home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.org.eff.talk:7747 alt.comp.acad-freedom.talk:3792 comp.security.misc:2318
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!cs.utexas.edu!sun-barr!olivea!spool.mu.edu!agate!stanford.edu!rock!concert!duke!news.duke.edu!ee.egr.duke.edu!jpe
- From: jpe@ee.egr.duke.edu (John P. Eisenmenger)
- Newsgroups: comp.org.eff.talk,alt.comp.acad-freedom.talk,comp.security.misc
- Subject: Re: CERT and the Dept. of Justice on keystroke monitoring
- Message-ID: <jpe.724599105@ee.egr.duke.edu>
- Date: 17 Dec 92 13:31:45 GMT
- References: <1992Dec13.085734.19916@news.Hawaii.Edu> <mt_rrwn@dixie.com> <1992Dec14.180915.13795@cc.ic.ac.uk> <1992Dec16.192639.12991@eecs.nwu.edu>
- Sender: news@news.duke.edu
- Followup-To: comp.org.eff.talk
- Lines: 48
- Nntp-Posting-Host: ee.egr.duke.edu
-
- mack23@avalon.eecs.nwu.edu (Chris Walsh) writes:
-
- >P.S. How would you feel about the adminstrators of a router doing the same
- >kind of thing, assuming that this router tied together traffic from many
- >diverse autonomous entitities? I see no logical reason to argue against it,
- >assuming for a moment that the property rights crowd is correct. The
- >privacy ramifications *there* give one pause.
-
- I think at issue here is the implicit acceptance of monitoring by anyone who
- uses the system. This wouldn't be so bad if the admins were held accountable
- for their actions and had some sort of requirements to meet before monitoring
- a user's (or tty's, network's, etc.) actions. Such a code of ethics must
- prevail in order for users to feel secure in their environment.
-
- Unfortunately this banner is the equivalent of James Bond's "License to Kill"
- -- allowing the sys admin to do anything s/he d*mn well pleases in the hopes
- of catching "unauthorized" users or uses of the system. There is some shady
- references to conditions, but the conditions are not explicitly stated. I'm
- not saying this banner is useless -- you can't print the policy guide on every
- user's screen when they login, but some reference to the policy guide is
- clearly in order.
-
- I am not a lawyer, nor will I pretend to be, but something like the following
- should be in the banner:
-
- It is assumed that users of this system are doing so in accordance
- with usage guidelines set forth in the policy guide (available
- online in the file .../policies.txt). The administration reserves
- the right to monitor an individual's interaction with this machine
- should evidence warrant such investigative tactics.
-
- I don't think there's a clear win here either, but a banner should not
- attempt to give a broad legal license. Without a specific policy guide
- and rulebook for investigations you have no business putting the CERT/DoJ
- banner on your system.
-
- -John
-
- --
- *************************************************************************
- * John P. Eisenmenger Phone: (919) 660-5248 *
- * Duke University FAX: (919) 660-5293 *
- * Department of Electrical Engineering Email: jpe@egr.duke.edu (pref) *
- * Box 90291 jpe@cs.duke.edu *
- * Durham, NC 27708-0291 *
- * *
- * Reports of problems w/EE systems should go to problem@egr.duke.edu *
- *************************************************************************
-