Plan to extend police-hacking powers gathers pace

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The UK government has agreed to work with the European Parliament on plans to extend police powers to conduct remote searches of computers.

The European Union Council of Ministers approved a plan in November 2008 to grant law-enforcement authorities in member states the power to perform remote searches of suspects' computers, as well as to perform 'cyber patrols' of the internet and increase data sharing between European police forces. The plan, to be implemented within the next five years, raises the possibility of cross-border co-operation on cyber investigations.

The Home Office said on Monday that it has decided to participate in the further formulation of the European Parliament plans, but that no timetable or detail for the proposals had been settled.

"The UK has agreed to a strategic approach towards tackling cybercrime on the same basis as all member states; however... the Council conclusions are not legally binding, and there are no agreed timescales," the Home Office said in a statement. "We fully support work to develop an understanding of the scale and impact of electronic crime across the EU and will work with member states to develop the detail of the proposal."

According to Richard Clayton, a Cambridge University computer security expert, it has been legal for the police to hack into suspect systems without a warrant since 1995, when a 1994 amendment of the Computer Misuse Act was brought into force. Remote warrantless searches of computers are also legal under part three of the Police Act 1995, and under parts of the Regulation of Investigatory Powers Act 2000.

Clayton told ZDNet UK on Monday that the most likely method for UK police to hack into computers was to enter a premises and install a keylogger on the target system. This would be more reliable than a drive-by download or "sending an email with a dodgy attachment", as the chances of successful interception of data were higher, said Clayton. Alternatively, police could hack Wi-Fi networks to gain access to systems, said the computer security expert.

"The police could sit outside the door, search for the Wi-Fi network, break the WEP or WPA encryption key and look at the contents of the hard drive," said Clayton.

The Association of Chief Police Officers (ACPO) said that between 2007 and 2008 there had been 194 warrantless searches performed by the police, but an ACPO spokesperson was unable to confirm at the time of writing how many of those searches had been of computers.

To perform a warrantless search, the police need the approval of a chief constable — no judicial oversight is necessary. However, according to an ACPO statement, the police should also in some circumstances seek the approval of the surveillance commissioner, except in an emergency.

"To be a valid authorisation, the officer giving it must believe that when given it is necessary to prevent or detect serious crime and action is proportionate to what it seeks to achieve," said the ACPO statement.

Privacy campaigner Simon Davies, director of Privacy International, called on the Home Office to reform the warrant process so remote searches of computer systems have judicial oversight.

"That level of intrusion is more intrusive than telephone interception," Davies told ZDNet UK. "Frankly, the entire warrant system needs to be overhauled."

Davies said that there was a danger that an EU-wide system of remote searches could open the UK to requests for remote warrantless searches of UK computers by law-enforcement authorities from other member states.

"That would open a whole Pandora's box," said Davies. "Any EU government that wanted to could invade the privacy of the British people."

Talkback

Forgive me and my American sentiment - Warrantless searches are among the reasons why the colonies broke away from Great Britain.

Are you folks asleep?
Can you not read George Orwell's text of 1984 buried in the EU proposals?
Every single legal Government oppression has begun with the police for some safety reason and ended with regular troops enforcing tyrranies.

Good Luck.

jeffreyvelasquez 5 January, 2009 20:41
Reply

It would be interesting to see if its legal to keep them from hacking into your system. Or would having a highly secure home computer system hooked to your cable or DSL line become prima-facie evidence that YOU are a criminal? (Obviously he's got something to hide. Let's go hack into that guy's system to find those naughty pictures so we can put him in jail before he does something EVEN WORSE!)

Assuming that if the police seem to think a suspect is "potentially going to commit a crime" the question becomes what did this potential terrorist or criminal or angry jobless IT nerd do to make the police think that he was "potentially" going to commit a crime?

How much pre-arrest surveillance do the police have to do to figure out that this potential terrorist was going to, at some time in the future, commit such a dastardly act as to merit such warrant-less lack of restraint by the police?

Please notice that you can't use the word "alleged" yet because he/she hasn't DONE ANYTHING ILLEGAL YET!

They made a really bad movie about this sort of thing called "Minority Report" starring the scientifically-challenged Tomas Cruising. I didn't realize that it was a reality-TV script for something that WAS GOING TO HAPPEN IN THE FUTURE!

And I thought the US Patriot Act was bad.

Xwindowsjunkie 6 January, 2009 02:27
Reply

What about when the Police hacked into someones PC.

They then managed to find Child Porn on it.

Coincidence or what?

KJR

334638 6 January, 2009 20:01
Reply

As we've been getting massive doses of lately, public officials aren't above turning corrupt especially when it lines their pockets. Planting evidence can justify a considerable amount of increased funding for the cops and loss of personal freedoms for the public.

Assuming you can hack your way into the system, you can mess with the clock and plant evidence indicating the owner is a criminal of just about any type of your choosing. Most judges are like the rest of the general population and untrained enough to be able to tell if an "IT forensic expert" or a "police security expert" is telling the truth or not.

If you want to scare the people into submitting to even more surveillance, just find some stooges to plant some terrorist manifestos on their laptops or desktops. Go hack back into their computers, find the planted evidence and then go publicize it and taint the entire jury pool. Throw him in jail and when he gets out, Mr Public Official is out of office and retired somewhere overseas.

Xwindowsjunkie 7 January, 2009 04:45
Reply

I can't help thinking that an experienced lawyer would make an effective case for having such material dismissed as potentially tainted evidence.

If they had to modify your computer remotely to obtain access, then there absolutely no way anyone could subsequently tell the source of any material then found on the machine.


Hmmm. Expect an upturn in the sales of W.O.R.M. drives.

Tezzer 7 January, 2009 15:08
Reply

We do need to improve our IT security from cybercrime, but shouldn't we be looking at other ways.

Either way, hacking is not legal for any of us - if I hacked into them they wouldn't like it. I'd be banged up..

The police is an invented organisation, they should NOT have the power to just delve in remotely onto our computers. They are OUR machines and we should be permitted to do what we like.

However where I do think we need changes is the Internet. We do need to improve fraud issues, viruses, terrorists.. but there's other ways than hacking our computers. I dont have a problem with ISPs keeping my traffic for a couple of years. I don't trust the government with that data and I think ISPs should say:

We've had a complaint about some traffic on ---- date, and we need to comply with the authorities.

This data will be disclosed to you in writing and passed to the government.

Then we should be able to see what was sent and then if we feel it's wrong we can justify it and complain. However, if this amount of expense and trouble is going to be required the average cop can't bugger about. Just an idea. But I wont tollerate hacking.. that's just wrong.

gareth25 7 January, 2009 22:54
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

6 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

6 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

6 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

12 hours ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

12 hours ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

15 hours ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

23 hours ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

1 day ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

1 day ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

1 day ago by apexwm on Ten flawed products that derail productivity
Paul Hutchinson

Absolutely - this should obviously not be handled my isp - but handled by their hosting operator. What's been suggested here is that my isp police...

1 day ago by Paul Hutchinson via Facebook on MPs urge ISPs to take down terrorist material
Techs UK

Looks like a great phone. I don't notice any deficiencies in WP7. used IOS before, that's pretty good. I don't spend much time in Apps, all i need...

2 days ago by Techs UK on Nokia pins US 're-entry' hopes on Lumia 900
Larry Bloggy

Now with the help of these apps you are always synced with MS outlook while on the move. Just download apps like xobni or outlookreflex and get...

2 days ago by Larry Bloggy via Facebook on Outlook Social Connector beta 2 and the LinkedIn connector
mike40g123

Your details are wrong. The version currently being made is the one with 2 USB ports, 256MB RAM and a network port. This is the Model B. The...

2 days ago by mike40g123 on Raspberry Pi boards set to go on sale
Moley

The thing that has been puzzling me for quite a while is how Anonymous can remain anonymous whilst not only being active on the Internet but also...

2 days ago by Moley on Anonymous activists release PCAnywhere source code
Don Dilly

If what Semantec is saying is rue, that is even worse and shows a complete disregard for thier users. If what Anonymous claims is true and the...

2 days ago by Don Dilly via Facebook on Anonymous activists release PCAnywhere source code
MattChurchy

Didn't seem particularly biased to me either. Oh though you might have mentioned some other competitors with free search and email services...

3 days ago by MattChurchy on Time for an evil umpire: Google, Microsoft & privacy
Simon Bisson and Mary Branscombe

James - exactly as much as anyone paid you for your comment; I don't feel that I need to say that I'm independant and unbiased, but just for you...

3 days ago by Simon Bisson and Mary Branscombe on Time for an evil umpire: Google, Microsoft & privacy
Carl White

Once they realise symantec are willing to pay real money, they will simply keep extorting, unless of course symantec/authorities can use the...

3 days ago by Carl White via Facebook on Symantec offered hackers $50k in source code sting
Jonathan Hassell

You can find more information on BS 8878 by Jonathan Hassell its lead-author at http://www.hassellinclusion.com/bs8878/ The page includes a...

3 days ago by Jonathan Hassell on BSI publishes first British web accessibility standard