Share on LinkedInShare on LinkedIn

ARTICLE · 15 MARCH 1999

Is Your Business Safe On The Web?

United KingdomIntellectual Property
The Internet is the world's largest marketplace, some 50 million people having access to it in the UK alone, with commercial transactions topping £850 million.

At present whilst an estimated 20% of "wired" adults have made only one on-line purchase, the value of transactions is expected to increase to £145 billion in Western Europe in the next two to three years, with some £30 billion of that generated in this country.

But how secure are commercial transactions which are carried out over the Web?

The answer is.... not very.

Internet communications are routed via public telephones lines which can be monitored in the same way as any telephone call. As a result, fears of industrial espionage are discouraging some businesses from using the Web for business which is commercially sensitive.

Financial information, such as credit card data, is held by the vendor indefinitely. Consumer concern that hi-tech hackers can gain entry to this information is justified, and has had considerable impact on business to consumer sales via the net.

The solution for business may lie in the use of encryption technology. There are various products available in the market, ranging from simple cyphers, to 128-bit encryption software.

Experts claim that while a 40-bit encryption would take 8 hours to break, a 128-bit code would take 2 trillion years. These encryption products are used to protect sensitive communications, and they can only be accessed by people who have a key.

As with much of the "new media", legislation is playing catch-up. In the UK there are proposals to introduce legislation, in the form of the Electronic Commerce Bill, which will, among other things, regulate the use of encryption codes.

It is likely that sellers of encryption products will have to be licensed, but more importantly, the legislation will allow the police to obtain court warrants to compel sellers and users to disclose encryption keys, principally as a response to concerns that organised crime is utilising the technology to hide their activities.

The introduction of this regulatory framework means that it will no longer be possible to assume that encrypted messages will only be read by the intended recipient, and care will still need to be taken when doing business on the Web.

In our next issue we will be looking at the security of payment transactions on the Web in more detail.

For further information please contact Liat Shimron, e-mail: Click Contact Link , 7 Devonshire Square, Cutlers Gardens, London EC2M 4YH, UK, Tel: + 44 171 655 1000

This article was first published in the March 1999 Hammond Suddards Commercial Dispute Resolution Newsletter

The information and opinions contained in this article are provided by Hammond Suddards. They should not be applied to any particular set of facts without appropriate legal or other professional advice.

See more popular content from