Skip to main content

Proceeding contribution from Lord Bhattacharyya (Labour) in the House of Lords on Friday, 10 October 2008. It occurred during Debate on select committee report on Internet: Personal Security (S&T Report).


Internet: Personal Security (S&T Report)

My Lords, this is an enormously important topic and one on which the well-being of a great number of companies and families rests. The effectiveness of the report and what has been said is shown by how far the Government have travelled since their first response last year. For this contribution, the noble Lord, Lord Broers, and all the members of the committee deserve the thanks of all of us who are concerned about data security in this interconnected age. As a society we are becoming increasingly dependent on technology, particularly the internet and communications networks; we use them at home, at work and throughout commerce and Governments across the globe. Risk, however, is less tangible in cyberspace. People know what it means to lock their front doors, but they do not have the same knowledge of what to do when online. It is not intuitive, we cannot use the senses upon which we depend in everyday life to help us. For example, a large online gambling company was recently discovered to have had ““super-users””. Certain players were able to win large sums at poker by knowing the cards that their opponents held. As those who are familiar with card games will recognise, that is a significant advantage. It became public knowledge only because customers of the company became aware of unusual play by such super-users. This triggered an online investigation by members of the internet forums and, as a result, the company concerned has so far repaid some $6 million to consumers who lost money on its site. There are some interesting lessons here. First, the company was incorporated under the jurisdiction of a Canadian Indian tribe, the Kahnawake. The company was a respected and trusted brand. It was regulated in the same way as its competitors, and the consumer’s only regulatory remedy was through the Kahnawake gaming commission. That is not satisfactory, to say the least. Millions were effectively stolen, and yet there is no clarity about who benefited or where the money went and no data trail on who lost out. Most remarkably of all, after having announced that their software contained holes that allowed the winning of millions of dollars through underhand means, the sites concerned are still trading and still prospering. We require a multi-layered approach to addressing these problems. That will involve building technology of higher integrity which is not pervaded by vulnerabilities to be exploited by those with malicious or criminal intent. But this will always occur. No matter how many safeguards you build in, there will always be someone with criminal intent. In turn, this means that we must make security solutions easy to use, not so difficult that users simply turn them off because they are unaware of the protection that they offer. The final step is to provide the necessary regulation and checks and balances so that we can deter misuse. The report used the helpful analogy of the road networks to describe a shared burden of responsibilities. It makes the key point that while great responsibility rests with the road users, their safety also relies on those who design and maintain the road network, with its signs, lines and markings. Online, I am concerned by the lack of security education on the part of software and hardware developers, business managers, civil servants and all those who have to interact with digital information. I believe we need to investigate the programmes developed by the United States; it has made it a priority to develop centres of national excellence to provide a framework and guidance for students and institutions in information assurance education. Consider the road example again: we provide awareness campaigns on specific issues and education on principles through driving lessons. Very little work has been done to understand how the computer user comprehends the risk that they are taking and what their actions or inactions actually mean. Alongside dealing with the problems of today, now is the time to design in security for the future. Traditionally, research on e-security has been focused on specific solutions for individual problems which results in individual products for each problem. Security solutions have followed only after the discovery of security gaps, so we have had firewalls, anti-malware programmes, anti-phishing measures, and so on. This is not scaleable and is limited in effectiveness since we only respond as we encounter problems, as opposed to proactively planning security for the future. We are now developing the networks and services for the next wave of technologies. We should not make the same mistake of failing to design in security from the start. With advances in mobile communications, we could soon be connected wherever we are and whatever we are doing, as noble Lords have said. Access to information and services via the internet will be as necessary as water and electricity. The increasing number of devices that will store and hold our information also increases the potential threat to our security and even our personal safety. Consider mobile healthcare in the future: tomorrow’s pacemakers might be part of an integrated body area network able to transmit patient healthcare data to doctors and allow them to modify patient treatment. With researchers already developing wireless attacks on current pacemakers, it is easy to see how this more complex internet-connected system raises concerns not only about data privacy but the potential for risk to patient safety. In other words, we will need to prevent new technologies and systems being attacked, and we cannot afford to wait for failures in order to plan our protection. We need to understand the changing threat and how to manage our risks dynamically and in response to it. We need to consider how to build systems to tolerate intrusions while still offering degrees of security, not have them fail. We need to develop technologies to allow individuals to have meaningful control over their information and online activities while still maintaining accountability. We need to provide tools to reduce and remove vulnerabilities and holes in our systems. We need to design the interfaces and controls of security technologies so that they are easy and intuitive to use, and so more effective when deployed. These are just a few examples of technological responses that must be researched now if they are to succeed. I welcome the decision of EPSRC and the Technology Strategy Board to invest in a range of projects on data security and privacy, but I believe that this can only be the beginning of such interdisciplinary research objectives. In the short term, we can focus on the current risks and make users aware of these and the techniques needed to keep them safe online. Raising consumer awareness to the dangers helps stimulate the adoption of the products and service which offer safety. At the same time, regulation has its place to play, and without teeth to remove business contracts, fines and penalties, business may decide that a lack of protection for their users’ data is a risk worth taking. The penalties have to serve as a deterrent to businesses that fail to act as well as the criminals who wish to take advantage of their weaknesses. This has to be an international effort—I cannot see it happening within our national boundaries alone. I hope that following the judicious use of the carrot and the stick by the committee, the Government will ensure that a similar carrot-and-stick approach to regulation is a high priority in the European and global forums, in which this issue must ultimately be resolved.


Secondary information

Type
Proceeding contribution
Reference
704 c468-70 
Session
2007-08
Chamber / Committee
House of Lords chamber
Subjects
Data protection Crime Banks Computers Credit cards Fraud Internet Personal records Police Security Internet service providers
Link
View this Proceeding contribution on www.publications.parliament.uk