Skip to main content

Proceeding contribution from Lord Birt (Crossbench) in the House of Lords on Friday, 10 October 2008. It occurred during Debate on select committee report on Internet: Personal Security (S&T Report).


Internet: Personal Security (S&T Report)

My Lords, I declare an interest as a director of PayPal Europe. I applaud the diligent and painstaking work of the noble Lord, Lord Broers, and his committee, an example of the House of Lords working at its very best. E-crime on the scale which we now see it has emerged only during the past four or five years. Before that, it was mainly a few geeky kids showing off; now we face a massive and sustained criminal attack. Many millions of emails are sent on phishing expeditions, aiming to trick the innocent into revealing their security details. Malware is infiltrated, like the creature in ““Alien””, into the inner workings of our PCs to steal our most confidential personal data. Botnets, networks of ill intentioned software robots, can attack and sometimes bring down major and sophisticated entities, and sometimes ransom them. Far worse is surely to come. The losers are not just major merchants offering products and services online and the online payment providers, but many tens of thousands of ordinary individuals who are not always protected from loss. The scale of the economic loss is now enormous. Gartner estimates the current global cost at $3.2 billion, but I suspect that that is a serious underestimate. Who are the perpetrators? Many perpetrators have highly advanced computing skills. Some are lone wolves, who, when they get up in the morning, devote their whole day to internet crime, knowing that they are highly unlikely to be caught. But those anti-fraud experts who have most studied online theft have good reason to believe that as much as 70 per cent of economic crime on the internet is now the work of organised crime syndicates As the noble Lord just said, e-crime is now primarily global, not national. The bulk of syndicates have home bases in Russia—which is interesting for those of us who sat through the previous debate—and elsewhere in eastern Europe and in some other identifiable nations. In all these countries, e-crime syndicates are largely ignored by local authorities. In addition, there is now an emerging black market in services. Botnets can be rented; phishing software can be bought wholesale. How can this growing threat be countered? First, individual consumers and merchants can of course be more savvy and alert, and can be better educated to be so. Secondly, online providers can intensify their work of hardening targets, making it increasingly difficult to commit e-crime. They are developing ever more ingenious means of achieving this. Thirdly, ISPs could stop averting their gaze from manifest criminality. Their technology is sophisticated. They can detect peer-to-peer theft. They can identify which of their customers’ PCs have malware. ISPs can pinpoint the originators of phishing expeditions sending out their millions of ill intentioned emails. But, so far, in the UK and around the world, ISPs have not been inclined to fight crime. Fourthly, government needs urgently to focus on this mushrooming economic threat, yet the UK Government’s first response to the Science and Technology Committee’s report was deeply disappointing—and, indeed, shockingly inadequate, as almost every noble Lord who has spoken in this debate has observed. There is a strong case for regulating and licensing ISPs and for placing requirements on them. A fit-for-purpose national agency is needed in the UK to focus exclusively on every kind of online crime. I know of one instance in which the police will not consider investigating a syndicate operating here in the UK until it has stolen more than £500,000 of goods—and one has almost done that. Imagine if the police said that about bank robbers. Britain’s police have not yet made the psychological shift from the physical to the digital world. I am sceptical that the recently announced unit will be remotely fit for purpose or of the required scale to deal with these problems. Moreover, a global and not just national approach is needed to counter a category of crime that is committed overwhelmingly across national frontiers. Here the UK Government could bring international leadership. In recent days, weeks and months we have seen the calamitous cost to Governments and governance of failing to manage risk in the financial sector. The internet is one of the glories of the age, as I am sure we all agree, with a profound and largely beneficial impact on all our lives. Government needs rapidly to engage with managing the risks arising from the internet’s dark side before a cancer takes hold. As yet, Whitehall, too, has been painfully slow to adjust to new digital realities. Let us hope that the excellent stimulus provided by the Science and Technology Committee eventually bears fruit.


Secondary information

Type
Proceeding contribution
Reference
704 c470-1 
Session
2007-08
Chamber / Committee
House of Lords chamber
Subjects
Data protection Crime Banks Computers Credit cards Fraud Internet Personal records Police Security Internet service providers
Link
View this Proceeding contribution on www.publications.parliament.uk