Recap: Thai Computer-related Crime Act
- Thai Computer-related Crime Act B.E. 2550 (2007)
- The Act Amending Thai Computer-related Crime Act B.E. 2560 (2017)— Where some sections are…
- Added
- Repealed
- Replaced
- Like other laws, computer law needs to be updated in order to prevent and suppress possible offences.
- This is due to rapid changes in technology which cause new and more complex forms of offences.
Structure of Thai Computer-related Crime Act
- พวก Definitions (Section 3) บอกไปแล้วใน Lecture 7 - Computer & Cyber Crime (Part I)
Lecture 7 - Computer & Cyber Crime (Part I) - Computer-related Offences (Section 5-17) → Discuss กันวันนี้!!!
- Competent Officials (Section 18-30)
Thai Computer-related Offences
Doors to Other Computer-related Crime Offenses
- The Thai Computer-related Crime Act B.E. 2550 and its amendment, B.E. 2560,
- Unauthorized Access (Section 5): Illegitimate entry into a computer system.
- Unauthorized Disclosure of Computer Data (Section 7): Improper revelation of computer data without proper authorization.
- Disclosure of Security Measures (Section 6): Violation of security measures protecting computer systems.
These offenses, as listed above, have the potential to lead to other computer-related crimes, emphasizing the interconnected nature of these legal provisions.
Unauthorized Access to Computer System
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 5: Whoever illegally accesses to a computer system that has specific security measures and such security measures are not intended for his/her use, shall be liable to an imprisonment for a term not exceeding six months, or a fine not exceeding ten thousand Baht or both.
มาตรา 5: ผู้ใดเข้าถึงโดยมิชอบซึ่งระบบคอมพิวเตอร์ที่มีมาตรการป้องกันการเข้าถึง โดยเฉพาะและมาตรการนั้นมิได้มีไว้สําหรับตน ต้องระวางโทษจําคุกไม่เกินหกเดือน หรือปรับไม่เกิน หนึ่งหมื่นบาท หรือทั้งจําทั้งปรับ
Components of the Offence
- Access
- Without right = illegal access
- Computer system
- that computer system has specific security measures which are not intended for the offender’s use
- Intention (เห็นมั้ย มาเองโดยไม่ต้องบอกเลย!— Internal Component, always.)
ทำไมเราต้องมา extract component แบบนี้ด้วยล่ะ? For fun? ไม่ช่ายยยย. In order to make that the case you’re analyzing that the case match with all the components stated here, in order to make a person liable
เหมือนกับ Legal Maxim ที่บอกว่า No crime no punishment without law, ไปฟังครูด้วย พูดดีมาก
Access (to a computer system)
- Physical access:
- Entry into computer systems within buildings, rooms, or other devices.
- Distinguished from the offense of trespass in the Thai criminal law code, with a focus on the specific subject matter of the offense. See below
If the offender broke into computer room to access computer system: Subject matter → Computer system
ถ้าบุกเข้าบ้านไปแล้ว Target อยู่ที่ Computer ไม่ใช่บ้าน (immovable property) ใช้กฎหมาย Section 5 ส่วนข้างล่างไม่ได้ apply
- Access to computer system of others:
- Instances where an individual, for example, person B, knows the password of another person's computer (person A) and uses it to access the computer without permission.
- Distant access:
- Achieved through the Internet, intranet, local area network (LAN)
- involving wire and wireless communication.
- Referred to as hacking or cracking, essentially constituting computer trespass.
The Criminal Code of Thailand #LawCode
Section 362: Whoever entering into the immovable property belonging to the other person so as to take the possession of such property in whole or in any part or entering into a property to do any act disturbing the peaceful possession of such person, he shall be imprisoned not over one year or fined not over twenty thousand Bath, or both.
มาตรา 362: ผู้ใดเข้าไปในอสังหาริมทรัพย์ของผู้อื่น เพื่อถือการครอบครองอสังหาริมทรัพย์นั้นทั้งหมดหรือแต่บาง ส่วน หรือเข้าไปกระทำการใด ๆ อันเป็นการรบกวนการครอบครองอสังหาริมทรัพย์ของเขาโด ยปกติสุข ต้องระวางโทษจำคุกไม่เกิน 1 ปี หรือปรับไม่เกิน 20,000 บาท หรือทั้งจำทั้งปรับ
^CCT362
Computer System
- ตามที่ได้ Mention Definition ไว้ใน Section 3 สรุปแล้วได้ว่า
- Computer system: includes hardware and software that is developed for processing of computer data. Computer system may refer to a single computer or many computers that are connected via networks. They can function automatically or following specific commands.
- Computer: refers to a computer as a device (hardware).
Specific Security Measures that is not Intended for the Offender’s Use
- Username
- Password
- Firewall
- Other measures for a security purpose to prevent an attack or unauthorized access.
Unauthorized Access to Computer Data
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 7: Whoever illegally accesses to a computer data that has specific security measures which are not intended for his/her use, shall be liable to an imprisonment for a term not exceeding two years, or a fine not exceeding forty thousand Baht or both.
มาตรา 7: ผู้ใดเข้าถึงโดยมิชอบซึ่งข้อมูลคอมพิวเตอร์ที่มีมาตรการป้องกันการเข้าถึง โดยเฉพาะและมาตรการนั้นมิได้มีไว้สําหรับตน ต้องระวางโทษจําคุกไม่เกินสองปี หรือปรับไม่เกินสี่หมื่นบาท หรือทั้งจําทั้งปรับ
Components
ง่าย ๆ ก็คือเหมือนกันเลยแหละ จะต่างกันตรงที่ Definition
- Access
- Without right = illegally access
- Computer data
- that computer data have specific security measures which are not intended for the offender’s use
- Intention
Computer Data
- Component of the offence are very similar to what provided for Section 5 of the same act apart from that…
Subject matter changed from ‘Computer system’ to ‘Computer data’
- Computer data: information, messages and concepts or instruction, a program or anything else in a form suitable for processing in a computer system and shall include electronic data under the law on electronic transaction. “Data message”
Disclosure of Security Measures
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 6: Whoever having knowledge of the security measures to access to a computer system created specifically by another person, wrongfully discloses, without right, such security measures in a manner that is likely to cause damage to another person, shall be liable to an imprisonment for a term not exceeding one year, or a fine not exceeding twenty thousand Baht or both.
มาตรา 6: ผู้ใดล่วงรู้มาตรการป้องกันการเข้าถึงระบบคอมพิวเตอร์ที่ผู้อื่นจัดทําขึ้นเป็นการเฉพาะ ถ้านํามาตรการดังกล่าวไปเปิดเผยโดยมิชอบในประการที่น่าจะเกิดความเสียหายแก่ผู้อื่น ต้องระวางโทษจําคุกไม่เกินหนึ่งปี หรือปรับไม่เกินสองหมื่นบาท หรือทั้งจําทั้งปรับ
Components
- Having knowledge of the security measures to access to a computer system created specifically by another person
- Wrongfully discloses the security measures, without right
- In a manner that is likely to cause damage to another person
- Intention (Internal Component)
Interference with Computer Data
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 9: Whoever illegally acts in a manner that causes damage, impairment, deletion, alteration or addition either in whole or in part of computer data of another person, shall be liable to an imprisonment for a term not exceeding five years, or a fine not exceeding one hundred thousand Baht or both.
มาตรา 9: ผู้ใดทําให้เสียหาย ทําลาย แก้ไข เปลี่ยนแปลง หรือเพิ่มเติมไม่ว่าทั้งหมด หรือบางส่วน ซึ่งข้อมูลคอมพิวเตอร์ของผู้อื่นโดยมิชอบ ต้องระวางโทษจําคุกไม่เกินห้าปี หรือปรับ ไม่เกินหนึ่งแสนบาท หรือทั้งจําทั้งปรับ
Components
- Causes damage, impairment, deletion, alteration or addition either in whole or in part
- Computer data of another person
- Illegally (without right)
- Intention
Examples
- Changing data
- Deleting data
- Altering websites
- A creation of “salami techniques”
- Salami Techniques วิธีการปัดเศษจำนวนเงิน เช่น ทศนิยมตัวที่ 3 หรือปัดเศษทิ้งให้เหลือแต่จำนวนเงินที่สามารถจ่ายได้ แล้วนำเศษทศนิยมหรือเศษที่ปัดทิ้งมาใส่ในบัญชีของตนเองหรือของผู้อื่นซึ่งจะทำให้ผลรวมของบัญชียังคงสมดุลย์ (Balance) และจะไม่มีปัญหากับระบบควบคุมเนื่องจากไม่มีการนำเงินออกจากระบบบัญชี นอกจากใช้กับการปัดเศษเงินแล้ววิธีนี้อาจใช้กับระบบการตรวจนับของในคลังสินค้า
- Logic bombs
Service Provider
- เช่นเคย เคยเขียน Definition ไปแล้วใน Lecture 7 - Computer & Cyber Crime (Part I)
Examples
- Examples of service providers in category (1) include:
- Telecommunication and broadcast carriers
- Fixed line service providers (e.g., TOT → NT)
- Mobile service providers (e.g., AIS)
- Leased circuit service providers (e.g., providers of leased lines and fiber optics)
- Satellite service providers (e.g., Thaicom)
- Access service providers
- Internet service providers (directly providing internet access to customers)
- Service providers offering access in specific places (e.g., restaurants, hotels)
- Service providers offering access within organizations (e.g., universities, companies)
- Host service providers (web hosting, web server, mail server service providers)
- Internet stores, internet cafes, online game stores
- Examples of service providers in category (2) include:
- Content service providers (e.g., application service providers)
- Web boards, blogs
- Internet banking
- Electronic commerce
- Electronic transaction
Offences of Service Provider
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 15: A service provider, who cooperates, consents or supports the perpetration of the offences under Section 14 by using a computer system under his/her control, shall be liable to the same penalty as the offender under Section 14.
(Paragraph 2) The Minister shall issue a Notification specifying the process of warning, as well as blocking the dissemination of such computer data and removal of such computer data from the computer system.
(Paragraph 3) A service provider who can prove that he/she has complied with the notification of the Ministry issued under Paragraph 2, shall not be subject to the penalty.
มาตรา 15: ผู้ให้บริการผู้ใดให้ความร่วมมือ ยินยอม หรือรู้เห็นเป็นใจให้มีการกระทําความผิดตามมาตรา 14 ในระบบคอมพิวเตอร์ที่อยู่ในความควบคุมของตน ต้องระวางโทษ เช่นเดียวกับผู้กระทําความผิดตามมาตรา 14
(วรรค 2) ให้รัฐมนตรีออกประกาศกําหนดขั้นตอนการแจ้งเตือน การระงับการทําให้แพร่หลายของข้อมูลคอมพิวเตอร์ และการนําข้อมูลคอมพิวเตอร์นั้นออกจากระบบคอมพิวเตอร์
(วรรค 3) ถ้าผู้ให้บริการพิสูจน์ได้ว่าตนได้ปฏิบัติตามประกาศของรัฐมนตรีที่ออกตามวรรคสองผู้นั้นไม่ต้องรับโทษ
Duties of Service Provider
Thai Computer-related Crime Act B.E. 2550 and The Act Amending Thai Computer-related Crime Act B.E. 2560 #LawCode
Section 26: A service provider shall maintain traffic data for a period not less than ninety days as from the date on which such data was entered into the computer system. If necessary, the competent official may, on case by case basis for particular cases and certain situations, order any service provider to maintain computer traffic data for a period longer than ninety days but not exceeding two years.
มาตรา 26: ผู้ให้บริการต้องเก็บรักษาข้อมูลจราจรทางคอมพิวเตอร์ไว้ไม่น้อยกว่า 90 วัน นับแต่วันที่ข้อมูลนั้นเข้าสู่ระบบคอมพิวเตอร์ แต่ในกรณีจําเป็น พนักงานเจ้าหน้าที่จะสั่งให้ผู้ให้บริการผู้ใดเก็บรักษาข้อมูลจราจรทางคอมพิวเตอร์ไว้เกิน 90 วันแต่ไม่เกิน 2 ปีเป็นกรณีพิเศษเฉพาะรายและเฉพาะคราวก็ได้
- บางครั้งอาจจะให้เก็บเฉพาะรายและเฉพาะคราวก็อาจจะพวกที่ หลักฐานที่ต้อง Investigate หรือใน Lawsuit อะไรก็ตาม
Note
Cyberbully—
Salami slicing—
Spoofing—
Espionage—
Legal Maxims
Exterior Act Indicates Interior Secret
Intention may be inferred from a person's action
- Legal Maxims มันคืออะไรกันแน่?