News: 1645787710

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK Computer Misuse Act reformers visit Parliament

(2022/02/25)


Infosec researcher Rob Dyke, best known to Reg readers for fending off legal threats from not-for-profit open-source foundation Apperta after finding a data breach, has visited Parliament to demand Computer Misuse Act reform.

Dyke, an open-source security researcher, was [1]threatened by the Apperta Foundation with High Court and criminal legal action after he discovered that some of the organisation's data was publicly available on GitHub.

Speaking to The Register today, Dyke said: "The Home Office is still sitting on the consultation they opened nearly 10 months ago. It would have been lovely to see some drafts or summaries from that so the conversation could carry on."

[2]

Yesterday he visited Parliament, meeting around a dozen MPs including former Conservative minister Esther McVey, now a backbencher, and Labour's shadow security minister Holly Lynch.

Esther McVey (left) poses with Cyberup spokesman Rob Dyke inside Parliament

Dyke and leading members of the Cyberup campaign also visited 10 Downing Street to hand in a letter signed by MPs demanding faster reform of the Act.

The security researcher's highly eventful attempt at vulnerability disclosure to Apperta last year resulted in him having to spend £25,000 to see off the open-source org's legal threats, though a crowdfunding campaign helped with the bulk of his legal fees.

[3]

[4]

"I have been heartened, though, by the generosity of the cybersecurity community, who rallied around me and helped me pay my legal bills," commented Dyke. "I think they know that it could have been any one of them that was put in this situation."

The Cyberup campaign, the NCC Group-sponsored industry effort to reform the Computer Misuse Act, highlighted Dyke's travails and said that vulnerability disclosure policies "have no basis in law." This, said Cyberup in a statement, meant that organisations could "on a whim decide to pursue legal proceedings against innocent cyber security professionals."

[5]

Dyke told us: "The legal threats and phone calls from the police amounted to a harrowing ordeal which has taken an enormous toll on me and my family. I couldn't sleep. I ate too little. I lost weight. I took time off work. The anxiety and stress I was feeling of course had a terrible impact on those around me."

As well as threatening ruinously expensive High Court action against Dyke, Apperta also reported him to Northumbria Police claiming he had committed a crime under the Computer Misuse Act. The police subsequently shrugged their shoulders and left the two sides to it.

[6]CyberUp presents four principles to keep security researchers out of jail for good-faith probing

[7]We're right behind Computer Misuse Act reforms for busting ransomware gangs, says UK infosec industry

[8]Labour reminds UK.gov that it's supposed to be reforming the Computer Misuse Act

[9]UK government opens consultation on medic-style register for Brit infosec pros

Cyberup is calling for the Computer Misuse Act to be amended and include a statutory defence "that would offer good faith cyber security researchers a legal basis to defend their actions against frivolous legal threats."

Big industry companies including F-Secure support the campaign, while smaller firms and independent researchers have expressed fears to The Register that any legal changes would benefit the big entities rather than the entire industry.

Other critics, speaking privately for fear of losing business and job opportunities in the UK's close-knit infosec industry, worry that a new legal defence might hinge on membership of some future registration scheme. Such a scheme was floated [10]by the government-controlled UK Cyber Security Council earlier this year ; at present, you don't need to be registered or licensed to work in cybersecurity (but good luck if you have neither industry certifications nor demonstrable skills).

[11]

Government wants to see the UK cybersecurity profession coming under greater central control, under the guise of driving up standards and introducing a UK-specific infosec certification and qualification framework.

Ruth Edwards MP said in a Cyberup statement that she supported CMA reform: "I applaud Rob for speaking out about his experience – it shines a light on what I am sure many others have gone through. It is time that we reformed the Computer Misuse Act and I will be taking this up further with ministers."

Kat Sommer, NCC Group's head of public affairs, added: "The Act – written in 1990 – didn't foresee the birth of the cybersecurity profession, and therefore leaves ethical cybersecurity researchers like Rob in the lurch as to whether or not they will be prosecuted simply for doing their jobs."

Conservative Party pledges to reform the CMA have petered out into nothingness over the past year. A cynic might suspect that reforms with support from both the ruling party and its Labour opposition is being banked until the next general election. ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2021/05/14/apperta_rob_dyke_disclosure_brouhaha/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YhkLOa-JqrTjSAS99PGMAwAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhkLOa-JqrTjSAS99PGMAwAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhkLOa-JqrTjSAS99PGMAwAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhkLOa-JqrTjSAS99PGMAwAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/11/03/computer_misuse_act_defence_principles_cyberup/

[7] https://www.theregister.com/2021/06/07/cma_reforms_anti_ransomware_high_agenda/

[8] https://www.theregister.com/2022/02/08/labour_computer_misuse_act_reform_questions/

[9] https://www.theregister.com/2022/01/25/ukgov_cybersecurity_profession_regulation_ukcsc/

[10] https://www.theregister.com/2022/01/25/ukgov_cybersecurity_profession_regulation_ukcsc/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhkLOa-JqrTjSAS99PGMAwAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



"Cyberup is calling for the Computer Misuse Act to be amended and include a statutory defence"

Mike 137

Considering both the prevalence of security vulnerabilities and the common laxity of vendors in addressing them, IMHO a statutory defence is insufficient. There should be a statutory exemption - obviously subject to strict controls to ensure research and disclosure are legitimate and responsible. For example, once a vulnerability is suspected, authorisation might be sought in confidence from NCSC before proceeding with verification, and disclosure could be managed by NCSC.

Re: "Cyberup is calling for the Computer Misuse Act to be amended and include a statutory defence"

Doctor Syntax

"disclosure could be managed by NCSC"

In fact, take it a step further with NCSC empowered to require the breach to be remedied and prosecute in event of failure to comply.

Lone actor

Dale 3

Certainly better than the inevitable alternative, the Computer Misuse Act Misuse Act.

Re: Lone actor

ShadowSystems

Or the Completely Misguided Computer Misuse Act Misuse Act?

I'll get my coat... =-)p

The Enemy are the Pirates within Pretending to be Friends of the Private Sector.

amanfromMars 1

There is a great suspicion of a huge vulnerability exploit opportunity, .... which mines covertly and is able to expose if desirous, certain leading activities and/or extremely sensitive information for which there will never be any acceptable viable defence in any court or jurisdiction, because it is so perversely blatantly corrupted to server one particular and peculiarly small group of parties to the almighty and continuing detriment and disadvantage of all other parties, ...... being revealed as easily used, abused and misused in trying to ensure cybersecurity practices are carefully not absolutely well defined and managed centrally by invested party committees.

And you can ponder yourselves on whether you think it valid, but that is one good and very bad reason for government continuing delays in any effective Computer Misuse Act reform.

Central control

Electronics'R'Us

Government wants to see the UK cybersecurity profession coming under greater central control, under the guise of driving up standards and introducing a UK-specific infosec certification and qualification framework.

I see no reason for this apart from control freakery.

In the not so very distant past I was a design authority for flight safety critical avionics and there is no certification required for that. I happen to be a chartered engineer but there is no such necessity (I find it opens useful doors at my age so I am willing to pay the annual fees but as a bonus the current $COMPANY actually allows me to expense it).

I also do not have a degree; the circumstances of the times were not suitable for me to do one.

The ID10T problem in UK government (and not just elected members of parliament) is enormous; don't foist it on the professionals just trying to do their jobs.

State snooping

tip pc

If the state wants to snoop then so be it.

They should tell us once they gave snooped though.

I’m sure the state misuse computers a lot.

QOTD:
I looked out my window, and saw Kyle Pettys' car upside down,
then I thought 'One of us is in real trouble'.
-- Davey Allison, on a 150 m.p.h. crash