home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:2260 comp.org.eff.talk:7676 alt.society.civil-liberty:6919
- Path: sparky!uunet!usc!cs.utexas.edu!sun-barr!olivea!spool.mu.edu!hri.com!enterpoop.mit.edu!eru.mt.luth.se!lunic!sunic!mcsun!news.funet.fi!funic!nntp.hut.fi!usenet
- From: jkp@cs.HUT.FI (Jyrki Kuoppala)
- Newsgroups: comp.security.misc,comp.org.eff.talk,alt.society.civil-liberty
- Subject: Re: CERT's login banner
- Message-ID: <1992Dec15.130027.22770@nntp.hut.fi>
- Date: 15 Dec 92 13:00:27 GMT
- References: <143411@lll-winken.LLNL.GOV>
- Sender: usenet@nntp.hut.fi (Usenet pseudouser id)
- Reply-To: jkp@cs.HUT.FI (Jyrki Kuoppala)
- Organization: Helsinki University of Technology, Finland
- Lines: 51
- In-Reply-To: karyn@cheetah.llnl.gov (Karyn Pichnarczyk)
- Nntp-Posting-Host: lusmu.cs.hut.fi
-
- In article <143411@lll-winken.LLNL.GOV>, karyn@cheetah (Karyn Pichnarczyk) writes:
- >What about this example:
- >
- >Joe works for company X. He is using their computers to calculate
- >payroll for a company Y that he owns and is in no way related to
- >Company X. He knows he is "not supposed" to do this because something
- >like that is in the policy of the company. Because of this, he does
- >his payroll after normal business hours.
- >
- >The system admin of company X gets suspicious of some random cracking
- >activity on computer systems (unrelated to Joe). Sysadmin decides
- >that since all cracking activity happens after normal business hours,
- >and since no users claim to use the computer after hours, keyboard
- >monitoring of all after hours users takes place and thus Joe's payroll
- >activity is discovered.
- >
- >Questions for comp.security.misc:
- >
- >1. Is this invasion of privacy?
-
- If the policy of monitoring is announced, I don't think so. If it
- isn't, it might be - if it's OK to use the computer after hours, it
- is, but if it's against company policy to use the computer after hours
- then I don't think it's that bad.
-
- >2. What if Joe's business is a random legal business?
- >3. What if it's an illegal Drug Ring?
-
- All possessions of companies X, Y and Joe will be instantly forfeited
- to the government and all employees will spend life in jail?
-
- Actually, I think 2. is worse since you can easily hire a company to
- do payroll for a normal company - with 3. it's understandable that one
- wants to hide the business because of the fascist laws.
-
- In both cases, the reasonable thing to do in my opinion would be for
- company X to give Joe a severe warning or perhaps sack him for
- violating a company policy by using equipment for non-company use.
- The fascist laws probably require the company X to report Joe to the
- authorities in 3., however, or the company itself will get in trouble.
- Or if it's 3. and the profits are good, perhaps ask Joe to buy some
- new and better computers for company X and let Joe have the old ones
- and say he can keep his job if the use of company resources will end ;-)
-
- >4. Do you think CERT's banner might make a difference in the legal
- >hassles?
-
- No idea, but the Justice Dept. seems to think it will, and I guess
- they have some expertise/influence on the topic.
-
- //Jyrki
-