Follow the rules – unless you shouldn’t follow the rules

Opinion
Jul 11, 20063 mins

* Peculiar ruling on file-deletion case

Declan McCullagh summarized an interesting interpretation of law that occurred in the U.S. Court of Appeals for the 7th Circuit in March. It seems that Jacob Citrin used to work for International Airport Centers. He quit and returned his laptop computer to them. They prepared to sue him for allegedly violating his employment contract by going into business for himself in the same field.

When they searched his hard drive looking for juicy files to undelete as part of their preparation for the civil case, they discovered that he had wiped files rather than deleted them: the old files were unrecoverable. So they accused him of violating the Computer Fraud and Abuse Act of 1986. The company’s first attempt at the lawsuit must have been dismissed, because they appealed to the Court of Appeals.

McCullagh wrote:

“That law says whoever ‘knowingly causes damage without authorization’ to a networked computer can be held civilly and criminally liable. The 7th Circuit made two remarkable leaps. First, the judges said that deleting files from a laptop counts as ‘damage.’ Second, they ruled that Citrin’s implicit ‘authorization’ evaporated when he (again, allegedly) chose to go into business for himself and violate his employment contract.”

McCullagh mused, “The implications of this decision are broad. It effectively says that employees better not use OS X’s Secure Empty Trash feature, or any similar utility, because they could face civil and criminal charges after they leave their job.”

Judge Richard Posner wrote:

“Citrin points out that his employment contract authorized him to ‘return or _destroy_’ data in the laptop when he ceased being employed by IAC (emphasis added). But it is unlikely, to say the least, that the provision was intended to authorize him to destroy data that he knew the company had no duplicates of and would have wanted to have – if only to nail Citrin for misconduct. The purpose of the provision may have been to avoid overloading the company with returned data of no further value, which the employee should simply have deleted.”

The fundamental question of fact that the court proceedings will surely involve now that the lawsuit has been reinstated is whether the file deletions occurred before or after the employee left his employment. If a court rules that using secure deletion of files _during_ employment is a crime, all of us security folks who have been insisting on the value of wiping vs. erasing will be in big trouble.

If explicit authorization to destroy data upon termination of an employment relationship does not authorize an employee to destroy data upon termination of an employment relationship, we had better be awfully careful about framing security policies and doubly careful about following them. Shall we send a memorandum to corporate attorneys before _obeying_ security policies from now on?

I hope their spam filters won’t be too selective.