Lessons 16 · 1 lessons · N. Ismatova, O. Karimova. Foundations of State and Law: textbook for Grade 11 of general secondary schools and for secondary specialised and vocational institutions. 1st edition. “Yangiyul Poligraph Service”, Tashkent, 2018
16
Crimes in the sphere of information technology
Textbook: pp. 89–94
GoalExplain the right to freely use information, the elements of crimes involving unauthorised access to computer information and malicious programs, and apply the rules of digital safety.
New words
freedom of information: the right to seek, receive and spread lawful information · Axborot erkinligiunauthorised access to a computer system or account · Ruxsatsiz kirishmalware: a programme created to damage data or break into systems · Zararli dasturcybersecurity: protection of networks, devices and data · Kiberxavfsizlik
Explanation
The Constitution gives everyone the right to seek, receive and spread any information the law does not forbid; this right is limited by other people’s private life, state secrets and other restrictions set by law. In the digital environment it is protected by the laws “On the principles and guarantees of freedom of information”, “On personal data” and “On cybersecurity”. The Criminal Code treats unlawful access to computer information as a crime: guessing a password or entering someone else’s account to view, change, copy or delete data is such an act. A separate crime is preparing, passing on or spreading special tools or malicious programs meant for unauthorised entry into a system. These crimes are committed deliberately, their object is information security, and the victim may be a person, an organisation or the state. The type of liability depends on the size of the harm and the consequence: minor cases lead to administrative liability, while serious harm or acts committed by a group lead to criminal liability.
Worked examples
Dilfuza guessed a friend’s social-network password, read the messages and deleted one photo. She broke the law by entering the account and changing data without consent; saying “it was a joke” does not remove liability.
The programmer Sherzod wrote a study project, tested it only on his own computer and encrypted his own file. Since he entered nobody’s system and caused no harm, there are no elements of a crime; spreading it to others would be a different matter.
Class activity
Class activity: together the class makes rules for strong passwords (length, mixed characters, a different password for each service, two-step verification). Nobody says or writes down a real password.
Practice
1
What information right does the Constitution give and what is its limit?
Everyone may seek, receive and spread information the law does not forbid; the limit is other people’s private life, state secrets and other restrictions in law.
2
Name three possible forms of the crime of unauthorised access.
Viewing, changing or copying data; deleting or destroying it; disrupting how the system works.
3
Someone sends you a link saying “your bank card is blocked, enter the code”. What do you do?
I do not open the link or give any code; I check by calling the bank’s official number myself and delete or report the suspicious message.
4
Why may saying “I only keep the malicious programme and do not spread it” not be enough? Explain.
Because the law also treats preparing it for unauthorised entry as a crime; spreading is not required, the purpose and preparation matter.