UK Law May Criminalize IT Pros
An anonymous reader writes "More worrying news from the UK. This time, a bill meant to fight cybercrime may make it illegal to use or make available network security tools available, just because they could be used by hackers." From the article: "Clayton cited the Perl scripting language, created by Larry Wall in 1987, as an example of a useful technology that could fall foul of the law. 'Perl is almost universally used on a daily basis to permit the Internet to function,' said Clayton. 'I doubt if there is a sysadmin on the planet who hasn't written a Perl program at some time or another. Equally, almost every hacker who commits an offense under section 1 or section 3 of the CMA will use Perl as part of their toolkit. Unless Larry is especially stupid, and there is very little evidence for that, he will form the opinion that hackers are likely to use his Perl system. Locking Larry up is surely not desirable.'" A note that this is equally confusing but separate from yesterday's story about the UK government wanting private encryption keys.
From the country that criminalized privacy:
I also heard that something called TPC or TCP is widely used by hax0rs to pwn remote servers. Wait till the UK Government can get their hands on it...
My 0.02 cents
Just as these tools are useful diagnostic tools they are also handy tools for commiting crimes as described under this proposed law. That's the nature of networks and tools to manage them. To deem these tools and availability of such a crime because they could be used to commit a crime is insane.
This is akin to the recent proposal that all encryption key owners make their keys available to law enforcement. The expected eventual end result will be cautious users relinquishing valuable resources with criminals holding the trump card. This too is insane.
So, when an administrator gets the call to investigate what appears to be suspicious behavior, where do they go to troubleshoot the problem? Heck, peel away all the layers of this onion and it wouldn't be surprising to find hackers are behind this... get the government to suspend priveleges using FUD, and run rampant over the network infrastructure.
There is a hint of sanity from the article:
I only hope the government will listen to that reasoning.
And I thought it was getting bad here in the U.S.
I guess a written constitution does have some utility.
A blog about stuff.
... Or at least forcing someone to debug it should
Let's ban the English language because you can discuss crimes with it.
This sort of news is great for nations like India, Singapore and Malaysia. The more the Western world places completely unnecessary and unjustifiable limits on its use of such technology, the better off the non-Western nations are.
A strong economy, and the higher quality of life it may bring, depends heavily on innovation and progress. That is clearly being hindered by those who support such legislation. Companies won't be able to take advantage of the productivity gains one gets from using the technology that may be restricted.
In the end, it comes down to a matter of freedom. Those nations who are now free to innovate will do so, and will eventually prosper. Those who seek restrictive legislation over free innovation will see their wealth and standard of living decline rapidly.
So, how long before compilers and debuggers are made illegal? Especially the open source ones.
As the island of our knowledge grows, so does the shore of our ignorance.
To compare this to another industry:
Person 1: Hi, I make hammers, would you like to buy one? You can use them to "hammer" nails into things, really quite nice for building houses and such.
Person 2: Wow, this is nice. I'll take one!
Law: Woah woah woah! Hold on right here... This "hammer" you got here... yeah well that can be used to bash someone in the head, so... it's now illegal, you'll have to come with me now. That's right, hands behind your back.
I've never understood the idea that because a tool can be used to commit a crime, that it inherantly makes the tool evil.
I suppose crowbars and hammers should be outlawed, too, since they can be used for burglary.
This is more sensationalist shit like the story about the RIPA. The law isn't very effective because the police can't force you to hand over keys that are used only to ensure the integrity of messages. This basically means that stuff like SSL, SSH and Zimmerman's Zphone are safe against seizure.
I submitted a story on this but obviously the Slashdot editors care more about exciting headlines than the sober truth. I wrote an essay in 2003 and you can read it here.
I've not read the act but I can already guess how useless it will be. The short and long of it is that it is very tough indeed to prove beyond reasonable doubt that someone that you put the software there. Believe me I know, I was a witness in a Child Porn case. The defence won because when we found the content we didn't follow CPS guidelines in the data recovery method.
Even worse, a hackers machine can look very much like a hacked machine. Hackers, after all, use one machine to get to the next. How are you going to prove they aren't the innocent bystander - BEYOND REASONABLE DOUBT.
Yet more time wasted by an incompetent government that can't even deport convicted foreign criminals.
Simon.
Computer hackers tend to use computers to commit computer hacker crimes. The link between hackers and computer systems is enhertiently intrinsic, therefore banning the use and ownership of computer systems would greatly reduce computer crime!
If there were no laws there would be no such thing as crime. To reduce crime, we should remove laws, not add more.
I'll probably be modded down for this...
They already want to ban pointy knives, so why not hammers?
u rope/27knife.html?ex=1274846400&en=cef76721be98494 c&ei=5090&partner=rssuserland&emc=rss
http://www.nytimes.com/2005/05/27/international/e
Leftist leaders even more than right wing leaders tend to have a hard time accepting the fact that you can do bad things with different tools. They also have a hard time blaming the person for their use of it. Conservatives do it with drugs by blaming the drugs for the armed robbery to feed the habit. Leftists do it with weapons. It's easy to blame a drug, a gun or a scripting language for a crime. It allows you to not be "judgemental" toward a person who is just an asshole. Neither side likes to admit that these things are totally the person's fault, derived from some inner flaw in the person's character that causes them to get high and rob, shoot to murder someone or hack to steal a person's money.
TFA also states that "People who distribute networking vulnerability scanning tools such as Nmap or Nessus could also be caught up in part (b), Clayton warned.". A quick reading of section 41 seems to bear that out. As author and maintainer of the Nmap Security Scanner, I am more than a little concerned.
I'm certainly not going to let anything as silly as some U.K. law stop me from distributing Nmap, but I also don't want to become like Dmitry Skylarov the next time I give a presentation in England. And even if (as I would expect) the rest of the world ignores this, it could have a chilling effect on important security tools and research from U.K. citizens. Think of all the good research and tools that David Litchfield from London (NGS Software) has brought us. And my London friend Hoobie brought us the free Brutus password cracker, which appears to be prohibited by this bill.
The good news is that this is just a proposal. So I would join the chorus in urging our British friends to make their voice heard against this silly bill.
-Fyodor
Insecure.Org
I know a lot of Americans are confused by the British political system, so I'd like to explain it to them.
First of all, the Labour Party has very little to do with the general, working-class labourers of the UK. So don't think of them as being liberal, or supportive of workers rights.
In the US political system, they're most like the Republicans. Basically, they're neo-conservatives. That means that they threw out what might have been the most beneficial of conservative ideals, and instead replaced them with the worst of the liberal convictions.
Unlike actual conservatism, they take a strong stance against personal freedoms. They are supportive of near-paranoid domestic surveillance and incomprehensible legislation designed to limit liberty.
Unlike actual liberals, they do not care what is best for society as a whole. They are often very supportive of corporations, and are often willing to use their power to mislead the public if it will help bring financial profit to their corporate supporters.
Hopefully that clears up the situation somewhat. We have to realize that even if they claim to be "conservative", neither the Republicans (in America) or Labour (in the UK) actually are.
I say we just outlaw those hideously dangerous 1's, and let us keep the safe, agreeable, non-pointy 0's.
Slashdot Burying Stories About Slashdot Media Owned
Is it just me or are legislators and government officials all nuts.
While they're at it, why not just criminalize the use of ANYTHING that could be used for less than honest purposes...
Let's start with any programming language that is used to write the tools that are available to the bad guys. hmmm... that would potentially be all of them... so we may as well just ban computers in general... and cell phones, PDAs and anything with microchips... There goes my new toaster... Can't let the bad guys get my toast.
But... wait there's more. Why not ban anything that could lead to the knowledge of how to do this crap in the first place? TV and radio are gone because of the whole microchip thing. Burn the books and close the schools. That way the kids don't learn about technology that may lead to tools that might be used by bad people for possibly malicious puproses...
And just to make sure that no one ever learns about it again, let's "silence" all programmers, scientists, researchers, teachers, librarians, hobbyists, and anyone who's ever operated a computer or even entered a Radio Shack.
I'm still not sure why vehicles are allowed on the road considering all the contraband and stolen possessions they could be used to transport. Coat hangers, hair pins, and any sharp tool. Instuments of evil, all of them.
Next up: Legislating the use of whatever part of the brain is the basis for the formation of new thoughts and notions.
Let them know it's horsecrap before businesses have to start moving out of the UK to survive.(!)
Criminalizing the mere possession of something just because it could potentially be used in a crime is pretty stupid. Until you do something that actually harms someone, where's the crime? "Innocent until proven guilty" remember? Just because someone has means, and could find opportunity, doesn't mean he has motive to commit a crime. Don't you need all three? Mens rea, anyone? All these sorts of laws do is make criminals out of normal, honest, otherwise-law-abiding people.
Until you stab someone, your knife is just a useful cutting tool. Until you shoot someone, your gun is just a useful self-defense and hunting tool. Until you crack something, your network analysis software is just another tool. There is nothing inherently bad/evil about them. Merely possessing them does not twist a normal person into a psychopathic criminal.
Anyone else think we'd have better lawmakers if we plucked some names at random from the phone book?
Constitutionally Correct
This makes me feel so much better about moving to the UK as an IT professional..
Why must they always pick on the good, honest guys while the criminals just dodge by their "preventative measures" every time?
Will program for karma.
Sorry innocent until proven guilty is obsolete.
They found it was inconvenient to prove someone did something before punishing them.
Much easier to simply accuse and punish, how else can they prosecute thought crime.
Seizure and liquidation of the property of people accused but never convicted of a crime does happen, and has for a long time.
Criminal justice reform is unlikely to happen because people see this as soft on crime, they just want to punish someone there is little political incentive to work on making sure they get the right person.
Plus when there is a wrongful conviction, they just blame the defendants lawyer.
At the risk of bordering on repeating the hammer/etc. analogies: "Nothing is intrinsically good or evil, but its manner of usage may make it so." Saint Thomas Aquinas
Only outlaws will have
#!usr/bin/perl
tshirts http://andrewhitchcock.org/index.pl?page=perl
actually I am happy to see you, however that is in fact a banana in my pocket.
I'm a United States citizen. While I am horrified about what's been going on currently in the US, it doesn't really suprise me, given our history as the self-appointed Savior of Europe after WWII, defender against communism, the Vietnam war, etc.
With our two-party political system, both parties have to pander to their base, which, to simplify a lot, is socialists for the Democrats and facists for the Republicans. Now that the republicans are in ascendancy, I'm not surprised that corporate power is going unchecked, and those who don't believe in government are unable to govern competently. After 9/11 burst our bubble that oceans would protect us from what's going on in the rest of the world, and the fact that we're waging a 'war on terror' that will never end, I'm not surprised that people would become fanatical and fall in line behind a militaristic administration.
However, what the hell is going on in Great Britain that gives political cover for this radical infringement into the rights and privacy of the people? Didn't the U.K. defeat Facism that threatened to overrun the country? Hasn't the UK been fighting terrorism from Ireland relatively sanely for decades? Doesn't the parliamentary system give *some* power to other policital groups which are somewhat left-leaning?
Computers are useless. They can only give you answers.
-- Pablo Picasso
...in both Britain and the US, laws phrased the way this is are usually construed such that, in order to commit an offense, the person making, distributing, etc., an article would have to have the intent or belief that that particular instance would or was likely to be used for criminal purposes. It wouldn't outlaw, e.g., making a software tool with the belief (or even near-certain statistical knowledge) that, among all the users, some number of them would use it illegally.
That's not to say its not still overly broad, unnecessary, chilling, etc., even so, but the idea that it amounts, if enforced across the board, to a ban on Perl on the basis that the creator knows that someone, somewhere is likely to end up using them illegally is probably greatly overstated. At least, as I understand things.
...that a good way to fight this would be for every single government IT worker to follow this law TO THE LETTER! "Sorry boss... can't do that anymore... here's why." When the lawmakers can't get their email and have their security breached because their own people didn't have the tools to do the job, maybe they'll see some sense. And, of course, if they fire you because you wouldn't do something illegal, that's probably a big settlement coming your way...
But small children will choke on 0's.
Won't someone PLEASE think of the CHILDREN????!!??
I'll never make that mistake again, reading the experts' opinions. - Feynman
I grew up in the 70s in London when the IRA were fairly routinely blowing stuff up. At no stage did anyone suggest compulsory ID to deal with this. Mainly the bins were taken off the trains and eventually a 'ring-of-steel' (meaning police checkpoints at increased presence) around the City Of London (our Wall St). Then somehow by the end of nineties we had become the most surveilled people on Earth.
Post 911 the talk of terrorism never went away. And then 7/7 came along and the paranoia and suspicion just went sky-high. Now we too lived in a country where any change of law could be carried off with the mere mention of the T-word. (Either that or the other one, the P-word, the Glitter-crime). This year Blair has is own little version of the Patriot act coming into force, one where he can issue laws without recourse to Parliament as long as they don't include tax increases or a prison penalty greater than 24 months.
Electronic sniffers are be trialed on a few parts of the underground smelling for explosive traces and there is a scheme in planning for a countrywide network of number plate recognition cameras recording all vehicles on a gigantic DB. Most London Transport users use RFID (oyster) in replacement for the old tickets and all this data is recorded. We will have RFID national ID soon at a cost of around £90 per person, compulsory. I could go on but here's a link or two to go on with.
http://www.no2id.net/
http://www.indymedia.org.uk/en/
So, as Orwell (real name: Eric Blair) predicted, we really are heading for a BB state. It's obvious that the UK is the USs puppy dog and we are in the 'endless' war just as long as you are. Really the UK is just another state of the USA. Maybe even quite a powerful and important one at that.
There is a saying in England "Watch America that's what here will be like in 10 years time" - now it seems we've just about caught up or even exceeded what's going on in the US.
spoonerize "magic trackpad"
See, Perl isn't hard to debug at all!
Presidential Aide: Great news, Mr President!
President George Bush: I get to play Dumbledore in the next Larry Potter movie?
Presidential Aide: Ah, no, Sir, no, not from Warner Brothers; we still haven't heard back from them yet, Sir, no. It's from the U.N. Our weapons inspectors are going in.
President George Bush: And why should I be interestificated in that?
Presidential Aide: Because we need a report, Sir, before we invade Iraq.
President George Bush: No we don't! Besides, we're not invading Iraq. We're invading Tiraq. Take a look at the survalence pictures.
Presidential Aide: Sir... Sir, that's not 'Tiraq', that's 'Tie Rack'; it's a store in Britain that sells ties.
President George Bush: That's just what they want you to think. You see, they're called 'Tie Rack', but they also sell cufflinks and underpants. And are we meant to acceptify that it's mere coincidenecification that they lurk in every airport and rail station.
Presidential Aide: Sir, if we invade Tie Rack, you're going to be a laughing stock.
President George Bush: You mean I have a choice?
Note that this is exactly like banning guns because "someone can use them to commit a crime".
And yes, that's INSANE!
Whatever you say - 150-200 years ago people were as used to having a gun or being able to shoot their own bottles as we are to being able run perl or test an exploit on our own machines. Arguable the former was even more common!