• On CHOW: Sexy vampire party
November 4, 2009 11:30 AM PST

Congress may require ISPs to block fraud sites

by Declan McCullagh
  • Font size
  • Print
  • 33 comments

For the last decade or so, Internet service providers have been dealing with requests to block access to pornographic or copyright-infringing Web sites, or in China, ones that dare to criticize the government.

Now a U.S. House of Representatives bill is taking the unusual step of requiring Internet providers to block access to online financial scams that fraudulently invoke the Securities Investor Protection Corporation--or face fines and federal court injunctions.

The House Financial Services Committee approved the legislation on Wednesday by a 41 to 28 vote.

If you've never heard of the SIPC, you're not alone. It's a government-linked entity that aids investors when funds are missing from their accounts, up to a limit of $500,000 for stocks, bonds, and mutual funds. Only investor accounts that investors have opened with members of the SIPC--here's a list--qualify for its protection.

It turns out that occasionally, Internet fraudsters, scamsters, and other assorted malcontents have posed as legitimate brokerage firms that are SIPC members, often with a similar name or domain name. The scam may be a too-good-to-be-true offer to buy securities that asks the unwitting customer to pay fees in advance, or schemes involving fraudulent checks that eventually bounce.

That seems to be in part what prompted Rep. Paul Kanjorski, a Pennsylvania Democrat and chairman of a key subcommittee, to introduce the Investor Protection Act a few weeks ago. Section 508 of that bill says:

Any Internet service provider that, on or through a system or network controlled or operated by the Internet service provider, transmits, routes, provides connections for, or stores any material containing any misrepresentation (of the SIPC) shall be liable for any damages caused thereby, including damages suffered by the SIPC, if the Internet service provider...is aware of facts or circumstances from which it is apparent that the material contains a misrepresentation.

That section isn't mentioned in Kanjorski's press release dated October 1, which is why Internet providers were a bit taken aback when they found out about it a few days ago. The Internet Commerce Coalition sent a letter to Kanjorski before Wednesday's vote raising concerns with the bill, but the industry isn't terribly optimistic.

One potential problem with Kanjorski's bill is that most Internet providers simply don't have a good way to block access to any electronic "material" containing fake SIPC data. That wording is broader than just Web pages: it includes blocking certain e-mail, IM conversations, VoIP chats, and so on. And even the more straightforward task of blocking Web sites can be overly broad and problematic, which is why a federal judge in Pennsylvania declared a child porn filtering law to be unconstitutional in a landmark 2004 ruling.

Internet providers are also worried that Kanjorski's requirement--and the accompanying civil penalties and injunctions--would apply even if the blocking is not technically feasible. Or if it's impossible. (Other questions: Would this blocking requirement apply to private-sector employers? Schools and universities? Locally owned coffee shops that provide Internet service through Wi-Fi?)

Fraudulent Web sites have bedeviled the SIPC, off and on, for at least six years. In 2003, the group distributed a public warning against "brokerage identity theft" and followed up by asking the FBI to investigate a fake site that resembled the SIPC's own.

The SIPC does have a searchable database of its members, listing street addresses, but it doesn't take the obvious step of listing members' official Web sites, which other certification programs like Truste do.

Searching on San Francisco shows, for instance, that SIPC-listed Whitehall-Parker Securities has an address on Pacific Avenue. But an investor can't easily tell whether whitehall-parker.com is the actual site; a scammer could easily set up a fake site at whitehallparker.com (which, as of this writing, is available to be registered).

The Treasury Department's version of the Investor Protection Act of 2009 released in July doesn't seem to include the Internet-filtering section, meaning that the Obama administration concluded that it was unnecessary. So what prompted Kanjorski to insert it?

Addendum at 11:30 a.m. PT: Abigail McDonough, Kanjorski's spokeswoman, told me that her boss is open to modifying the language of the bill to reflect industry concerns. It also turns out that the language from the Investor Protection Act was borrowed from H.R. 2798, which was introduced in June by Rep. Michael Arcuri, D-N.Y., as part of a post-Bernie Madoff scandal effort to increase the level of SIPC guarantees for investors.

One Capitol Hill source says the SIPC asked for that language to be included in the Investor Protection Act. And a representative of SIPC says the organization may not have a response until Thursday because its president, Stephen Harbeck, is traveling from China.

Declan McCullagh is a contributor to CNET News and a correspondent for CBSNews.com who has covered the intersection of politics and technology for over a decade. Declan writes a regular feature called Taking Liberties, focused on individual and economic rights; you can bookmark his CBS News Taking Liberties site, or subscribe to the RSS feed. You can e-mail Declan at declan@cbsnews.com.
advertisement
 
Business supplies and services can get expensive. Get smart spending tips and learn about new cost-saving opportunities for your business
Recent posts from Politics and Law
Spain mandates affordable broadband for all
Town to photograph every car that enters and leaves
Dot-com thinking for D.C.: Expert Labs debuts
FCC discusses barriers to national broadband plan
What Intel just bought for $1.25 billion: Less risk
Justice Dept. asked for news site's visitor lists
EC formally objects to Oracle buying Sun
Going rogue? Palin bans gadgets, reporters from speech
Add a Comment (Log in or register) (33 Comments) (33 Comments)
advertisement

E-tailers linked to 'scam' blame customers

Priceline, Classmates.com, and Orbitz say customers should read the fine print before complaining about being charged to join loyalty programs they didn't want.

The 411 on early-termination fees

Verizon Wireless has doubled its early-termination fees for smartphones, but what does it mean for the rest of the industry?

About Politics and Law

News at the intersection of technology, politics, and law, ranging from intellectual property to censorship to tech policy.

Add this feed to your online news reader

Politics and Law topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right