iEntry 10th Anniversary RSS Newsletter Advertising
Visit Twellow.com
Text: Decrease Font Size Increase Font Size | Print Print Article | Share: Delicious Digg StumbleUpon Post to Twitter Post to Facebook
CommentThursday, January 3, 2008

UK Aims to Stop Hackers by Banning Tools

It could be a bad day for security people in the UK

In what could be a bad day for United Kingdom pen testers, stress testers, and other systems security folks, the UK is getting ready to ban the creation and distribution of tools that could be used by hackers. This generally unpleasant concept could make it not only impossible to create the next nessus or nmap by anyone in the UK, it could also send them to jail for distributing the tools they make as well.

This ought to set back UK computer security by decades.

The distinctions between, for example, a password cracker and a password recovery tool, or a utility designed to run denial of service attacks and one designed to stress-test a network, are subtle. The problem is that anything from nmap through wireshark to perl can be used for both legitimate and illicit purposes, in much the same way that a hammer can be used for putting up shelving or breaking into a car. Source: Register

This should be quickly tested in the UK courts, the minute the ink is wet on the paper kind of legal testing. There are multiple programs, perl, c++, shell scripts in C, and other programs and tools that are made by people to do things. Dual use tools are tools that can be used for both good and evil. It will be difficult to determine the intent of the tool developer unless they leave behind incriminating e-mails saying the tool was created to rip off millions of people.

Any form of distribution would also be included in the statutes, meaning the mere act of sharing a tool with your security friends could be bad for you continued security career.

This is generally bad, and will hamper legitimate security workers and researchers. The state of the security industry in the UK is now dead. The hackers will win this one unfortunately, and there seems to be no way to stop this kind of legislation short of a court testing of its legitimacy.

Comments

About the author:
Dan Morrill runs Techwag, a site all about his views on social media, education, technology, and some of the more interesting things that happen on the internet. He works at CityU of Seattle as the Program Director for the Computer Science, Information Systems and Information Security educational programs.

Publish A Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
9 + 1 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
SEARCH
Popular WPN Business Resources












Subscribe to WebProNews


Send me relevant info