Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 78 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow UK Data Protection Act
EH-Net
May 25, 2012, 03:40:13 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: UK Data Protection Act  (Read 5350 times)
0 Members and 3 Guests are viewing this topic.
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 857



View Profile WWW
« on: November 14, 2008, 06:07:34 AM »

<Disclaimer: I am not a lawyer>

It's been a long running saga, but the changes to the UK's Data Protection Act are now in force. Similar to the changes in German legislation, the creation, modification or supply of any tool or information that could result in unauthorised access to a computer is now explicitly illegal in the UK.

On top of the standard, and already well argued, debate concerning dual-use tools such as nmap, wireshark et. al. It has been suggested that the act could even go so far as making vulnerability research and disclosure illegal, even if no code or tools are developed. Think I better be careful what I post to EH-Net from now on.

When the good guys can't play the game, the bad guys will win by default.
Logged

jason
Hero Member
*****
Offline Offline

Posts: 945



View Profile
« Reply #1 on: November 14, 2008, 08:25:00 AM »

Well obviously this will prevent the bad guys from getting ahold of the tools, so the good guys won't *need* to have access to them any more.
Logged
NickFnord
Full Member
***
Offline Offline

Posts: 117



View Profile WWW
« Reply #2 on: November 14, 2008, 10:38:51 AM »

just had a quick read of the actual statute, and to my relief there are "intent" clauses.

I am also NOT a lawyer, but having spent a while in the hobby lockpicking community I've done a bit of research on posession of locksmith tools etc.  These laws vary greatly depending on where you go, but in a majority of places, posession and distribution of lockpicks is only illegal if the intent to use to commit an offence is there.   i.e. if you are caught carrying picks, the court would take into account surrounding evidence - if you are a known hobby picker or have a locksmith licence it is considered not-illegal, however if you are caught at 2am at someone elses backdoor, then intent becomes an issue.  the same goes for non-specific tools - carry a screwdriver?  not a problem.  carry a screwdriver at 2am behind someone else's house?  intent rules in these cases.

the Police and Justice act says the following:

Quote
Making, supplying or obtaining articles for use in offence under section 1 or 3

(1)A person is guilty of an offence if he makes, adapts, supplies or offers to supply any article intending it to be used to commit, or to assist in the commission of, an offence under section 1 or 3.
(2) A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence under section 1 or 3.
(3) A person is guilty of an offence if he obtains any article with a view to its being supplied for use to commit, or to assist in the commission of, an offence under section 1 or 3.


Note the necessity of intent.  I know it is still a potentially serious issue for legitimate ethical hackers like us, but pardon a bit of cynicism on my behalf if I say "the media sensationalises these things because going into the legal details doesn't make a good story.  it also gets a rise out of the people who read the article and take it at face value:  'oh noes every tool I use is going to be illegal the bad guys have won'.  which is certainly not the case.

The other thing to note is that (generally) laws are made but only tested in court where the first few cases define a precident - if the first few convictions under this law distinguish (which they should) between deliberate malicious intent and research/hoby or even miss-guided accident, then we'll know that the law isn't quite as dumn as the media portrays. (at least in this case).
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 857



View Profile WWW
« Reply #3 on: November 18, 2008, 03:12:42 AM »

Nick,

mostly I agree with you, I find it very unlikely that we are going to see stories where 'admin for X arrested for passing copies nmap and wireshark to colleague'. However, the creation and possession of exploits and penetration frameworks are a different matter, especially with the 'limited' knowledge of the legal profession in these areas, and are equally vital to security professionals.

Even with the intent aspect of the clauses I feel uncomfortable performing any activity where the legality of the actions can be decided after I have committed the act. I'd feel a lot happy with a firm yes or no beforehand. I don't fancy being one of the test cases, regardless of outcome I don't think I could afford the legal fees.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.413 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.