Skip to main content

Proceeding contribution from Tom Harris (Labour) in the House of Commons on Tuesday, 12 July 2005. It occurred during Debate on bill on Computer Misuse.


Computer Misuse

That leave be given to bring in a Bill to amend the Computer Misuse Act 1990; and for connected purposes. In moving this motion, may I first of all pay tribute to the work undertaken by the all-party group on the internet, which carried out a thorough review of the Computer Misuse Act 1990, and whose recommendations form the basis of the Bill that I present today? I want particularly to thank my hon. Friend the Member for Sittingbourne and Sheppey (Derek Wyatt). He presented a similar Bill to the House in March of this year, but in the end it was defeated by the timetable for the general election. My Bill will revise the 1990 Act to take account of commitments made in European instruments in respect of combating and effectively punishing attacks against computers, and it will update the Act in other areas. It will amend section 1(3) to increase the term of imprisonment for a related offence from six months to two years. It will amend section 3(7) to increase the term of imprisonment for a further related offence from five years to 10 years. It will amend section 3 in order to clarify that all means of interference with a computer system are criminalised. And in particular it will ensure that adequate provision is made to criminalise all forms of denial-of-service attacks. It will also give effect to article 6(l)(a)(i) of the convention on cybercrime, which requires criminalisation of the distribution of, or making available of, a computer password through which a computer system is capable of being accessed, with intent to commit an offence. This Bill will, I hope, meet with the House's approval. It contains only six clauses, has no financial implications, implements measures that have been approved by Ministers and Parliament and is, I hope, relatively simple. As last year's report by the all-party group on the internet demonstrates, these measures already have cross-party support. I trust this will remain the case after I finish my speech. As the report pointed out and as every Member of this House will doubtless accept, the worldwide web has changed out of all recognition in the past 15 years, as has the nature of cybercrime. The media like to imagine that hacking, virus proliferation and denial-of-service attacks using e-mail are the product of bright but lonely and socially challenged teenagers sitting in their bedrooms. That is an outdated, inaccurate and, I think, dangerous notion. Those who regularly and increasingly hold website operators to ransom are more likely to be members of an organised crime syndicate than the school computer club. It is time that cyber crime was recognised for the serious crime that it is. Following the recent sentencing of teenager Joseph James McElroy to 200 hours of community service for breaking into a US Government laboratory system, detective chief superintendent Len Hynds, the former head of the national hi-tech crime unit, called on the Government and the courts to reform sentencing policy 12 Jul 2005 : Column 700 to reflect the damage caused by hackers breaking into government and private sector computer systems. He said: "The internet has grown up and we need to say to people who think its fun to rifle through people's private files that they are actually committing a crime". My Bill seeks to specify a new offence of denial of service. A denial-of-service attack occurs when a deliberate attempt is made to stop a computer performing. Examples include attempts to flood a network, thereby preventing legitimate network traffic; attempts to disrupt the connections between two machines, thereby preventing access to a service; attempts to prevent a particular individual from accessing a service; and attempts to disrupt services to a specific system or person. Denial-of-service attacks can essentially disable one's computer or one's network. Some denial-of-service attacks can be executed with limited resources against a large, sophisticated site. For example, an attacker with an old PC and a slow modem may yet be able to disable much faster and more sophisticated machines or networks. One form of such attack could mean a large number of remote computers being orchestrated to attack a target at the same time. In some cases, the attacks overwhelm the connecting links to a machine rather than the machine itself. That can result in significant collateral damage that extends beyond the machine being attacked. Denial-of-service attacks are extremely common on today's internet. At the lower end of effectiveness, the blips in traffic are hardly noticeable, but we are told of cases at the other end in which large university networks have been made unusable for hours at a time. The chief constable of Greater Manchester, Michael Todd, was bombarded with thousands of threatening e-mails in a denial-of-service attack shortly before the May Day bank holiday this year. At one point, 2000 e-mails were being sent every hour. The purpose of the attack was to crash the force's computer systems through the volume of e-mails being sent. Cambridgeshire police were subject to a similar denial-of-service attack almost two years ago, when thousands of spam e-mails told recipients that their credit cards were about to be charged for an iPod that they had purchased unless they phoned a customer service number. The customer service number turned out to be the switchboard at Cambridgeshire police, which was deluged by thousands of people who had received the hoax e-mail. Closer to home, a gun control website contacted me two years ago to complain that one of my constituents, a gun enthusiast, had bombarded the site with so many e-mails over a short period of time that their server had crashed. The Computer Misuse Act 1990 came into force on 29 August 1990 and specifies offences for attacks against computer systems or data. Criminal denial-of-service attacks are regularly made on gambling websites both in the United Kingdom and elsewhere. Such attacks are invariably accompanied by demands for amounts between £10,000 and more than £100,000 in order to make the attacks stop. The impact on gambling businesses has been severe. The national hi-tech crime unit has become involved in the investigations, but the perpetrators are believed to be based abroad, which sets some limits on what can be achieved quickly. 12 Jul 2005 : Column 701 The second part of the Bill deals with the length of sentences. At present, offences under section 1 of the Computer Misuse Act 1990 can be dealt with only in a magistrates court, where the maximum penalty is six months in prison and/or a fine of £5,000. A conviction in a higher court currently applies only to offences defined in sections 2 and 3 of the Computer Misuse Act. In those cases, the maximum penalty is five years in prison or an unlimited fine. By increasing the tariff on these crimes, the House would be sending a message to the courts and the public prosecution service that these crimes must be taken seriously and that, where appropriate, custodial sentences must be applied. Home Office figures show that, when an offence under the Computer Misuse Act is the principal offence with which someone is charged, only about a third of those found guilty are given custodial sentences. When such an offence is not the principal offence, the proportion is very small indeed. It is regularly claimed that the cost of cleaning up virus or worm attacks runs into billions of pounds. The current level of sentences does not reflect the seriousness of such offences. This Bill would therefore raise the maximum sentence for a conviction under section 1 of the 1990 Act to two years. That would have a number of indirect benefits. It would make an offender subject to extradition procedures, and also make it possible to prosecute for a criminal attempt, even where such an attempt had not succeeded. Before I conclude, I wish to draw the House's attention to a recent NOP survey conducted on behalf of the national hi-tech crime unit. It estimates that the minimum cost of the impact of high-tech crime on UK-based companies with more than 1,000 employees is no less than £2.5 billion every year. As the worldwide web grows both in size and in its influence on all our daily lives, the threats posed to all of us by cybercrime also grow. Although high-profile denial-of-service attacks have been made against e-commerce and, especially, gambling sites, the UK Government and the country's critical infrastructure are also vulnerable. It is essential that we have a law in place to make prosecution possible when offences are committed, because that will send the strong and unambiguous message that e-crime will be treated with the utmost seriousness. I commend the Bill to the House. ------------------------------------------------------------------------


Secondary information

Type
Proceeding contribution
Reference
436 c699-701 
Session
2005-06
Chamber / Committee
House of Commons chamber
Subjects
Crime prevention Crime Computers Convictions Computer networks Fixed penalties Fines Prosecutions Sentencing Computer viruses Hacking
Legislation
Computer Misuse Bill 2005-06
Link
View this Proceeding contribution on www.publications.parliament.uk