Slashdot Mirror


Phishers Face Jail Time Under New U.S. Bill

An anonymous reader writes "Democrat Patrick Leahy has introduced a new federal anti-phishing bill that would impose jail terms up to five years and fines up to $250,000 for criminals creating fake web site designed to con consumers in to giving them their personal information. 'Some phishers can be prosecuted under wire fraud or identity theft statutes, but often these prosecutions take place only after someone has been defrauded - that leaves plenty of time to cover their tracks. Traditional wire fraud and identity theft statutes are not sufficient to respond to phishing.' said Leahy in a statement regarding the Anti-Phishing Act of 2005."

19 of 262 comments (clear)

  1. Re:The crime is creating a website? by LiquidCoooled · · Score: 5, Insightful

    Parody sites do not usually require you to give up account numbers of other information.

    Any that do should be rightfully concerned.

    --
    liqbase :: faster than paper
  2. Great..... by Capt+James+McCarthy · · Score: 4, Insightful

    Congress is all over it. Now the problem is sure to be solved. :-/ I'm afraid that this lip service will once again make the general public think this will solve the problem. Nope. It may slow down folks within the US borders, but we all know the true result of bills like this. It just won't work.

    --
    There are no loopholes. It's either legal or it's not.
  3. Please explain why by Anonymous Coward · · Score: 5, Insightful

    "Traditional wire fraud and identity theft statutes are not sufficient to respond to phishing.' said Leahy in a statement regarding the Anti-Phishing Act of 2005."

    Please explain why. New laws suck. 99% of the time the old existing laws are completely capable of handling the problem... just enforce the laws we have.

    1. Re:Please explain why by ednopantz · · Score: 3, Insightful

      Somebody should develop a tool to bombard their websites with junk data. They want acct #s and passwords? Give em 10,000 fake ones for every real one. Let them try and figure out which is which. It could even be a distributed app: FoilPhishers@Home.

      But yeah, send 'em to Federal PMITA prison at first opportunity too.

    2. Re:Please explain why by glyn.phillips · · Score: 5, Insightful

      Don't forget Illegal Use of Trademark.

    3. Re:Please explain why by RobotRunAmok · · Score: 4, Insightful

      Leahy is a lawmaker. Lawmakers make laws. There is no glamor for him in enforcing existing (i.e., someone else's) laws.

      How many congresspeople do you know who run for re-election on a platform of, "Hey, y'know, we've pretty much got a law for every possible crime imaginable, I just spent my term minimizing bureacracy so Justice, the cops and the courts could do their thing" ?

      It's all about the re-election. "Hey, lookit me! The hip Anti-Phish Candidate! A year ago it wasn't even a word, but last week I wrote a law against it!! Who's your Re-Electable Daddy?!"

      It's the same headline-generating mentality that prompts these bozos to make cellphone-specific anti-driving-while-distracted laws.

    4. Re:Please explain why by dasunt · · Score: 4, Insightful
      Please explain why. New laws suck. 99% of the time the old existing laws are completely capable of handling the problem... just enforce the laws we have.

      Here's my theory what happens:

      Imagine a congressman or congresswoman wants to appear to be doing something. Or perhaps they are just naive. Either way, they come up with a new law which more or less covers an existing law. We'll use a hypothetical "Violence against Women Act 2005", which makes kidnapping a woman across state lines a federal offense.

      Now, its already illegal to kidnap someone across state lines, as we all should know. However, considering that there is a 2006 election just around the corner, the average member of congress will not vote against this act -- just imagine the attack ads if he did!

      Look at the AARP -- they are being attacked by USA Next for supporting gay marriage. What really happened is that Ohio was passing a constitutional amendment to ban gay marriage. The bill was broad enough to apply to unmarried cohabiting heterosexual seniors. The AARP, acting in the best interests of its members opposed the bill, and now we see ads about how AARP is for gay marriage.

      So, let me ask you one question: Why are you against punishing criminals? Your opponent will be asking you this question in 2006.

      As always, there is a Simpson's quote for this. Episode 2F11, where Bart discovers a comet that happens to be directly headed towards Springfield:

      KENT BROCKMAN
      With our utter annihilation imminent, our federal government has snapped into action. We go live now via satellite to the floor of the United States congress.

      SPEAKER
      Then it is unanimous, we are going to approve the bill to evacuate the town of Springfield in the great state of--

      CONGRESSMAN
      Wait a second, I want to tack on a rider to that bill - $30 million of taxpayer money to support the perverted arts.

      SPEAKER
      All in favor of the amended Springfield-slash-pervert bill?

      FLOOR
      Boo!

      SPEAKER
      Bill defeated.
  4. How is this different... by 91degrees · · Score: 5, Insightful

    From exisitng conspiracy to commit fraud crimes?

    Why do we need a new law when an existing one will do?

  5. Re:The crime is creating a website? by erick99 · · Score: 3, Insightful

    The crime is tricking someone into giving up sensitive information such as bank account info so that their money can be stolen (as one example). Building the web site is a tool to accomplish the theft. I don't believe, however, that the legislation will outlaw websites in general.

    --
    http://www.busyweather.com/
  6. This may actually help by wingspan · · Score: 5, Insightful
    Phishing exists because the phisher has a favorable risk/reward relationship. This legislation will help change that relationship by allowing law enforcement to get involved earlier. Today, LE has to wait for a fraud to occur and someone to complain. If my understanding is correct, under this legislation LE can get involved much earlier, when phishing or pharming is first detected. Earlier involvement means less time for the phish site to be operating (reducing return), and less time to destroy evidence (increasing risk).

    Of course, whether they will become involved or not is subject to debate.

  7. Hot air by glyn.phillips · · Score: 3, Insightful

    Apparently Patrick Leahy is ignoring just how easy it is to move phishing opperations off shore. This looks more like a means to keep Leahy in the news rather than an effective crime-fighting law. In the horse and buggy days people learned not to walk right behind a horse unless willing to get kicked. When automobiles came out everyone learned to look both ways before crossing the street. As any new technology appears, a new set of safety rules comes with it, and each individual needs to learn the new rules. Many institutions are busy educating their users and now law is needed to force them to do this as it is already in their best interest.

    1. Re:Hot air by Steve+B · · Score: 3, Insightful
      Apparently Patrick Leahy is ignoring just how easy it is to move phishing opperations off shore.

      The host computer can be moved offshore, but the phisher himself can still be nabbed as long as he stays in the US (or a country with an extradition treaty). As a few people pointed out on spammer thread the other day, not many of the crooks are willing to actually go live in Elbonia so they can hide from the law.

      --
      /. If the government wants us to respect the law, it should set a better example.
  8. Re:The crime is creating a website? by josh3736 · · Score: 4, Insightful
    Christ, take off your tinfoil! This is an entirely reasonable and proper use of legislative power.

    This bill stops Bad Guys® from stealing the inexperienced users' life savings before they actually steal anyone's money. It does not outlaw building any website, just those designed with the intent and purpose to steal your bank password.

  9. And all Phishing sites are US-based too. Whew! by mattspammail · · Score: 3, Insightful

    How many of you have actually traced down an IP address to find its origin? I know I'm not the only one. The first thing you find out is that the IP address is registered in Latin America or some other part of the world where we have no jurisdiction. The second thing you find out is that there is no way to do anything about their perceived illegal activities. I say perceived, because it may be un-legislated activity where they come from.

    I say all of this because I don't think there's a single thing we can do to prevent those outside our country from doing this over and over and over again.

    Practically useless, if you ask me.

    --
    Now accepting PayPal donations!
  10. Re:Evidence by Anonymous Coward · · Score: 3, Insightful

    That shouldn't be difficult.

    Creating a website that looks like that of an existing bank or commercial concern using graphics and layouts harvested from said bank or commercial concern's website and asking for account numbers and PINs, SSNs and other personal information should be ample proof of intent. Using browser address bar and security certificate spoofs/hacks should cement the proof of intent.

    An individual or group who collects usernames and passwords like that doesn't do so for curiosity's sake.

  11. Re:better solution. by Speare · · Score: 4, Insightful

    I agree...the more we "police" the internet ourselves, the less the government will need to regulate it.

    An' if we take 'em out o'the holdin' cell afore their trial, an' string 'em up inna tree, then the liberal activist judges cain't set 'em free! Who's wit' me? Grab yer hoods an' meet me by the libary at half past midnight. We're gonna do some justice.

    --
    [ .sig file not found ]
  12. Why can I murder someone for less jail time? by IpsissimusMarr · · Score: 4, Insightful

    Is it just me or is doing something illegal in the cyber-world more dangerous than the real world? How is it possible that I get more jail time for cracking into and defacing a web page than I'd get for shooting someone?

    For our 'cyber-laws' we should be taking precidence from our existing laws. Instead of levying new fines for phishing, add this definition onto our current fraud and identity theft laws. Instead of creating crazy fines for spammers (although I want to see them pay just like everyone else) and model the punishments similarly to the do-no-call lists?

    Law-makers don't see the internet as an extension of the physical world, and in term of law it should be seen in this light. Extend Current laws, don't make them up in a flight of fancy.

    --
    "Engineers do the work of man, Physicists do the work of God"
  13. Re:The crime is creating a website? by squiggleslash · · Score: 3, Insightful
    I think the page you link to has so little in common with Phishing that it's about as likely to be prosecuted under a hypothetical badly-worded anti-phishing law as it is under a hypothetical badly-worded anti-cellphone-while-driving law. It doesn't represent itself as the bank in question, no reasonable person would see it as the bank in question, and the only way anyone would class it as "phishing" would be if the author is actually keeping the login information and abusing it (in which case he should be prosecuted!)

    I think, to be quite honest, it takes the cake to criticise a law you haven't read and have no reason to believe is overbroad for being overbroad or badly worded. Yeah, it might be. Likewise the law on murder might be so overbroad that you can be prosecuted under it for eating beef. But that's not the case, and there's no reason, at this stage, to believe the anti-phishing law is overbroad either. Criticise it when it's actually got something in it to criticise.

    --
    You are not alone. This is not normal. None of this is normal.
  14. Re:New *Introduced* Bill by geoffspear · · Score: 3, Insightful
    Not only are you cynical, you're completely delusional, too.

    The Supreme Court overturns very few laws. Congress passes plenty of laws. You have no idea what you're talking about, and should stop wasting everyone's time by posting such stupid messages.

    --
    Don't blame me; I'm never given mod points.