Debates between Sally-Ann Hart and Chris Elmore during the 2019 Parliament

Tue 15th Mar 2022

Product Security and Telecommunications Infrastructure Bill (Second sitting)

Debate between Sally-Ann Hart and Chris Elmore
Chris Elmore Portrait Chris Elmore
- Hansard - - - Excerpts

Q I have a final question for Ms Concha on the online marketplaces, which do significant work in this area. In your view, how easy would it be to change the Bill to ensure that online marketplaces are part of it as well as manufacturers? The argument was made earlier that there most certainly is a responsibility on those who sell the product. Particularly if you are using, say, eBay, there is often limited interaction between the seller, the parent company and the person purchasing. Arguably, eBay as the organisation should take significant responsibility. I am keen to understand whether you think that is a relatively easy change for the Government to make to help close what you describe as a significant loophole in the Bill.

Rocio Concha: In terms of the Bill, an example could be to change or tighten the definition that you have of distributors. In terms of implementation, online marketplaces are the gateway between the consumers and the manufacturers of these products. They are the ones that have the power to make sure that these products comply with the law. Let me give you an example. We routinely do product tests to identify security vulnerabilities with these products. Often when we go to the online marketplaces, we get the answer that, because there is no regulation, they cannot take these products out.

We need the regulation to be clear that any smart product needs to comply with these baseline security requirements. Also, we need regulation to put responsibility on the online platforms to make sure that they are monitoring proactively which products are being sold on their platforms. That is key, and I feel that it is not optional. It is quite clear what is going to happen. There are bad actors out there, manufacturing products that are not going to comply with the baseline requirements. They know that there are not going to be the necessary checks in there by the online marketplaces, but the consumer does not know. It is impossible for the consumer to make an assessment of whether the product will be secure or not. Unless we put in regulation, you can see where all these bad actors are going to go.

Sally-Ann Hart Portrait Sally-Ann Hart (Hastings and Rye) (Con)
- Hansard - -

Q Good afternoon to you both. It is clear that in the Bill the onus is on the manufacturers to meet the product security and safety requirements. Clearly, consumers also need to be aware of security threats both within the context of domestic abuse and otherwise. Should the Government be giving guidance to consumers? I do not know what the current situation is, but is it the role of the Government to give guidance to consumers?

Rocio Concha: I personally think that yes, the Government should provide information to consumers so that they are aware of this. Organisations such as ours also play a role, and we play it. We continuously publish our findings on security vulnerabilities and the sorts of things that consumers can do to protect themselves. There is a need for more information for consumers in general so that they can be aware that when they put these products in their homes, unless they take certain steps and buy products that meet the regulations that we hope will soon be introduced, they are putting themselves at risk.

Jessica Eagleton: I would agree with what my fellow panellist has said. When we think about tech abuse, we see that awareness of it is quite low among the general public. In fact, in a survey we ran last year the results were that two thirds of women did not know where to go for information if they thought that a device in their home was compromised. There is a role there for that awareness piece. At Refuge, the approach we tend to take is to empower survivors to use technology safely and to take back control of their products and technology. We have developed a range of resources to do that, but we would welcome more work and more efforts on this more widely.