Be cautious – be very, very cautious

Opinion
Oct 7, 20094 mins

In our last newsletter we discussed how our research into cloud computing had sensitized us to the overwhelming concern that IT organizations have for the security and privacy of their data. We also began to analyze how the US government has been gaining increasing power to access data that once appeared to be private. In this newsletter, we will continue that analysis and will also discuss what this means for IT organizations.

In our last newsletter we discussed how our research into cloud computing had sensitized us to the overwhelming concern that IT organizations have for the security and privacy of their data. We also began to analyze how the U.S. government has been gaining increasing power to access data that once appeared to be private. In this newsletter, we will continue that analysis and will also discuss what this means for IT organizations.

U.S. gov’t panel calls for new privacy rules

In our last newsletter we quoted an interesting article in the UCLA Journal of Law and Technology by Matthew Lawless. The article explains that the third party doctrine provides that information “knowingly exposed” to a third party is not subject to Fourth Amendment protection because one “assumes the risk” that the third party will disclose that information to the government.

One of the cases that Lawless discusses in that article involves federal law enforcement officials issuing subpoenas to two banks to produce a customer’s financial records. The defendant contended this constituted a violation of his Fourth Amendment rights. The court disagreed: it held that the customer lacked a reasonable expectation of privacy in the financial records maintained by his bank, because those records where voluntary conveyed by the customer, and exposed to the bank’s employees in the ordinary course of business.

Another case that Lawless discusses involves a robbery victim who received threatening and obscene telephone calls from a man identifying himself as the robber. Law enforcement officials subsequently used a pen/trap register at the phone company’s headquarters to trace the calls dialed by the suspect at his home. The evidence obtained implicated the suspect; charges were brought; and the defendant sought to have the evidence excluded on Fourth Amendment grounds. The court denied the defendant’s motion, holding that individuals lack a reasonable expectation of privacy in the phone numbers they dial because people know they must convey that information to the phone company and thus “cannot harbor any general expectation that the numbers they dial will remain secret.”

Neither Steve nor Jim are lawyers and it is not our intention to discuss the ethical or legal issues associated with the two cases described above. However, those cases do raise some important issues for an IT organization that is looking to utilize public cloud computing services. The exact definition of cloud computing is somewhat fuzzy. However, it is generally agreed that public cloud computing refers to an IT organization utilizing some form of a WAN to access IT resources provided by a third party. 

For the sake of example, let’s assume that a company called Acme uses the Internet to access Salesforce.com. If the government is investigating some issue, even if it has nothing to do directly with Acme, can the government get access to data about Acme from the ISP? From Salesforce.com? Does it take a subpoena to get that data or will something less suffice? Will Acme be told if the government or some other entity has a copy of its data? What safeguards will the entity use to keep Acme’s data confidential? Is there any requirement that the entity that has a copy of Acme’s data destroy that data at some point in time?

These are just a few of the questions that IT organizations need to ask their network service providers and their cloud computing service providers. We should point out that while we do see tremendous potential in the use of public cloud computing services, we do advise IT organizations to be cautious – to be very, very cautious.

Jim has a broad background in the IT industry. This includes serving as a software engineer, an engineering manager for high-speed data services for a major network service provider, a product manager for network hardware, a network manager at two Fortune 500 companies, and the principal of a consulting organization. In addition, Jim has created software tools for designing customer networks for a major network service provider and directed and performed market research at a major industry analyst firm. Jim’s current interests include both cloud networking and application and service delivery. Jim has a Ph.D. in Mathematics from Boston University.

More from this author