On the cyber beat
By Tom Espiner
Published: 5 January 2009 16:53 GMT
The UK government has agreed to work with the European Parliament on plans to extend police powers to conduct remote searches of computers without a warrant.
The European Union Council of Ministers approved a plan in November 2008 to grant law-enforcement authorities in member states the power to perform remote searches of suspects' computers, as well as to perform 'cyber patrols' of the internet and increase data sharing between European police forces. The plan, to be implemented within the next five years, raises the possibility of cross-border co-operation on cyber investigations.
The Home Office said on Monday it has decided to participate in the further formulation of the European Parliament plans but that no timetable or detail for the proposals had been settled.
The Home Office said in a statement: "The UK has agreed to a strategic approach towards tackling cybercrime on the same basis as all member states; however... the Council conclusions are not legally binding, and there are no agreed timescales.
"We fully support work to develop an understanding of the scale and impact of electronic crime across the EU and will work with member states to develop the detail of the proposal."
According to Richard Clayton, a Cambridge University computer security expert, it has been legal for the police to hack into suspect systems without a warrant since 1995, when a 1994 amendment of the Computer Misuse Act was brought into force. Remote warrantless searches of computers are also legal under part three of the Police Act 1995, and under parts of the Regulation of Investigatory Powers Act 2000.
Clayton told silicon.com sister site ZDNet UK on Monday that the most likely method for UK police to hack into computers was to enter a premises and install a keylogger on the target system. This would be more reliable than a drive-by download or "sending an email with a dodgy attachment", as the chances of successful interception of data were higher, said Clayton. Alternatively, police could hack wi-fi networks to gain access to systems, said the computer security expert.
"The police could sit outside the door, search for the wi-fi network, break the WEP or WPA encryption key and look at the contents of the hard drive," said Clayton.
The Association of Chief Police Officers (Acpo) said that between 2007 and 2008 there had been 194 warrantless searches performed by the police but an Acpo spokesperson was unable to confirm at the time of writing how many of those searches had been of computers.
To perform a warrantless search, the police need the approval of a chief constable - no judicial oversight is necessary. However, according to an Acpo statement, the police should also in some circumstances seek the approval of the surveillance commissioner, except in an emergency.
The ACPO statement said: "To be a valid authorisation, the officer giving it must believe that when given it is necessary to prevent or detect serious crime and action is proportionate to what it seeks to achieve."
Privacy campaigner Simon Davies, director of Privacy International, called on the Home Office to reform the warrant process so remote searches of computer systems have judicial oversight.
Davies told ZDNet UK: "That level of intrusion is more intrusive than telephone interception. Frankly, the entire warrant system needs to be overhauled."
Davies said there was a danger that an EU-wide system of remote searches could open up the UK to requests for remote warrantless searches of UK computers by law-enforcement authorities from other member states.
"That would open a whole Pandora's box," said Davies. "Any EU government that wanted to could invade the privacy of the British people."
Original article: Plan to extend police-hacking powers gathers pace from ZDNet UK
Does the term "innocent until proven guilty" mean ...
drew stephenson
Its bad enough the police having the right to hack...
Anonymous
Well if they can do that I should be able to ethic...
Richard Davies
Does the term "innocent until proven guilty" mean ...
Guy Reynolds
No Drew
Not a damn thing!
Anyway our lords and ...
Galleyslave
Law enforcement or investigative experience is highly desirable. Perform comprehensive technical analyses and interpret computer related evidence on ...
C C++ Senior Software Test EngineerOur client is looking for a Senior Software Test Engineer to test and debug software for wireless communication ...
If you are a non-EU citizen, please state your eligibility to work within the EU. Healthcare We currently have an exciting vacancy for a bright ...
Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath
Next stop HMRC: How TfL CIO will shake up the taxman
Interview: Phil Pavitt, CIO Transport for London, on making IT boring
Gary Bettis
Public sector CIOs: It's your time to shine
Comment: Efficiency programme offers big challenges and opportunities
Gary Lynch
How e-coding can prevent NHS slip-ups
Barcodes to run in their blood
silicon.com
Inbox: Chip and PIN latest big IDea - and still no readers
"PIN numbers do not present much of a challenge to a determined crook"
Jo Best
From army officer to IT chief - CPS CIO David Jones
Profile: What IT and the military have in common
silicon.com
Inbox: Government IT ignoring red lights?
"The civil servants who specify these projects are not competent technically"