Skip to content
Annuaire
Sections
Technology

The fight against personal identity theft: the solutions!

The fight against personal identity theft: the solutions!
L’essentiel

The creation of an identity theft offense on the Internet: digital identity theft techniques are numerous and the legal vacuum that persisted until LOPPSI 2.

À retenir

The creation of an identity theft offense on the Internet: digital identity theft techniques are numerous and the legal vacuum that persisted until LOPPSI 2.

The development of an identity theft offense on the Internet

Digital identity theft techniques are numerous and the legal vacuum that persisted until the adoption of the LOPPSI 2 law did not allow them to be addressed. Indeed, until now, identity theft was not sanctioned as such, but through more general texts. Now, the offense of identity theft on the internet advocates a legal solution intended to more broadly framework attacks on people’s identity and to improve network security via sanctions. However, this exclusively repressive policy is not truly satisfactory. This is why a technical solution based on prevention has been put in place to reduce identity theft.

The legal solution via sanctions

The need for repression of online identity theft has gradually been felt, but several proposals, which remained without follow-up, were suggested before the government made identity theft one of its priorities within the evolving digital framework.

Faced with the absence of a specific offense for identity theft on the Internet, the orientation and programming bill for the performance of internal security (LOPPSI) proposed to specifically criminalize digital identity theft. But the bill was incomplete insofar as the new offenses did not allow for the sanctioning of identity theft behaviors that escaped the law. Furthermore, it did not determine what a person’s digital identity represented on the Internet.

The bill, although subject to many debates, eventually led to the adoption of Law No. 2011-267 of March 14, 2011, known as orientation and programming for the performance of internal security (LOPPSI 2), establishing a provision more protective of the citizen and which aims to define and criminally sanction identity theft. In this way, the new established offense sanctions identity theft in general, whether it occurs in the real world or on an online public communication network. This new measure takes into account technological developments and the importance of networks for internet users.

Also, the new measure took into account the fact that online identity theft could consist of using confidential and personal information on the Internet such as the last name, first name, pseudo, addresses, photographs, and all personal data. It also took into consideration that theft could take place on any type of website, and for many reasons: committing reprehensible acts, harming an identity by creating a false profile, recovering personal information from a fake site for the purpose of hacking mailboxes or accounts such as Facebook, accessing secure accounts, or even sending a message pretending to be a public body or a private entity for essentially commercial, economic, and financial purposes.

Now, under the provisions of Article 226-4-1 of the penal code: “The act of usurping the identity of a third party or making use of one or more data of any kind allowing their identification with a view to disturbing their peace or that of others, or to harm their honor or consideration, is punished by one year of imprisonment and a €15,000 fine. This offense is punished with the same penalties when committed on an online public communication network.”

This new offense, expressly targeting online public communication networks in its second paragraph, is likely to apply when the following conditions are met: data of any kind allowing the identification of a person must be used with a view to disturbing their peace or harming their honor or consideration. And it can continue to be sanctioned according to the provisions of the Data Protection Act (loi Informatique, fichiers et libertés) since it gives rise to the processing of personal data of an individual without their consent. This constitutes an offense punishable by 5 years in prison and a €300,000 fine.

Also, it is important to take the necessary measures to limit the risk of infringement.

To do this, every internet user must be cautious when entering personal data on the Internet or upon receiving messages asking to provide or update their credentials. One should not respond to suspicious messages or click on links contained in messages whose origin is uncertain.

Furthermore, the victim can request the removal of any content likely to be put online by a thief. In this case, they must contact the site broadcasting this content. In the absence of a reaction from the site to remove the content brought to its attention, it will be appropriate to initiate a procedure to engage its responsibility as a host and obtain the withdrawal of the litigious content.

In principle, notifications for the withdrawal of illegal content result in execution by websites such as Facebook or Google, automatically. Indeed, from the moment identity theft goes against both legal texts and general terms of use, the network must proceed to close the account or ask the creator of the page to change its name.

Note that it is not always easy to address the creator of the litigious page directly and engage their responsibility, because their identification is difficult to establish. Also, in the absence of knowing the identity of the usurper, the victim can hope to see the usurper sanctioned by filing a criminal complaint with the Public Prosecutor based on a report of the facts and litigious statements. The prosecutor will draft the complaint justified in fact and in law to allow for rapid and effective criminal prosecution.

Thus, as we have just seen, there are various modes of identity theft that can be criminally sanctioned. However, recourse to sanction is not the only solution.

 

The technical solution via prevention

In the absence of legal solutions responding to all problems related to security and the preservation of identities on the Internet, there may be ways to fight identity theft upstream online, such as measures that can be developed by companies to protect themselves from identity theft. Indeed, companies can establish privacy policies relative to the content of their emails and warn their clients of the existence of this policy. This same policy could provide for not introducing hyperlinks in the emails they distribute or including elements in the emails allowing the client to ensure the authenticity of the content and provenance.

Companies can also use authentication elements allowing them to identify the recipient. For this, it will be necessary to use a reliable domain name provider capable of guaranteeing maximum security on its servers and certifying the veracity of the information collected. Like banking institutions, which use the “3DSecure” security system consisting of providing a certain number of additional information items, which each bank chooses freely, and which allow for the identification of the user, identification is done upstream. In this case, the issuing bank authenticates the payment card holder and confirms the identity of the buyer to the merchant’s bank. For the payment to be made in 3DSecure mode, it is necessary for the payment card to be a 3DSecure card and for the online merchant to accept this payment mode. Generalizing this type of tool to other services requiring an identification process would be a useful and interesting means of protection.

For social networks, and particularly the Twitter site, which is a social network tool focused on micro-blogging, it has been a matter of setting up certified accounts, certifying the veracity of the person’s account identity.

These certified accounts are accompanied by a logo entitled “Verified Account”. This measure has the effect of reducing the number of people who use another individual’s identity for the purpose of harming their reputation. These account authentication measures tend to generalize across all networks. Consequently, it is up to social network users to align with these new practices and configure their accounts.

Internet users can voluntarily follow awareness policies on the risks of digital identity theft, allowing them to learn about new uses of the Internet and adopt more responsible behavior by adopting various preventive measures. These preventive measures can be proposed regarding attacks on identity carried out by the technique of phishing. Indeed, instead of clicking on the hyperlink, it is preferable for the internet user to manually enter the website address. Thus, they can check the website address in the browser’s address bar.

Similarly, when consulting secure sites, it is recommended to check that data encryption is activated to protect the data. To carry out the verification, the internet user must double-click on the “padlock” that appears at the bottom right of the page; they can then see the company’s security certificate and ensure that the beneficiary company is indeed the one operating the site. But on social networks, there is not, strictly speaking, a visible padlock. Therefore, nothing certifies the security measures carried out by site managers. The only mentions relative to network security are provided in the general terms of use or the privacy policy. But this requires that the user can refer to these mentions even before proceeding with their registration.

Finally, the internet user can inquire about the site managers and check that the site is indeed secure. One can use “computer toolbars” allowing for the detection of reliable sites. In this way, with a vigilant attitude, the adoption of technical tools for securing the Internet connection and authenticating websites and users, the risks of identity infringement could be limited, but not neutralized.

Sources:

– AMAUDRIC du CHAFFAUT (B.) and LIMOUZIN-LAMOTHE (T.), “Une nouvelle forme de criminalité informatique à l’épreuve de la loi : le phishing”, Expertises, April 2005, p. 14;

– TGI Paris, 3rd ch., June 24, 2009, Jean-Yves Lafesse et a. c/ Google et a, no 08/03317;

– MANARA (C.), “Conditions de la sanction de l’usurpation de nom sur Internet”, D., 2006, p. 1443;

– MARIEZ (J.-S.), “Un premier pas vers la mise en place d’un dispositif pertinent de lutte contre l’usurpation d’identité sur Internet ?”, RLDI, November 2008, p. 65;

– CAPRIOLI (E.), “De l’usurpation d’identité en matière pénale”, CCE, July-August 2006 pp.39-40;

–  COUSIN (A.), “L’usurpation d’identité sur internet : une lacune à combler ?”, Expertises, August-September 2006, p.322-32;

– DÉTRAIGNE (Y.) and ESCOFFIER (A.-M.), La vie privée à l’heure des mémoires numériques. Pour une confiance renforcée entre citoyens et société d’information, Information report made on behalf of the law commission, Doc. Parl. S., n°441, 2008-2009;

– “Dossier Cybercriminalité : morceaux choisis”, AJ Pénal, revue de sciences criminelles, n° 3, March 2009, p. 12;

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi

April 6th at Grand Rex - Tech For Future
Innovation

April 6th at Grand Rex - Tech For Future

Celebrating the 90th anniversary of the Grand Rex, Tech For Future highlights French technology's commitment to ecological transition,…

1 min read

Free, no spam, one-click unsubscribe.