iTnews
  • Home
  • News
  • Technology
  • Security

Laws to prosecute malware makers flagged

By Brett Winterford
Oct 28 2009 12:51PM
Follow google news

Liberal Senator proposes to tackle malware using the Spam Act.

A senate inquiry into cybercrime has discussed the possibility of extending Australia's Spam Act to specifically prosecute Australians that distribute malware or trick internet users into uploading programs onto their device without consent.

Laws to prosecute malware makers flagged

The Spam Act of 2003 currently covers electronic messages sent with a commercial purpose, but under a proposal by Liberal Party Senator Bruce Billson, the Act could be extended to include a set of harsher penalties specifically for the distribution of malware.

Billson told iTnews that the matter had come up for discussion on a couple of occasions during the cybercrime inquiry and was supported by several submissions, including a paper by the Cyberspace Law and Policy Centre at UNSW.

"At the moment we are very much focused on spam itself and not on the consequences of the malware that often comes with it," he said. "I am particularly interested in that. My instincts are that this is the issue."

Billson suggested that the Spam Act could be updated such that it would become unlawful to have software uploaded to any computer without express approval of the user - with penalties that reflect that malware goes "beyond the nuisance value of spam" and "undermines the performance of systems."

Billson stressed that legislation - which the Federal Government would "need to get right" - would only be a small part of the solution to the cybercrime problem. He said that more coordination between industry and government on detecting attacks and protecting systems from infection was also required.

"I have been encouraged by the range of people wanting to be a part of ensuring the integrity of the internet in this country," he said. "Most advocate a collaborative approach, where we take the best knowledge of IT engineers, commercial interests and law enforcement to address the problem."

Billson said he recognises that there is "no point building walls" to enforce security, but that the Government and industry "need to build resilience and responsiveness" to tackle the malware problem.

The cybercrime committee is yet to specifically discuss the inclusion of Billson's idea in any official report to Government, he said. His proposal would first "need consensus among committee members". But he is happy to have the idea pitched to iTnews readers for feedback such that he can "take an informed view to the Government."

No need, says the ALP

A Federal Government spokesperson told iTnews that the distribution of malware is to a large degree already covered under the Spam Act 2003 (in so far as it covers electronic messages with a commercial purpose) and that the creation and distribution of malware is similarly considered a criminal offence (under part 10.7 of the Criminal Code Act 2005), and is thus unlikely to be specifically addressed under the Spam Act as per Billson's idea.

Paul Ducklin, head of technology at security vendor Sophos Asia Pacific told iTnews he agreed with  this assessment, with the disclaimer that he is not a lawyer or member of the judiciary.

Ducklin said his concern would be that adding malware under the Spam Act might dilute or complicate the Spam Act and provide a "silly loophole" for malware distributed by other means.

He also expressed concerns that such changes would create a distinction between 'bad' and 'less bad' spam - the former being spam loaded with malware, the latter being made to appear seemingly less harmless.

"The old-school spammers might suddenly manage to appear less troublesome than they undoubtedly are," he said.

Ducklin said the key to solving the malware problem involved scammers being charged under a variety of laws - whichever were applicable - be it the Spam Act, the Trade Practices Act or the Criminal Code Act.

"That way, you can set not just [telecommunications regulator] ACMA but also the [competition watchdog] ACCC, the various State offices of fair trading and the cops onto them," he said.

What's your view? Is the current legal framework adequate to tackle malware? What do you think of Billson's idea?

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
actbillsonmalwaresecurityspam

Related Articles

  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
Join our WhatsApp Channel

Partner Content

Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.