Rethinking legal privacy framework: a call to arms

Opinion
Jun 6, 20053 mins

The courts and Congress are arriving at a crossroads: Either they can try to retrofit the new computer and information technology pegs into the old telephone policy holes, or we can collectively agree to rethink the meaning of privacy in the 21st century. I’m voting for the latter. But the courts and legislators can’t do it alone. They need to hear from us.

I noted recently that we need to rethink the broader public policy on information stewardship in the context of 21st century technology.

That’s no small task. It affects everything from our understanding of the Fourth and First Amendments to local and national law-enforcement and anti-terrorism initiatives.

This might sound a wee bit “out of scope” for IT executives (let alone for us networking pundits). But here’s the thing: As the ones who best understand the potentials and pitfalls of technology, we have a particular obligation to speak up, because we’re approaching a policy crossroads.

And as they say, the devil’s in the details. For example, in a widely quoted piece that appeared in last month’s Communications of the ACM, security guru Bruce Schneier warned, “The police need a warrant to read the e-mail on your computer, but they don’t need one to read it off the back-up tapes at your ISP.”

Schneier is making a specific point, and his comment is 100% correct. But a casual reader might mistakenly arrive at the erroneous conclusion that the police can walk in off the street and start reading your e-mail.

Not quite. In the case of U.S. vs. Lifshitz, courts ruled the government can gain access to stored e-mails by warrant, court order or subpoena. In other words, the cops don’t need an actual warrant, but they do need either a subpoena or a court order. The distinction’s important because it’s much harder to get a warrant than a subpoena. Warrants require probable cause; subpoenas don’t.

The bottom line is it’s not as if the cops can walk in off the street and start rifling through your e-mail. But the barriers to government surveillance are much lower than you might have thought.

It gets worse. The courts have made confusing and increasingly contradictory distinctions about which communications are protected and which aren’t. There’s the distinction between “temporarily” stored e-mails (on a server) vs. backed-up e-mails (on tape drives), with lower standards for protection of the latter. Ditto stored “content” – the text body of a message – and less-protected “records and information” – the e-mail, IP and geographical addresses of the senders and recipients. Finally, there’s the looming question of VoIP. Wiretapping laws govern “wire” transmissions (voice calls) but not e-mail. But adding voice to an e-mail changes the e-mail from an electronic communication to a more stringently protected voice communication.

There’s a great rundown of these issues in a story in American Bar Association magazine.

The authors conclude that the courts and Congress are arriving at a crossroads: Either they can try to retrofit the new computer and information technology pegs into the old telephone policy holes, or we can collectively agree to rethink the meaning of privacy in the 21st century.

I’m voting for the latter. But the courts and legislators can’t do it alone. They need to hear from us.