Skip to main content

Proceeding contribution from Earl of Northesk (Conservative) in the House of Lords on Monday, 30 January 2006. It occurred during Debate on bill on Identity Cards Bill 2005-06.


Identity Cards Bill

My Lords, it may be of convenience to the House if I could speak in this group to Amendment No. 100, which proposes the deletion of Clause 31. None of us questions the desirability of maintaining the security and integrity of the register. At first blush, therefore, the inclusion of the clause to deal with the possibility of its being tampered with is both sensible and welcome. But, in reality, the way in which it has been drafted creates all sorts of problems. I shall turn to those in due course. First, it is important, so far as we can, to understand the IT architecture that the Government are contemplating. As the noble Lord, Lord Bassam, told us:"““The national identity register is not physically connected to the Internet or any publicly available network””.—[Official Report, 16/11/05; col. 1105.]" I can understand that. Clearly, and sensibly, the intention is that the scheme should operate via closed and secure servers. But we also know—because the noble Lord, Lord Bassam, has told us and, indeed, the noble Baroness, Lady Scotland, confirmed it last week—that facility will exist for individuals to access their records on the register via the Internet. I can understand that too. Presumably data will be uploaded to firewalled gateway servers, which will, in turn, access the secure register servers to submit the revised information or, indeed, for verification and validation purposes. In fact, as envisaged by Clauses 11 and 19 to 23, there will be a myriad of such gateways, not least to satisfy the law enforcement and national security purposes of the scheme. To that extent, therefore, it will probably be more accurate to say that the register will be ““connected”” to the Internet, albeit virtually rather than physically. That relates back to the point that I made earlier in respect of DNA data, but, again, I am not going to go down that path. Unfortunately, so far as I understand it, Clause 31 creates only the offence of tampering with the register; it does not provide any protection for these gateways. That is crucial because, in effect, they are likely to be the weakest and least secure links of the design. To illustrate the point, we can consider so-called ““denial-of-service”” attacks. In effect, the gateways could be rendered inoperable by any given DOS attack, thereby compromising the register itself. Yet, as I read the clause, such a circumstance would not necessarily be covered by the current drafting. The Government may wish to argue that the provisions of the Computer Misuse Act offer adequate protection in this regard—something about which I and many others have expressed concern for some years. The Minister will know only too well that the view that the CMA provides adequate coverage is a very long way from being universally shared. Indeed, we have to approach its applicability to DOS attacks with healthy dollops of scepticism, not least because of the judgment a month or so ago in Wimbledon magistrates’ court. Be that as it may, Clause 31 would appear in part to have been drafted to protect the register from such attacks, although, as I have already implied, I am far from convinced that the current drafting offers very much protection. Yet, in respect of all other governmental databases, it is argued that CMA is robust enough to be proof against such attacks. In her letter of 11 January—again, I express my gratitude to her for it—the noble Baroness correctly identifies that the provision in the Bill goes further than Section 3 of the CMA. Nevertheless, it strikes me as odd that the clause increases the penalties for unauthorised modification of information on the register while penalties for attacks on law enforcement IT systems or other elements of the critical national infrastructure system—air traffic control, hospital support systems and so on—remain consistent with the CMA. I do not decry the evident intent to secure the data on the register against attack—indeed, at many levels I welcome it—but can it really be said that it is that much more important a system than, say, the police national computer or the national health data spine, where, should their operation be compromised, a welter of life-threatening situations could develop? The Minister might like to imagine that the Police and Justice Bill, introduced in another place last Wednesday, offers adequate rebuttal to my comments here. On the face of it, Clauses 33 to 36 of that measure would appear to represent the much-needed update of the CMA. However, I am bound to say that Clause 35, intended to criminalise the development, distribution or possession of so-called ““hacker tools””, is especially asinine—not least because very few of these do not have entirely valid and legitimate uses. Moreover, the fact that these clauses effectively replicate the drafting of Clause 31 of this Bill, giving the appearance of having been added almost as an afterthought, adds weight to my argument. Surely a more appropriate way forward here would be to update the CMA properly rather than, on the one hand, singling out the register for this preferential treatment and, on the other, seeking to rely on the decidedly suspect drafting of the Police and Justice Bill. Indeed, viewed from an alternate perspective, if, as the Government have previously maintained, the CMA is an adequate measure to deal with the problem of DOS attacks generally across their IT infrastructure, or if it is supposed that Clauses 33 to 36 of the new Bill update the CMA appropriately, what useful purpose is therefore served by including this clause at all? As we have already experienced today, in defending amendments that seek to write elements of data protection into Bills, Ministers never tire of telling us that to do so would be otiose because such extant legislative provision has efficacy in any event. Viewed logically, the same could be said of this clause in respect of either the CMA or the Police and Justice Bill. But, as I have already implied, this is not the clause’s only problem. Subsection (3)(b) is particularly troublesome. In terms, it defines ““unauthorised modification”” of data on the register as ““conduct”” which,"““makes it more difficult or impossible for such information to be retrieved in a legible form . . . or contributes to making that more difficult or impossible””." A host of wholly innocent circumstances could occasion such an event. For example, it is not unheard of for systems to crash when being subject to routine maintenance or updating. The House will no doubt recall the recent occasion involving 60,000 desktop computers at the Department for Work and Pensions. Is it really the intention that IT contractors servicing government computers should be criminally liable simply for making a mistake, or are civil servants to face prosecution for going on strike? What, too, of forensic hacking—possibly the most effective method of properly testing the parameters of an IT system’s security and integrity? It seems to me that these are all circumstances that, notwithstanding the qualification of ““requisite intent”” at subsection (1)(b), could fall foul of the drafting at subsection (3)(b). As I have already indicated, I am fully aware of the contents of the letter of 11 January from the noble Baroness. It offers various reassurances about some of the issues that I have raised. While I suspect that a difference of opinion between the Government and myself will persist in respect of the Computer Misuse Act, none the less I should be extremely grateful if, for avoidance of doubt, the Minister could put on the record the interpretation of the scope of subsection (3)(b) contained in her letter when she comes to reply. Certainly that would assuage many of my anxieties about the clause. With that in mind, I look forward to her response.


Secondary information

Type
Proceeding contribution
Reference
678 c63-5 
Session
2005-06
Chamber / Committee
House of Lords chamber
Subjects
Complaints Disability Disclosure of information Data protection Databases Codes of practice CCTV Biometrics Costs ICT Genetics EU law Identity cards European communities Internet Ethnic groups Personal records Public appointments Photographs Nationality National identity register Proof of identity Passports Prescriptions Registration Surveillance Hacking Office of the Identity Commissioner Driving licences Transgender people
Legislation
Identity Cards Bill 2005-06
Link
View this Proceeding contribution on www.publications.parliament.uk