Home Office demands massive cybersecurity overhaul

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The government has warned that police and law makers need to step up their efforts to fight crime on the Internet.

A Home Office report called "The Future of Netcrime Now", which it began work on two years ago and published last week, said that police need to try and get ahead of the growing problem of cybercrime if they are to successfully tackle it.

The report stated: "The continuing emergence of new opportunities for offending requires a broadening of the parties involved in tackling such problems; hence policy makers and law enforcement must continue to gear up, building relationships with the kind of individuals and organisations recruited for this research so as to remain abreast, if not ahead, of the criminal threats and challenges we continue to face."

The Home Office did not respond for comment on the report in time for this article, but sources say that the author behind it has moved on from Home Office cybersecurity research team. According to reports, the Home Office asked the last survey question in February 2003 -- suggesting the reports findings could be at least a year old.

The report said that seven out of the top ten problems on the Internet related to online paedophilia groups, and that technology was providing more opportunities for crimes such as spying and piracy.

"The combination of the Internet and global retailing now paves the way for such rapid and wide dissemination of new technology that unpredictable negative consequences do not just locally emerge but often explode onto the global environment. Such a rapid emergence of new criminal tools or opportunities can lead to what has been termed a 'crime harvest', as offenders reap the new found criminal opportunity before it is closed," said the report.

It added that police could soon be forced to play a similar game of catch-up with crime as software vendors face today when they are required to reactively patch vulnerabilities in their software.

"The lag between offender first move and defender response is what one must seek to reduce or even close. Unfortunately, in terms of software vulnerabilities, the lag is moving in the offenders' favour, as the time delay between the discovery of a vulnerability (by various sources) and its exploitation by offenders is narrowing, giving less time for the vendor to produce and distribute the patch. What is one to do in light of the increasingly complex and rapid development of information and communications technology which is often accompanied by criminal opportunities?"

The report criticised British banks' security practices, stating that they needed improved measures to protect their customers from crime. Unlike some banks in Scandinavia, British banks have failed to implement two-factor authentication technology, such as RSA's SecureID, for Internet banking, despite calls from former White House cyber-security advisors Howard Schmidt and Richard Clarke to do so. Clarke said that online banking transactions cost just half of one percent of a physical transaction.

"Organisations such as online banks are only recently getting to grips with how they inform their users of threats such as the use of fake emails and bank Web sites. They, along with numerous other providers of online goods and services, need to review the security of their offerings, the secure practice information they give customers, and put in place rapid response measures when a vulnerability of some kind is exploited by adaptive criminals," said the Home Office's report.

The Association for Payment Clearing Services (APACS), which represents the banking industry, said last month that no decisions had been taken to go ahead with two-factor despite the rise in phishing attacks.

"The fact is it's a massive undertaking," said Tom Salmond, a managing consultant in the e-banking fraud liaison group at APACS. "It's under active consideration, but no decisions have been made at this time."

The Home Office report makes several recommendations to improve Internet and cybercrime policing in general. It said that 'netcrime' investigative techniques should be integrated to work with physical investigation practices, and that there should be a co-ordinated intelligence gathering exercise to examine organised crime on the Web.

The National Hi-Tech Crime Unit, which is dedicated to fighting organised hi-tech crime, was unavailable to comment on this issue at the time of writing.

The report also said that efforts should be made to remove or disrupt the availability of malicious Internet tools and that every police officer should be given a basic level of anti-cybercrime training. Earlier this year Centrex, the organisation that provides anti-cybercrime training, saw its budget cut by 30 percent. It said that cuts were not just applicable to training in computer investigations.

The police could begin employing private companies to handle digital forensics work, the report said. "Possible solutions include the outsourcing of such examination to a suitable third party and the use of police staff specialists rather than officers to undertake such forensic recovery." It added that police forces needed to allocate resources to for specialist officers to receive relevant cybercrime training. Last month, the Association of Chief Police Officers said police forces were facing a £350m shortfall in budgets from struggling to juggle funds because of new responsibilities, such as fighting cybercrime.

The report also hinted that police could employ the skills of people with questionable backgrounds. "Law enforcement and other agencies must be creative in identifying additional skilled individuals to support netcrime investigations."

The report backed suggestions from European security lobbyist EURIM that the UK needs to have a facility to report cybercrimes. It said that the government needed to launch a 'safe and legal surf' awareness campaign to children to make them aware of the penalties for illegal activity.

The report surveyed 53 security experts.

Talkback

Liability might provide an answer.

Think about it. When vendors, solution providers, service providers, consultants, advisors, teachers, decision makers, etc etc would have more liability then the risk of not doing things securely right from the start would be a higher risk then not doing things securely.

That could in turn stop advisors from advising unsecure things. Stop implementors from implementing unsecure things. Stop providers from providing unsecure things. Stop decision makers from deciding for unsecure things. Stop teachers from teaching unsecure things. And as a result stop vendors from producing unsecure things.

Geez. If everyone was advised to carry loaded guns. And everyone was teached to use loaded arms for, say, securing your way of life. And everyone was provided loaded guns then pretty soon everybody would walk around with loaded guns. Next thing you know people start complaining how unsafe the streets are and anyone can get gunned down while minding their own business. Well duh.
If you didn't see that one coming then maybe now you understand why I need to drive around in a tank these days. Makes for easy parking though.

What wouldn't work would be to give, say, the police more powers. Simply too many guns that are too easy to get and too few policemen out there to deal with the problem at hand. Ask the US.

via Facebook 13 December, 2004 22:24
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 hour ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

4 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

6 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

11 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

14 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

15 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

16 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

17 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

18 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

18 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

18 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

18 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

19 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

22 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA