secureworks. ®
Get our [21]Tech Resources
[1] https://www.youtube.com/watch?v=fBQcAMF9QVk&list=PLBQXJX7r5ayPWOWAm2ig3zeW93KkZleK2&index=4
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJr@fJT998QJm72aAPlA-gAAAAE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJr@fJT998QJm72aAPlA-gAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJr@fJT998QJm72aAPlA-gAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2008/09/30/uk_cybercrime_overhaul/
[6] https://www.gov.uk/government/consultations/computer-misuse-act-1990-call-for-information
[7] https://www.theregister.com/2020/11/19/computer_misuse_act_reform_cyberup/
[8] https://www.theregister.com/2021/04/09/prince_philip_obituary/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJr@fJT998QJm72aAPlA-gAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2020/01/22/clrnn_computer_misuse_act_reform_call/
[11] http://www.theregister.com/2021/04/09/prince_philip_obituary/
[12] http://www.theregister.com/2021/03/18/lord_joins_cyberup_cma_reform_campaigners/
[13] http://www.theregister.com/2021/04/13/uk_computer_misuse_act_conviction_analysis/
[14] http://www.theregister.com/2020/11/19/computer_misuse_act_reform_cyberup/
[15] https://s3-eu-west-2.amazonaws.com/lawcom-prod-storage-11jsxou24uy7q/uploads/2020/10/Search-warrants-report-grayscale-web-1.pdf
[16] https://www.theregister.com/2021/04/19/uk_anti_encryption/
[17] https://securityandtechnology.org/wp-content/uploads/2021/04/IST-Ransomware-Task-Force_Final_Report.pdf
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJr@fJT998QJm72aAPlA-gAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/
[20] https://www.reuters.com/business/energy/statement-suspected-us-pipeline-hackers-say-they-dont-want-cause-problems-2021-05-10/
[21] https://whitepapers.theregister.com/
Oh no, a review of the act by Darth Pritel? This wont end well
Sadly
Sadly theres not many choices.
a) Stop storing so many secrets on servers that are open to the whole company. This means that any attack can get to less information.
b) Stop storing so much data - do you REALLY need to store the inside leg measurement of someone who just wants to contact your customer service or apply for a job? If I wanted a bloody account on your server to apply for a job then you should not employ me as I am evidently stupid. What you should do is open up a route for me to submit a CV for a job direct to the person responsible.
c) Switch off known and obvious vulnerabilities - you dont need macros enabled to view a word document.
d) Compartmentalize - its what the terrorist guys do, its what the resistance in France did, in fact it goes back long before that - if people in the office in Vancouver dont have access to information that is only relevant to the guys in London then they cant lose it and cant have it locked.
e) Sort out backups. Yes I understand that some of these attacks manage to set themselves up so your standard copying the files to another disk doesnt help because they too are somehow actually encrypted - so find a route to backing it up into a different file format that you write fresh - e.g. print it to a text file or some such - and then you can just read the text file back into the database - yes it IS slow but hell, it isnt as bad as paying billions.
In order for any of the above to work you need managers that understand IT, you need to pay engineers enough money they actually give a shit about the company. Basing wages in London on what you might be get away with paying an Outer Mongolian goatherd isnt going to get you the people with the skills you need or the enthusiasm to cover your arse.
Re: Sadly
One thing that really pees me off is buying stuff online and I get to the 'checkout' stage and I have to set up an account with yet another username and password, for a company I will probably never buy from again in the next 5 years. I generally try to find some other supplier. Some companies do have a 'proceed as guest' payment option, which I use, and is welcome, but on the occasions where I've needed to generate an account, what do I do, write down the password or just realise I'm going to forget it in the next half hour anyway?
Yes backups are really useful, but they have to be offline at some time so that the ransomers can't encrypt those as well.
Oh and as for "In order for any of the above to work you need managers that understand IT, you need to pay engineers enough money they actually give a shit about the company." I feel your pain, bro, I feel your pain*.
*Or at least I did until I retired a couple of years ago.
Sorry, RANT OVER. I need a drink.
Computer misuse
Considering who is promising the review, I wonder if there will be prison sentences for typos and floggings for clogging keyboards with pizza crumbs?
Aside from any likely governmental ridiculousness, the act does need an overhaul so this is hopefully going to be a good thing, also including recommendations or standards for in house hygiene may be helpful as a means to go some way towards preventing attacks in the first place.
Re: Computer misuse
Quote
" I wonder if there will be prison sentences for typos and floggings for clogging keyboards with pizza crumbs?"
EEEEKKK no more BOFH stories for me.
Re: Computer misuse
Could be the end of "Who, Me?" as well.
There is literally only one important thing that needs to be done ...
... and it won't be.
The people in charge need to carry the can for the cock-ups. They aren't shy about (over-)rewarding themselves when things are going (even moderately) well and the customary justification is the enormous burden they have to shoulder. But when the excrement hits the air movement device their shoulders become both even more slopey and virtually frictionless.
"online child sexual abuse"
Yes, of course, obviously. You definitely need to mention online child sexual abuse if you want anything computer-related to pass into law.
I wonder if such a review might lead to a ban on the trade in bitcoins and similar, as they are perceived to be only suitable for use by criminals and scammers.