When did the law pass making owning software illegal, as opposed to using it for nefarious means? (Last time I looked CMA required use.)
Anyone have details of the exact charge?
When did the law pass making owning software illegal, as opposed to using it for nefarious means? (Last time I looked CMA required use.)
Anyone have details of the exact charge?
https://www.europol.europa.eu/newsroom/news/international-cr...
No idea what law it breaks, but apparently the developer of a similar Trojan got 30 months in prison in a similar case: https://thehackernews.com/2018/10/hacking-tool-luminositylin...
I’m sure glad that wasn’t a thing when I was a teenager and cult of the dead cow was cool.
I really don't mean to flame-bait, but I've noticed HN has a mild pro-EU/anti-Brexit bias, so I would be remiss if I didn't draw attention to the fact that this is part of what Brexiteers are against.
Here we (apparently) have a case in which the law of the land is at odds with EU regulation. I leave it as an exercise to the reader to research how EU regulations are drafted and ratified.
Disclaimer: I'm a remoaner, but I'm also trying to understand just WTF is going on.
Also AFAIK Europol is a co-operation facility, not a front line policing organisation. It is a means by which the member states co-operate and share intelligence, but not (yet) a source of rules and regulations.
Also the UK relations to Europol is a a bit freestanding, and we opted out of the Justice and Home Affairs stuff, then asked to opt back in to making use of Europol.
Obviously, the prosecution would need to prove intent but it's possible the mere presence of the software could suffice for mens rea — people don't typically buy this software accidentally.
Presumably most people who bought the software will have used it, making a prosecution under S1 CMA more likely.
It's probable that the CPS will only charge people they are likely to get an S1 conviction from and discard any S3A charges as S3A charges will be difficult to prove.
I guess that it's OK if you're a "government" user.
Edit: To unpack that a little, I've read that repressive/authoritarian governments have used these sorts of malware to harass, arrest, and kill people.
And furthermore, I wouldn't be surprised if the UK government itself is using these sorts of malware.
The Security Services of the UK Government have statutory exemptions allowing them to use these tools. These statutory exemptions are contained within the Intelligence Services Act 1994 Section 5 and the Investigatory Powers Act 2016 Section 99.
Hacking tools aren't illegal by default, that I know of anyway.
https://www.europol.europa.eu/newsroom/news/international-cr...
Presumably there would have to be some allegation of UK law-breaking in order to get a search warrant for properties in the UK.
Also it seems like taking down the website stopped the software working. If it was centralised then there is a link between the theft of bank logins and the associated fraud directly to the website. Of course it might just be dialing in and checking the license as opposed to the website facilitating functionality.
Edit. Just seen an archived page for the tool, looks like a legitimate network access and monitoring tool. If that's the case then arresting the dev seems excessive. I did note that the page provided support, so I wonder if there was some entrapment along the lines of "how do I monitor for bank logins ?" Perhaps with enough info to make it clear the tool was being used to perform illegal activity, and that support is what fucked the dev?
A large portion of common law revolves around intent - I think the technical term is "mens rea" (mentioned by another poster).
If a site sold knives as "neighbor killers", with the comment "use this and you can definitely kill your neighbor, $19.95", then all the same considerations would come into play. And knives aren't illegal, at least to cook with.
It's a crime to own the software intending to use it even if you don't actually use it. Arguably, the purchaser intended to use it at the point they made the purchase; people don't typically purchase software like this accidentally (of course there are obvious exceptions like perhaps security researchers wanting to decompile it to understand how to block it in the future, etc.)
AFAIR that's different to how the act was prior to SCA2015. Indeed this section including "material kind" strongly suggests that the original intent was that the Act would punish material damage, rather than a trumped up suggestion by the CPS (on whomevers behalf) that an act might be reckless as to whether it creates an increased risk of serious damage.
This legislation seems to work like "well you went on a road near some property, which is exactly what a criminal who was going to destroy that property would do, so you're clearly guilty". It seems somewhat over-reaching to me.
However, they do have to actually take action and material damage is defined by s3ZA(2) with "damage to human welfare" (s3ZA(2)(a)) constrained by s3ZA(3).
It is unlikely that the threshold for a charge under S3ZA would be met. The more likely charge is S1 (unauthorised access) or S3A(3) which makes it an offence to obtain any article intending to use it to commit, or to assist in the commission of, an offence under section 1, 3 or 3ZA — you don't even have to actually use the software to be criminalised, merely possessing it is enough provided the prosecution can prove your intent beyond reasonable doubt.
You can read the Explanatory Notes for the SCA 2015 amendments that altered the CMA 1990 at http://www.legislation.gov.uk/ukpga/2015/9/notes/division/3/... for background on why these changes were made.