News: 1644317767

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Labour reminds UK.gov that it's supposed to be reforming the Computer Misuse Act

(2022/02/08)


The shadow foreign secretary for UK's opposition Labour party, David Lammy MP, has asked why the reform of the Computer Misuse Act appears to have stalled in an open letter to government.

The letter, published on the Labour Party [1]website , takes the ruling Conservative Party's ministers to task over a range of what Labour sees as a failure to act on various Russia-linked topics.

One of those is the Computer Misuse Act (CMA), which Home Secretary Priti Patel pledged to reform in a [2]major speech last year . Yet Lammy and his colleague Rachel Reeves MP, Labour's shadow chancellor, asked in their letter: "Where is the replacement to the outdated Computer Misuse Act, as recommended by the Russia Report?"

[3]

While Labour was referring to Parliament's Intelligence and Security Committee [4]report of July 2020 , calls for CMA reform from the British cybersecurity industry [5]pre-date that .

[6]

[7]

Political attention to CMA reform has generally been absent. Although Lord Holmes of Richmond [8]lent his weight to the industry's CyberUp campaign in early 2021, other politicians have largely ignored what is admittedly a niche issue when viewed against other challenges that Britain faces. Even though Labour raising CMA reform publicly is part of a political swipe at ministers rather than genuine agreement that change is long overdue, any public mention of it is likely to be good rather than bad.

[9]Brit infosec firms urge PM Boris to reform the Computer Misuse Act

[10]UK's Computer Misuse Act to be reviewed, says Home Secretary as she condemns ransomware payoffs

[11]Academics call for UK's Computer Misuse Act 1990 to be reformed

[12]Cyberup campaign: 80% of infosec pros fear they might fall foul of UK's outdated Computer Misuse Act

Around 80 per cent of infosec professionals surveyed by CyberUp in 2020 said they feared [13]prosecution under the CMA for making a bad judgment call , though prosecution statistics show the odds of being taken to court under the act are vanishingly low.

Other industry sources from outside the big companies have told The Register they fear CMA reform may be a government excuse to increase the number of criminal offences under the act instead of enacting genuine change that protects security researchers and puts them on a level footing with their foreign counterparts.

Currently the act bans any unauthorised access to data held on a computer – even data that may have been stolen by ransomware criminals, for example. Proposals for reform include public interest defences and amendments aimed at narrowing existing offences.

[14]

So far the government has published nothing concrete about CMA reform other than vague promises that it's being looked at. With the next general election due in May 2024, it may be the case that a policy with broad support across the political spectrum might not emerge until then.

We have asked the Home Office for comment and will update this article if the government department responds. ®

Get our [15]Tech Resources



[1] https://labour.org.uk/press/lammy-and-reeves-joint-letter-on-the-ukraine-crisis-and-illicit-finance/

[2] https://www.theregister.com/2021/05/11/computer_misuse_act_review_priti_patel/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgJNWlKzqdLlhgIKVP4vSAAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://isc.independent.gov.uk/news/

[5] https://www.theregister.com/2019/07/29/computer_misuse_act_1990_reform_letter/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgJNWlKzqdLlhgIKVP4vSAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgJNWlKzqdLlhgIKVP4vSAAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2021/03/18/lord_joins_cyberup_cma_reform_campaigners/

[9] https://www.theregister.com/2019/07/29/computer_misuse_act_1990_reform_letter/

[10] https://www.theregister.com/2021/05/11/computer_misuse_act_review_priti_patel/

[11] https://www.theregister.com/2020/01/22/clrnn_computer_misuse_act_reform_call/

[12] https://www.theregister.com/2020/11/19/computer_misuse_act_reform_cyberup/

[13] https://www.theregister.com/2020/11/19/computer_misuse_act_reform_cyberup/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgJNWlKzqdLlhgIKVP4vSAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



It's a small world, but I wouldn't want to have to paint it.
-- Steven Wright