The computer misuse act 1990 covers the act while the device is located in the United Kingdom. With section 1 defining the act of hacking in relation to the act. This includes anyone who accesses a computer program or data without authorisation or secures access to with full knowledge of restriction to them. Therefore, proving ‘mens rea’ in any case is paramount. Uk nationals can also be held accountable aboard. This is held accountable as per the serios crime Act 2015 extending jurisdiction for crimes committed against the CMA sections 1-3A. Here I will critically examine legislation and case law whether the act provides as a deterrent for hackers.
Before this act was created, the legal system relied on old Victorian laws to prosecute, as the era developed from a curiosity of developing software of trains at a university in Massachusetts America ‘MIT’ in the 1950’s to 60’s. At this time the concept of cyberlaw did not exist in the UK as everything was academic or military . In the 1970’s ‘hackers’ developed ‘blue box’ for telephone communications and the ‘freakers’ manipulated frequencies in the phone line to make free calls. The 1980’ was when the first computers, using modems, were brought into people’s homes where they could share and look up other corporate networks by dialling into ‘bullet board networks’ . Around this time, prosecutors were relying on ‘forgery’ for using passwords and ‘criminal damage’ for tampering with magnetic particles on a disc. The case of the hackers – Mr Schifreen and Mr Gold, that hacked the Duke of Edinburgh’s emails at BT led to an overhaul in defining ‘computer misuse around the world and ultimately led to the Computer misuse Act 1990.
The ‘legal vacuum’ of the 1990’ describes legislation evolving as cyber defences lawyers were putting across were not satisfied with definitions given as ‘physical theft’. For example; stealing information did not permanently deprive the owner of physical property . In the Prince Philip case, both were charged as per the forgery and counterfeiting Act 1981, however, the argument of typing a stolen password into British telecoms Prestel Network through a computer amounting to creating a false instrument, was not acceptable. The house of Lords, upon an appeal of conviction by the defendants, saw that this did not amount to forgery and called for Parliament to modernise the law . Before this, there were no laws around the world equipped to deal with such defences in the way the Uk had created. Instead of basing ours on old statutes, such as Sweden, the U.S and Canada – we created a tier legislation that
- per section 1 of the act. Here they focused the point-in-law with the actual data being accessed and not just the computer. The accused Mr Alison was actually extradited to be tried in the U.S as there was dual criminality requirement in both countries.
Section 2 covers unauthorised access with the intent to commit or to facilitate further offences, solely or with another person having first committed an offence as per section1. The summary conviction is the same as section 1 although conviction or indictment includes 5 years maximum. An example of this is the R v Seth Nolan McDonagh 2015 who gained thousands of pounds in one of the largest ‘digital disputed denial of service (DDoS) he caused collateral damaged and slowed down the internet for others, all in exchange for financial payouts. He received 240 hours community service which was lenient due to his mental health and age at the time of the offence. Whereas another hacker was jailed for 8 years for copying employee data at Morrisons superstore and producing them online. He copied the entire database onto his personal encrypted USB stick. Most of this sentence was due to the further offences. The Meldrum case sparked outrage as an offender also as per section 2 of the act but for hacking cameras and taking indecent pictures of people among other offences, only received a 12-month prison sentence suspended for two years for ‘unauthorised remote access application as per section 1 and further sexual offences as per section 2. It seems to be at this point that sentencing is very low for offenders of the CMA, which is not much of a deterrent at all.
Section 3 covers – with intent to impair, or with recklessness as to the impairing of the operation of a computer” this includes the same sentencing for summary it carries 10 years max imprisonment. R v Nazari 2016 received a sentence of 11 years and 3 months impairment for stealing and sharing 450,000 customer email addresses and passwords from Yahoo. Which he attempted to sell. Although, again we do not know what years were given for each offence covered, this is a lot and without the act there would be no link to further offences, therefore for this I would say that justice is a deterrent.Section 3ZA covers – unauthorised acts causing or creating risk of serious damage. This offence is indictment only, which includes; 14 years and/or a fine. However, where the risk caused to human welfare or national security this can be up to life imprisonment. The WannaCry Ransomware attack [2017] is legally cited as the offence which triggers this section. This was a global attack on ransomware attack where no-one was tried as the perpetrators are from North Korea who do not extradite their citizens but they remain fugitives and face life-imprisonment for this crime . With this, extraditions are - an issue once again, the act itself carries a deterrent as the people indicted could be caught.
Section 3A – the making or supplying of malware, as possessing is not an offence. This may make it difficult as ‘intent’ must be proven. By producing any article assisting in any of the previous section offences. Usually, this offence is committed alongside another in this act. Such as the Skelton and McDonaugh cases referred to above. It carries a smaller sentence such as section 1.
Conclusion
As computers evolved, legislation dragged its feet behind. The Uk was the fourth country to create suitable legal frameworks to adapt to the growing interests of hackers. With the creation it did not ‘miss and hit the wall’ so-to-speak. However, in practice it was found to have loopholes in regard to ‘authorisation’ in the workplace, although this to me did not seem a failure as this is something that should be made clear by employers’ contracts. Proving ‘mens rea’ without ‘authorisation’ is the crux of this act. The Mckinnon case and the Love case both give way to a culture of hackingclassified sources abroad. Human rights can over -ride the extradition legislation and other parties are not in a position to provide evidence to have them tried in the UK as per the serious crime Act 2015. This is situation is not much of a deterrent and hackers might want to take the chance. Even without existing mental health issues anyone could claim this to be an impact on mental health in this way. Also, there is plenty scop for the UK to block extradition in this way as per the extradition ‘forum bar’ in section 83A of the Extradition Act 2003. The Meldrum case had a ‘gap’ in that legislation did not fulfil the obligations as per the Meldrum case for ‘cyber-stalking’ although he admitted to section 1 offence, this was for further offences, but this is seen as a limitation of the act as it is not included and maybe should be. This act has sentencing of good deterrent however, from the cases and legislation more often than not people do not meet the full extent of the law. In practice, it’s the judgments that are letting it down by way of other legislation such as the Human rights protections, and extradition laws.Before all this began the term Hacking meant – to be finding clever, creative solutions to technical difficulties, now it has become a greedy problem.