Skip to content


May 25, 2007

Germany leads the way with tough anti-hacking law

Opponents warn legislation could let government to insert spyware on systems

By John Blau, IDG News Service


The Germany government has passed a tough new law against hacking.

Advert

The legislation, which the German government proposed earlier last year and approved Friday with no changes, aims to crack down on the sharp rise in computer attacks in the public and private sectors.

Although Germany already has a comprehensive penal law against attacks on IT systems, the new legislation looks to close any remaining loopholes.

It defines hacking as penetrating a computer security system and gaining access to secure data, without necessarily stealing data. Offenders are defined as any individual or group that intentionally creates, spreads or purchases hacker tools designed for illegal purposes. They could face up to 10 years in prison for major offences.

Other punishable cybercrimes include DOS (denial-of-service) attacks and computer sabotage attacks on individuals, which would extend the existing law that limited sabotage to businesses and public authorities.

The new law, however, has drawn criticism by several groups, including the hacker club Chaos Computer Club eV, which points to the work of "white hat" hackers who work for security companies. These experts, the club argues, could be restricted in their ability to help software makers develop secure products and businesses to deploy them.

That opinion is shared by some hackers as well.

In an e-mail, a hacker, known by the pseudonym van Hauser, wrote that if hackers are unable to share their tools with the public, white hats will not be able to get them and use them internally for testing or external security consultants won't be able to do security testing. "It's a win-lose law in favour for the bad guys," he wrote.

Chaos Computer Club also warns that the law could make it much easier for the German government to allow law enforcement officials to install spyware on computers of suspected criminals without their knowledge. The club is concerned about the ability of consumers and businesses to protect their systems from government spyware without support from the hacker community.

In February, the country's High Court handed down a landmark decision banning police from installing spyware, delivering a blow to the plans of the German Interior Minister Wolfgang Schäuble to give the Federal Criminal Police Office greater power to monitor terrorists and other criminals online, and peek inside their computers.

But Schäuble is seeking ways ever since to have the court revise its decision.

Follow highlights from ComputerworldUK on Twitter
Sign up for our Daily Newsletter
The UK IT News widget Get it for your site!

« prev article | more security news | next article »

Advert

close

Email this article to a friend or colleague:




PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

close
  • This article is now being printed.
close

What are your views on this subject? Use the form below to post a comment on this article up to 1000 characters.


Characters remaining:

close

Click below to add 'Germany leads the way with tough anti-hacking law - Cybercrime & Hacking - ComputerworldUK' to your blog.



If you do not have a ComputerworldUK Account and would like to use this feature, please Register.

If you are a registered, logged-in user, this will post the title and first paragraph of this story to your blog to share with your readers.

What is this?

Advert

WHITE PAPERS

  • Legal risks: Employee use of the internet and email
    Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.
  • Phishing for victims
    This White Paper examines the phenomenon of phishing. It explains the potentially catastrophic threat it presents to all kinds of organisation. Exploding some widespread myths, it lights up the murky waters where phishing first emerged and where it continues to evolve. But it also highlights what your business can do to blunt the threat.
  • Challenges and opportunities of PCI
    The control framework implicit in the Payment Card Industry Data Security Standard (PCI DSS) provides an enterprise structure for improving operational, security, and audit performance.
  • Social CRM comes of age
    Who is this “social customer”? What strategies and tools does the new breed of CRM provide to do something about this?
  • Risk Management: Protect and Maximize Stakeholder Value
    What has held organisations back from a broader adoption of risk management programs?
*