Greetings:

As leading security practitioners, educators, vendors, and users of information security, we wish to register our misgivings about portions of the Council of Europe draft treaty on Crime in Cyberspace.

We are concerned that some portions of the proposed treaty may inadvertently result in criminalizing techniques and software commonly used to make computer systems resistant to attack. Signatory states passing legislation to implement the treaty may endanger the security of their computer systems, because computer users in those countries will not be able to adequately protect their computer systems and the education of information protection specialists will be hindered.

Critical to the protection of computer systems and infrastructure is the ability to

System administrators, researchers, consultants, and companies all routinely develop, use, and share software designed to exercise known and suspected vulnerabilities. Academic institutions use these tools to educate students and in research to develop improved defenses. Our combined experience suggests that it is impossible to reliably distinguish software used in computer crime from that used for these legitimate purposes. In fact, they are often identical.

Currently, the draft treaty as written may be misinterpreted regarding the use, distribution, and possession of software that could be used to violate the security of computer systems. We agree that damaging or breaking into computer systems is wrong and we unequivocally support laws against such inappropriate behavior. We affirm that a goal of the treaty and resulting legislation should be to permit the development and application of good security measures. However, legislation that criminalizes security software development, distribution, and use is counter to that goal, as it would adversely impact security practitioners, researchers, and educators.

Please do not hesitate to call on us for technical advice in your future deliberations.


This statement represents the professional opinion of each individual signer. Unless stated otherwise, it may not represent the official position of the signer's parent organization.



  • Scott Blake
    Security Program Manager
    BindView Corporation

  • Adam Shostack
    Director of Technology
    Representing Zero-Knowledge Systems, Inc.

  • Stuart Staniford, PhD
    President
    Representing Silicon Defense

  • Robert A. Clyde
    Vice President Security Management
    Representing AXENT Technologies, Inc.

  • Craig Ozancin
    Senior Security Analyst
    Representing AXENT Technologies, Inc.

  • Elias Levy
    Chief Technical Officer
    Representing SecurityFocus.com

  • Scott A. Lawler, CISSP
    Chief, Vulnerability Analysis
    U.S. Department of Defense Computer Emergency Response Team

  • Mike Prosser
    Research Manager
    Enterprise Solutions Division
    Symantec Corporation

  • Pascal Meunier, M.Sc., Ph.D.
    Research Scientist
    CERIAS

  • Thomas Stracener
    Technology Research
    Hiverworld, Inc.

  • Paul E. Proctor
    Director of Technology
    Cybersafe Corporation

  • David LeBlanc, Ph.D.
    (currently with Microsoft Corp. Information Security)

  • Eugene H. Spafford, Ph.D, FACM, FAAAS
    Professor and Director
    Purdue University CERIAS

  • Kelly J. Cooper
    Internet Security Officer
    Genuity

  • Ken Armstrong
    Senior Network Security Engineer
    EWA-Canada / CanCERT

  • Ron Moritz, CISSP
    Senior Vice President and Chief Technical Officer
    Representing Symantec Corporation

  • Rebecca Gurley Bace
    President/CEO
    Infidel, Incorporated

  • Peter Sommer
    Senior Research Fellow
    Computer Security Research Centre
    London School of Economics & Political Science

  • Edward W. Felten, Ph.D.
    Associate Professor of Computer Science
    Director, Secure Internet Programming Laboratory
    Princeton University

  • Alan Paller
    Director of Research, The SANS Institute

  • Winn Schwartau
    President, Interpact, Inc. (USA)

  • Dorothy E. Denning, Ph.D.
    Professor of Computer Science
    Director, Georgetown Institute for Information Assurance
    Georgetown University

  • Dan Farmer
    Security Researcher
    EarthLink

  • Bruce Schneier
    Chief Technical Officer
    Counterpane Internet Security, Inc.

  • Crispin Cowan, Ph.D
    CTO
    WireX Communications, Inc.

  • Gary Bratzel
    Senior Information Security Analyst
    EDS

  • Donn B. Parker, CISSP
    Senior Information Systems Management Consultant
    Retired from SRI Consulting

  • Kenneth R. van Wyk
    Corporate Vice President and Chief Technology Officer
    Para-Protect, Inc.

  • Simon Robert Finn
    IT Security Analyst
    Cisco Systems

  • Mowgli Assor
    Network Security Group
    OSU Incident Response Team
    Ohio State University

  • RNDr. Pavel Zaruba, MSc.
    Director IT Security
    Corporate Express, Inc.

  • Matt Power, Ph.D.
    (currently with the Massachusetts Institute of Technology Network Security team)

  • Henry E. Binger
    Owner
    Texys Services

  • William A. Frauenhofer
    Project Leader
    Intrusion.com

  • Paul A Clark MS, MCSE
    Technical Services Manager
    Wilderness Coast Public Libraries

  • Jerry Dixon
    Director, Information Security
    Marriott International

  • Stephen Carville
    Network Engineer
    Unigraphics Solutions, Inc.

  • Dr. Peter Li, Ph.D.
    Researcher
    Nippon RAD, Inc.

  • Michael H. Warfield
    Senior Researcher and Fellow
    Internet Security Systems, Inc.

  • Steven M. Bellovin, Ph.D.
    AT&T Fellow
    AT&T Labs Research

  • Chase Giles
    Director of Internet & Networks
    NetNearU Corp.

  • David M. Balenson, Director of Technical Outreach
    NAI Labs, The Security Research Division
    Network Associates, Inc.

  • Steven R. Snapp
    Senior Security Engineer
    CyberSafe Corporation

  • David Mann, Ph.D.
    Senior Security Analyst
    BindView Corporation

  • Matt Bishop
    Associate Professor
    Computer Security Laboratory
    Department of Computer Science
    University of California at Davis

  • Bill Wall
    Senior Computer Security Engineer
    STAT Operations, Harris Corporation

  • William Fithen
    Senior Member of the Technical Staff
    CERT Coordination Center
    Software Engineering Institute
    Carnegie Mellon University

  • Eric Cole, CISSP
    SANS Institute

  • Jim Magdych
    Security Research Manager
    Network Associates, Inc.

  • William Hill
    Principal INFOSEC Engineer
    The MITRE Corporation

  • Casper Dik
    Security Architect,
    Solaris OS Engineering
    Sun Microsystems, Inc.

  • Steve Schall
    Sr. Product Manager
    Intrusion.com

  • David W. Baker, MFS
    Senior INFOSEC Engineer
    The MITRE Corporation

  • Ronson Nguyen, CISSP
    Information Security Services
    Ernst & Young LLP

  • Steve Northcutt
    SANS Institute

  • Steven M. Christey
    Lead Information Systems Engineer
    The MITRE Corporation

  • Ken Williams
    eSecurityOnline.com

  • Simson L. Garfinkel
    Chief Technology Officer & Founder, Sandstorm Enterprises, Inc.

  • Professor David Farber DE
    The Alfred Fitler Moore Professor of Telecommunication Systems
    Department of Computer and Information Science and Electrical Engineering University of Pennsylvania

  • Kenneth A. Dresser, PE
    Network Security Consultant
    IBM

  • David Wagner, M.S.
    Co-founder, ISAAC security research group
    U.C. Berkeley

  • Mark G. Graff
    Chief Scientist
    Para-Protect Services, Inc.

  • Pamela Samuelson
    Professor of Information Management and of Law
    University of California at Berkeley.

  • Lance J. Hoffman
    Professor of Computer Science
    The George Washington University

  • Drs. Jacques Schuurman
    Chair of CERT-NL
    SURFnet bv
    Netherlands

  • Terry Lee Simpson
    Senior INFOSEC Engineer
    Electronic Data Systems (EDS)

  • Richard M. Bejtlich
    Network security consultant
    TaoSecurity

  • Barbara Simons, Ph.D.
    Past-President
    Association for Computing Machinery (ACM)

  • John Appel, CISSP
    Lead Security Analyst
    Cendant Corporation

  • Ron Weinberg CCSA, CCSE
    Network Security Consultant

  • Joseph A. Lazzaro
    Manager of Information Systems
    The Learning Network, Inc.

  • Kurt Seifried
    Senior Analyst
    SecurityPortal

  • Alexander L. E. Eriksson
    System Administrator
    Datortek/Aktivitetscenter (Västerås Sweden)

  • Eberhard K. Wildermuth, Ph.D.
    Chief Technical Officer
    Network Defense Systems

  • Mark Loveless
    Senior Security Analyst
    RAZOR Security
    BindView Corporation

  • Steve Manzuik
    Security Analyst
    RAZOR Security
    BindView Corporation

  • Sean Michael Dalnodar
    Information Security Specialist/Analyst
    Comstar.net, Inc.

  • Matthew Blaze, PhD
    Research Scientist
    AT&T Laboratories

  • Michael T. Babcock
    Chief Technical Officer
    FibreSpeed

  • David C. Burch
    Sr. Application Developer
    Information & Display Systems, Inc.

  • John P. McGraw, CISSP
    Information Security Master
    EDS