[00:00.000 --> 00:04.440] This is Network Monitoring and the Law with Alex Muentz. [00:13.380 --> 00:18.630] Hi, sorry everything's late, but can you switch the video? [00:19.540 --> 00:20.020] Thanks. [00:22.840 --> 00:24.080] Here's a standard disclaimer. [00:25.840 --> 00:27.260] I'm going to discuss U.S. [00:27.400 --> 00:27.780] federal law. [00:27.920 --> 00:33.520] There is some state law that sort of depends on federal law or mirrors it, but every state has its own laws. [00:33.520 --> 00:41.360] If you're hit up for something in state X, always talk to an attorney in that state. [00:41.940 --> 00:43.500] This isn't legal advice. [00:43.940 --> 00:46.960] If you have questions, talk to a lawyer in your jurisdiction. [00:47.160 --> 00:48.840] There may be some weird little wrinkle locally. [00:49.200 --> 00:53.280] Also, what I'm going to tell you today may change tomorrow. [00:54.000 --> 01:01.200] As of midnight last night, I was reading an opinion out of the Ninth Circuit about the FISA court. [01:03.560 --> 01:04.360] Thanks, everyone. [01:04.900 --> 01:05.640] Thanks to all of you. [01:05.820 --> 01:07.190] Thanks to the people who organized HOPE. [01:07.460 --> 01:14.140] I also want to thank the Third Circuit Executive's Office for funding this research and, of course, my own law school. [01:15.500 --> 01:15.980] Okay. [01:16.340 --> 01:16.820] Overview. [01:18.460 --> 01:22.260] I base most of this talk on what a sysadmin or network engineer can look at. [01:24.000 --> 01:31.480] As your rights kind of depend on where, you know, how close you are to being someone who's authorized to look at traffic. [01:32.220 --> 01:34.120] So figure yourself accordingly. [01:34.480 --> 01:37.600] I want to talk about what protected traffic is and what isn't. [01:38.360 --> 01:41.500] And how can you protect yourself and your organization? [01:42.240 --> 01:43.720] And what does the future hold? [01:43.720 --> 01:46.960] I'll try to make some half-assed guesses of what the future will say. [01:48.280 --> 01:48.760] Okay. [01:49.020 --> 01:53.580] There are a couple important statutes that really determine what your rights are vis-a-vis the network. [01:54.360 --> 01:55.600] Fourth Amendment of the U.S. [01:55.700 --> 01:57.140] Constitution is kind of an important one. [01:57.420 --> 01:58.620] Still, we hope. [02:00.260 --> 02:06.400] The Wiretap Act, which has been amended by the Electronic Communications Privacy Act. [02:07.380 --> 02:09.290] The Stored Communications Act. [02:11.110 --> 02:13.950] The definitions of a pen register and trap and trace. [02:14.110 --> 02:15.420] And I'll go into what those are in a bit. [02:15.820 --> 02:19.100] And then there are state and local statutes that affect your rights as well. [02:20.730 --> 02:21.570] Fourth Amendment. [02:22.200 --> 02:23.380] We still have one. [02:24.200 --> 02:25.140] What's left of it? [02:25.760 --> 02:27.160] Right of the people to be secure. [02:27.160 --> 02:30.350] Now, persons, houses, papers, and effects. [02:30.640 --> 02:31.660] Doesn't say packets. [02:31.820 --> 02:33.140] Doesn't say electronic communications. [02:33.350 --> 02:34.330] It says papers and effects. [02:35.450 --> 02:38.760] I'm going to go into how this has changed over the years. [02:39.790 --> 02:42.070] But against unreasonable searches. [02:42.350 --> 02:43.610] A reasonable search is allowed. [02:43.880 --> 02:45.460] Doesn't say warrantless search. [02:47.020 --> 02:48.550] Some things it doesn't apply to. [02:48.640 --> 02:50.540] Does not apply to non-governmental actors. [02:51.140 --> 02:54.680] If AT&T looks at your stuff, completely different rules. [02:54.900 --> 02:56.460] The Fourth Amendment no longer applies. [02:56.460 --> 03:01.770] If AT&T at bequest of the federal government looks at your stuff, then it does apply. [03:03.120 --> 03:13.180] However, even for private actors looking at your communications, there are state laws that prevent what's known as intrusion to seclusion. [03:15.720 --> 03:18.180] Now, I'm going to go into a little bit of a history lesson. [03:18.320 --> 03:22.900] Because the way the Fourth Amendment has been interpreted has changed over the years. [03:22.900 --> 03:24.480] This is an old rule. [03:24.760 --> 03:26.360] This is no longer current law. [03:26.460 --> 03:27.710] But I want to show Olmstead. [03:27.930 --> 03:34.580] Because the idea was, of course you have no privacy rights in this newfangled telephone thing. [03:34.640 --> 03:42.210] Because you're broadcasting your thoughts, your statements, on wires that leave your house and go outside. [03:43.320 --> 03:46.860] And it's not unreasonable for the police to tap that. [03:46.930 --> 03:48.110] Because you offered it. [03:48.240 --> 03:49.900] It's like broadcasting it. [03:50.800 --> 03:57.460] And that was because 1928, not that, you know, the phone was not yet completely endorsed by everybody. [03:57.660 --> 03:59.260] Not everyone had a phone in their house. [04:00.740 --> 04:01.540] Roll around. [04:01.710 --> 04:03.550] And that was the law until 1967. [04:03.830 --> 04:05.330] When, same thing happens. [04:05.700 --> 04:06.040] Cats. [04:07.320 --> 04:08.270] Guy's a bookie. [04:08.640 --> 04:11.180] Guy's making phone calls, placing and taking bets. [04:12.050 --> 04:14.660] Police under Olmstead say, I can tap that. [04:14.920 --> 04:16.460] Put a tap on his phone line. [04:16.600 --> 04:17.620] No warrant, no nothing. [04:17.770 --> 04:24.680] And they go, you know, really I think the framers of the Constitution would imply that you do have a privacy right in your phone. [04:24.880 --> 04:26.220] The law doesn't change. [04:26.380 --> 04:27.440] Same Fourth Amendment. [04:27.440 --> 04:30.580] All of a sudden the court says, eh, no. [04:30.820 --> 04:32.060] You have a privacy right now. [04:32.200 --> 04:36.220] So now it is unreasonable to tap your lines without a warrant. [04:38.080 --> 04:43.760] And it's a fairly strong, it's a, this holding kind of is important for future use. [04:43.960 --> 04:49.660] Because it's, is there, do you have an expectation of privacy that you expect? [04:49.900 --> 04:53.220] And then do you have an expectation of privacy that society expects? [04:54.000 --> 05:00.560] And we can establish this rule kind of further on to, can the feds sniff your email? [05:00.800 --> 05:04.660] Can they sniff what pack, what, what, you know, what websites you're looking at? [05:06.860 --> 05:08.740] So we have the Wiretap Act. [05:08.920 --> 05:11.800] This is passed in 1968 after the CATS opinion. [05:12.060 --> 05:14.200] And it effectively codifies CATS. [05:15.370 --> 05:16.940] It's updated twice. [05:17.200 --> 05:19.580] It's updated in 1986 when they make it. [05:19.640 --> 05:20.980] It's no longer just phones. [05:21.160 --> 05:22.700] It's electronic communication. [05:23.480 --> 05:27.460] And it's updated again in 2001 by the USA PATRIOT Act. [05:28.940 --> 05:33.780] I threw this in last minute because FISA is kind of of interest right now. [05:33.780 --> 05:35.160] I'll go a little bit into FISA. [05:37.640 --> 05:39.980] Now, this is kind of the guts of the Wiretap Act. [05:40.280 --> 05:42.680] Interception is acquisition of the contents. [05:42.980 --> 05:45.100] And I highlighted that because it's kind of important. [05:45.260 --> 05:49.740] Of any electronic or oral communication through any device. [05:50.080 --> 05:51.480] Really, really, really vague. [05:51.700 --> 05:52.900] I don't know what this means. [05:53.040 --> 05:54.480] The courts don't know what it means. [05:54.740 --> 05:58.260] Does this mean that the feds can't even sniff one packet? [05:58.620 --> 06:01.160] Maybe, if it grabs the contents of the data. [06:02.500 --> 06:06.000] There's a holding in Steve Jackson Games vs. Secret Service. [06:06.880 --> 06:10.200] Which is probably the landmark case in interception claims. [06:10.760 --> 06:14.880] Not only because it set the precedent that's followed in almost every state. [06:15.220 --> 06:18.400] It's also the... this is the case that founded the EFF. [06:18.940 --> 06:22.360] You know, people were pissed off about this case and said, Damn it, I want to do something about it. [06:23.560 --> 06:31.580] Under the Wiretap Act, you're facing up to five years in prison if you violate the Wiretap Act. [06:31.900 --> 06:34.260] Even if you're law enforcement, if you violate it. [06:35.080 --> 06:40.360] And victims may sue for whatever damages they have and the legal fees in the suit. [06:41.680 --> 06:48.460] Also, you're protect... there's an exclusionary rule that says that evidence taken under this is inadmissible in federal court. [06:50.900 --> 06:52.700] Now, what does interception look like? [06:52.700 --> 06:55.060] And I've got a, you know, half-assed map up here. [06:55.380 --> 06:57.740] Say A is sending email to B. [06:59.080 --> 07:07.080] If... you know, it goes... it goes from A's personal PC to the mail server, to the Internet, to B's mail server, down to B. [07:07.540 --> 07:09.780] C wants to read the mail before B does. [07:10.820 --> 07:12.060] That would be interception. [07:12.240 --> 07:13.640] It's grabbing it on the Wire. [07:13.860 --> 07:17.300] And this was sort of an important rule out of Steve Jackson. [07:17.300 --> 07:23.300] If C sniffs it while it's being transmitted, it's interception under the Wiretap Act. [07:23.700 --> 07:30.240] If he gets it there, if he gets it between, you know, on the LAN between B's mail server and B. [07:30.820 --> 07:36.760] But if he hack... if he somehow gets access to B's mail server, pulls it out of storage. [07:36.780 --> 07:39.220] Say, for example, B is a pop client. [07:40.820 --> 07:43.300] It's stored waiting for B to pop in. [07:44.020 --> 07:47.040] C gets in, reads the mail, not interception. [07:47.460 --> 08:02.100] That was the case in Steve Jackson, where the feds came in without a warrant, took Steve Jackson's mail server, read the mail on it, deleted some mail, before it ever got to the actual owners, and the court said, that's not interception. [08:02.100 --> 08:08.520] Any storage is... any taking from storage is not interception under the rule. [08:10.320 --> 08:15.100] There are a couple of interception exceptions that allows you to intercept mail under... [08:15.700 --> 08:18.840] or intercept, sorry, any electronic communication, no matter what. [08:19.400 --> 08:21.840] If you're the recipient, you're allowed to look at it. [08:22.040 --> 08:26.100] It's one of those odd things, but I think they want to prevent, you know... [08:26.860 --> 08:29.080] If you're allowed to sniff your own traffic. [08:30.140 --> 08:31.260] Service provider. [08:31.540 --> 08:35.020] Now, this is sort of a fluid term, and I'll show you later. [08:36.050 --> 08:38.790] Agents and employees of the service provider. [08:39.070 --> 08:43.330] To provide service, to protect the rights, and the facilities. [08:43.640 --> 08:48.740] So, you're allowed to look at traffic if you're an ISP employee. [08:48.880 --> 08:58.690] You're allowed to look at the contents of communication to protect your own system, or your customers, or other people attached to your network. [08:58.690 --> 09:06.190] So, if you're afraid that some... one of your users is sending out viruses or spam, you're allowed to look for that... [09:06.190 --> 09:09.280] Because what you're doing is you're protecting other networks attached to yours. [09:09.430 --> 09:11.590] Which, theoretically, would be any network. [09:13.470 --> 09:17.190] There's this rule to determine the source of harmful electronic interference. [09:17.520 --> 09:21.810] This seems to be talking about radio, but I've not seen any cases that talk about it. [09:21.810 --> 09:22.950] So, who knows? [09:24.540 --> 09:34.120] You may also... and anyone may allow either fed or state agency to come in and sniff your own packets. [09:34.140 --> 09:45.310] If you either lack the capability or you want to set this up for some kind of law enforcement action, you are allowed to grant to a law enforcement agency without a warrant, you may sniff my packets. [09:46.670 --> 09:50.140] And then there's the final one, pursuant to a valid FISA court order. [09:52.520 --> 09:53.920] I'll go a little bit into FISA. [09:55.040 --> 09:57.810] Special secret court, the proceedings are sealed. [09:58.620 --> 10:02.120] You may grant an interception order without input from the target. [10:02.450 --> 10:10.330] Anyone who is given a valid FISA order, if you are an ISP and feds come in and say this is a valid FISA order, you must keep your mouth shut. [10:12.740 --> 10:16.970] However, interceptions without a valid warrant are illegal, even if under color of law. [10:17.500 --> 10:23.260] I'm a fed, I have a fake FISA order, I go to Verizon and say, I want to sniff some packets. [10:23.970 --> 10:25.330] It's still a violation. [10:26.440 --> 10:29.210] Verizon's protected because it's, I thought it was good. [10:29.400 --> 10:31.550] You know, how am I supposed to know what a valid FISA order is? [10:31.620 --> 10:33.090] Because you're not allowed to look at them. [10:34.050 --> 10:37.050] But it's five years imprisonment, $10,000 fine. [10:37.310 --> 10:41.450] Law enforcement officers are not immune from this. [10:42.520 --> 10:52.070] So it should be interesting, considering that the Ninth Circuit just said that there is no state secrets about the various wiretap brouhaha going on. [10:52.210 --> 10:55.050] So we may actually see some NSA agents getting arrested. [10:55.820 --> 10:56.590] Or not. [10:58.400 --> 11:00.280] Okay, there is an exception. [11:01.360 --> 11:12.800] The Attorney General or the President may order warrantless interception if known that it's between foreign powers and agents thereof. [11:13.840 --> 11:19.500] There has to be some finding that you are an agent or you are a foreign power. [11:20.230 --> 11:24.710] I like the second line, and I'm curious to see how this plays out. [11:25.320 --> 11:30.850] No substantial likelihood of intercepting communications of Americans or American companies. [11:31.240 --> 11:33.500] So foreign subsidiary of a U.S. [11:33.660 --> 11:35.960] company is also protected under FISA. [11:37.850 --> 11:43.970] Even with this special warrantless exception, the AG must go to Congress within 30 days. [11:43.970 --> 11:47.780] There's this emergency within 15 days of declaration of war. [11:50.400 --> 11:56.320] Clearly what's happening, if it all plays out with this AT&T case, clearly there's some violations here. [11:57.000 --> 12:03.090] I'm not sure who's going to actually prosecute it because it's the same Attorney General, but we'll see. [12:03.280 --> 12:06.210] Maybe, you know, 2008 there's a change of regime. [12:07.420 --> 12:09.580] Okay, back to what we have to deal with. [12:09.740 --> 12:11.180] Stored Communications Act. [12:12.220 --> 12:14.960] This is sort of the counterpart to interception. [12:15.160 --> 12:18.280] This is what happens if you grab something while it's in storage. [12:18.740 --> 12:23.020] This is kind of one half of the federal anti-hacking law. [12:23.440 --> 12:30.940] There's also the, sorry, Computer Fraud and Abuse Act, which I'm not going to go into because there are so many cases on that, it's also fairly settled. [12:30.960 --> 12:34.210] But it's accessing a stored communications service. [12:35.490 --> 12:39.540] Not really sure what that is because it's kind of vague. [12:39.800 --> 12:43.460] But it would seem to be an ISPs, mail server. [12:43.680 --> 12:48.700] It could be anything that material or data is stored on, even temporarily. [12:49.280 --> 12:50.970] There's an incidental rule. [12:51.240 --> 12:57.920] So theoretically, even pulling out of the memory buffer of a router would be stored communications before it's forwarded. [12:59.240 --> 13:01.120] There's an interesting split here. [13:01.120 --> 13:04.350] There's a, if done for profit, there's a greater offense. [13:04.520 --> 13:05.460] It's a greater penalty. [13:05.460 --> 13:07.830] If done for other reasons. [13:08.500 --> 13:10.960] And the exceptions are much broader. [13:11.460 --> 13:12.820] The owner of the service. [13:13.260 --> 13:17.210] So it's not just provider for protection of the system. [13:17.400 --> 13:18.540] It's, I own the router. [13:18.740 --> 13:19.680] I can look what I want. [13:20.300 --> 13:21.830] No, I'm doing to protect it. [13:21.960 --> 13:24.580] I can, I could claim to be, I'm being nosy. [13:24.800 --> 13:25.620] I'm Verizon. [13:25.620 --> 13:27.740] I want to see what you're storing on the mail server. [13:28.160 --> 13:29.320] Perfectly acceptable. [13:29.920 --> 13:31.420] I can't sniff it. [13:31.580 --> 13:33.880] But I can look at it while it's stored on my mail server. [13:34.420 --> 13:37.760] And then there's the, if you're accessing your own stuff. [13:38.180 --> 13:47.400] So theoretically, if Verizon, for example, holding your data, holding your email, you cancel your account. [13:47.400 --> 13:50.740] You could then go back in and get what your mail is. [13:53.830 --> 13:59.080] Providers may also, what they, they're limited in what they can divulge to a third party. [14:00.470 --> 14:05.200] They can divulge content to a recipient or provide, or forward communication. [14:05.500 --> 14:06.640] Which is kind of an obvious rule. [14:06.820 --> 14:09.160] Like, you know, we hold this data. [14:09.320 --> 14:11.850] We're allowed to give it to you because you're the intended recipient. [14:12.020 --> 14:12.900] Well, that's your job. [14:13.060 --> 14:14.120] That's why we hired you. [14:15.680 --> 14:28.620] But providers may not intentionally divulge content of the fact that a transmission occurred unless there's an intelligent waiver by the person who, by the recipient. [14:29.980 --> 14:31.920] Also, with a valid court order. [14:32.160 --> 14:33.260] Not, it doesn't have to be FISA. [14:33.260 --> 14:36.140] It can be just a regular search warrant. [14:36.140 --> 14:38.460] It can be even a subpoena, a civil subpoena. [14:41.250 --> 14:52.560] Now, there's a, there's this inadvertent discovery rule that says that if I negligently, if I'm an ISP and I get data somehow, not intentionally. [14:52.680 --> 14:53.470] I'm not looking for it. [14:53.470 --> 14:58.880] But a male from A to B talking about a criminal act like, we're going to go kill C. [14:59.500 --> 15:01.640] I'm the sysadmin and it was misrouted. [15:01.740 --> 15:03.200] I'm reading the Postmaster account. [15:03.400 --> 15:04.330] It bounces to me. [15:04.330 --> 15:05.560] I'm allowed to tell C. [15:05.970 --> 15:11.740] But it's, uh, has to be criminal evidence or reasonable belief of death or grievous physical harm. [15:11.970 --> 15:15.820] So it's not just a, hey, Bob, you want to help me with some tax fraud. [15:15.820 --> 15:17.040] It's got to be something serious. [15:19.020 --> 15:25.240] Now, there's a lesser protection given to, uh, pen register and trap and trace. [15:25.420 --> 15:28.300] This is not content of data. [15:28.540 --> 15:30.380] This is sort of metadata. [15:30.710 --> 15:33.560] This is where's the, where's the communication going? [15:33.560 --> 15:34.780] Who is it from? [15:35.200 --> 15:40.470] There isn't anything specifically talking about, uh, sort of packet routing. [15:40.470 --> 15:53.240] Uh, I argued this, um, when I, when I helped write the white paper for the Third Circuit to say that packet header information is like, is like a phone number. [15:53.350 --> 15:54.300] It's like a mail address. [15:54.300 --> 16:02.940] That you have less of an interest, uh, uh, uh, privacy interest in it because you have to give it to someone else for you to get the information to where it's going. [16:03.180 --> 16:05.850] For example, uh, you sent, you mail a letter. [16:05.850 --> 16:12.760] You have no right of privacy about the, the cover of the letter because someone has to read it to get it to where it's going. [16:13.420 --> 16:23.680] Um, but the wiretap law says that there's some protection on who you're dialing and who's calling you. [16:24.260 --> 16:29.020] Um, and the old terms are trap, pen register, trap and trace. [16:29.140 --> 16:34.710] They haven't changed them even though I don't think there actually are any physical pen registers in trap and trace devices anymore. [16:35.700 --> 16:43.060] But records, names, dates, times, payment method and addresses may, are also protected. [16:43.800 --> 16:50.060] Um, you can get those with a less, with a warrant that requires less probable cause. [16:50.320 --> 16:59.820] Um, but the, unless there's a waiver to the ISP or to the, the provider, they can't divulge that to a third party. [17:02.100 --> 17:05.580] So, providers may use this information either with informed consent. [17:05.920 --> 17:13.420] So, in somewhere in that 18 page contract you signed with your provider, they may allow this information to go to third parties. [17:14.060 --> 17:20.700] Um, for billing purposes, of course, they're allowed to see, you know, wow, you made a, you know, 25 minute phone call to EastJBIP. [17:20.820 --> 17:22.320] Well, they're allowed to bill you for it. [17:22.860 --> 17:27.600] Um, they're also allowed to do it for testing or maintenance or operation of the service for obvious reasons. [17:28.440 --> 17:35.240] And then there's this sort of out, uh, to protect the service user are connected networks from illegal or abusive acts. [17:35.860 --> 17:37.420] I'm not really sure what that means. [17:37.540 --> 17:38.840] There hasn't been any cases on it. [17:38.860 --> 17:40.680] So, it's sort of out there and vague. [17:42.840 --> 17:47.360] Now, when may law enforcement do a pen register slash trap and trace? [17:47.840 --> 17:53.320] Um, if it's a part of a legitimate investigation with the recipient's permission. [17:54.060 --> 17:58.620] Uh, so you're allowed to say, hey, I think someone's using my telco. [17:59.000 --> 18:00.780] Uh, my, I'm a provider. [18:01.020 --> 18:03.100] They're, I think they're using my systems for fraud. [18:03.480 --> 18:09.360] I'm allowed to let a fed in to look at metadata. [18:09.360 --> 18:12.740] I'm allowed to say packets are coming from A to B. [18:12.940 --> 18:15.660] I'm not allowed to look at the content without a warrant. [18:15.820 --> 18:19.920] But I'm allowed to look at sort of information about the information. [18:20.500 --> 18:24.560] Um, any law enforcement can also get an ex parte order. [18:25.080 --> 18:27.320] Um, basically, it's that it's relevant. [18:27.320 --> 18:31.240] A judge or a magistrate finds that it's relevant to an ongoing criminal investigation. [18:31.680 --> 18:32.820] Very low standard. [18:33.100 --> 18:36.400] You know, it's no affidavits really have to come out that are anything serious. [18:36.400 --> 18:39.800] It's just, hey, uh, we're investigating A for fraud. [18:40.220 --> 18:44.140] Can I have a warrant to go, go see where the packets are going? [18:44.240 --> 18:45.080] Not content. [18:46.420 --> 18:49.520] Now, the remote tapping requirements under CALEA. [18:49.640 --> 18:52.020] And I'm not going to go into CALEA because CALEA is a mess. [18:52.300 --> 18:58.760] But, this eliminates the requirement to actually physically install pen registers trap and trace. [18:59.040 --> 19:03.440] Every communications device has to be easily tapped. [19:04.000 --> 19:13.580] Uh, the feds have argued that that means it has to be remotely tappable without permission, control, even notification of the provider. [19:14.000 --> 19:17.300] Um, it's been, it's being rebuffed. [19:17.580 --> 19:30.620] But, because there is such an interest in this right now, every manufacturer, at least that I know of, is making stuff that you can remotely tap it with no operator control. [19:30.880 --> 19:36.220] Because, God knows your Cisco, you don't want to sell stuff that, you know, you're thinking total cost. [19:36.220 --> 19:39.920] Um, you know, you want to make stuff that's like, I'm going to sell this as CALEA compliant. [19:40.060 --> 19:44.820] Like, you know, you know, you know, this is, this is also not the Y2K problem. [19:44.940 --> 19:46.240] It's going to be the new version of that. [19:46.360 --> 19:48.340] It's like, hey, this fits with all your regulatory needs. [19:48.620 --> 19:49.480] Buy this. [19:50.160 --> 19:53.820] Um, it should be, it should be interesting to see how that plays out. [19:54.000 --> 20:02.500] I haven't seen any cases yet arguing that a provider can man, can, can install non CALEA remote wiretap compliance stuff yet. [20:04.040 --> 20:06.900] Um, it's not limited to voice and wire. [20:07.060 --> 20:11.580] It seems to also include, um, any, any kind of electronic communication. [20:11.580 --> 20:12.760] So that could be radio. [20:13.120 --> 20:14.300] That could be microwave. [20:14.800 --> 20:16.420] Um, it's vague. [20:16.560 --> 20:17.180] It's open there. [20:17.300 --> 20:18.800] It's just like any communication. [20:20.340 --> 20:24.340] Um, I think it could be used to describe sniffing packet headers. [20:24.840 --> 20:28.660] Um, time, date, date stamp, stuff like that. [20:28.780 --> 20:29.520] But I don't know yet. [20:29.520 --> 20:30.340] We don't know yet. [20:34.170 --> 20:34.770] Okay. [20:35.070 --> 20:36.010] Now there's civil remedies. [20:36.250 --> 20:38.970] What do you do if your packets get sniffed? [20:39.730 --> 20:44.310] Um, there's this common law tort of intrusion into seclusion. [20:44.490 --> 20:46.090] You can get damages for that. [20:46.870 --> 20:56.210] Um, about 22 states allow such an action where it's an unreasonable or unwarranted intrusion into someone's privacy. [20:57.090 --> 21:01.710] Um, there's kind of mixed holdings on that of whether or not you have perfect privacy. [21:01.710 --> 21:02.470] And email. [21:03.070 --> 21:05.850] Because there's this whole, well, it's going to someone else. [21:06.190 --> 21:08.230] You, as a sender, have no protection. [21:08.430 --> 21:12.350] Because the idea is that, um, you're sending it to a third party. [21:12.450 --> 21:13.910] That third party could send it off. [21:14.410 --> 21:16.750] You know, uh, I'm, you know, I send an email to B. [21:16.970 --> 21:18.670] B could forward it to 10,000 people. [21:18.870 --> 21:20.290] I, therefore, have no protection. [21:20.570 --> 21:24.670] B has an interest in protecting incoming communications. [21:25.950 --> 21:27.750] So, A has no standing. [21:27.890 --> 21:29.450] I have no standing if I'm sending to B. [21:29.670 --> 21:31.430] B has standing to sue for that. [21:32.590 --> 21:39.270] Um, the Stored Communications Act allows a fine, a civil fine, for $1,000 per violation. [21:39.730 --> 21:53.070] Um, I haven't seen any cases on that yet where how they're going to define that, if that's per packet, if that's going to be per email message, or if that's going to be, wow, you read 1,800 of my email messages, here's your $1,000. [21:53.530 --> 21:54.270] Don't know yet. [21:55.010 --> 22:06.330] Um, Electronic Community Wiretap Act allows civil suits against private parties for damages, but fed and state agencies are immune to civil suit on this. [22:06.730 --> 22:12.090] That's why, um, the case against AT&T is going against AT&T and not the feds. [22:12.090 --> 22:15.570] Because they can say, yeah, yeah, we violated your rights. [22:15.790 --> 22:16.510] Have a nice day. [22:16.870 --> 22:17.230] We're immune. [22:19.230 --> 22:33.450] Uh, I'm going to go into a couple of interesting cases about, uh, about how interceptions kind of fall and what privacy rights you have in your electronic communications in the workplace, at home, at schools. [22:34.530 --> 22:36.950] Um, recent one, uh, Garrity v. John Hancock, you have no expectation of privacy in work email. [22:41.310 --> 22:42.170] None. [22:42.650 --> 22:52.170] Even if the, the, this is, this is kind of scary because I read parts of the John Hancock manual that said, you do have a right of privacy. [22:52.390 --> 22:56.470] We will not divulge any emails unless they're necessary. [22:57.570 --> 23:02.310] They've, John Hancock violates this in this case and the court says, that's fine. [23:02.310 --> 23:07.550] Um, so even if there's like, hey, we're going to give you privacy, no privacy. [23:10.010 --> 23:14.370] Um, however, govern, uh, MUIC is kind of equivalent to that. [23:14.910 --> 23:20.130] Um, even, they, they kind of felt that, well, if they do state there's privacy, then you have a privacy right. [23:20.130 --> 23:25.510] However, I'm sure every employer is saying, you have no privacy right just to protect themselves. [23:26.210 --> 23:30.210] Um, two kind of weird splits. [23:30.550 --> 23:37.290] Uh, there's a, the CONOP case says that, um, any user can grant permission to view a website. [23:39.010 --> 23:43.330] So, I have, I register to use a, a password protected website. [23:43.650 --> 23:48.850] I sign terms of service that say, I ref, I will not divulge my password to anybody. [23:49.730 --> 23:54.270] I hand it off to B, who does not sign the contract, who doesn't click the, you know, I agree. [23:56.030 --> 23:59.150] And the website, the website operator says, well, wait a minute. [23:59.650 --> 24:01.990] You dive, you know, you improperly came in. [24:02.410 --> 24:05.590] It's too bad, any user can grant access. [24:05.590 --> 24:06.770] It's kind of creepy. [24:08.030 --> 24:15.010] Because then you could have, you know, you could have a disclaimer that says, no law enforcement may come in, they can come in. [24:15.670 --> 24:19.950] Um, however, the, the, this, there's a split in this thinking. [24:20.310 --> 24:30.950] Um, there's a kind of a creepy case out of Chicago, uh, Citroen, where they said it's unauthorized access to use your own work laptop. [24:30.950 --> 24:37.450] It was a, a deletion of data case, where even though you hadn't quit yet, you were going to quit. [24:37.770 --> 24:40.910] You have decided that, I'm not gonna work for you anymore. [24:40.910 --> 24:45.370] I'm using my work laptop to start kind of feeling for other jobs. [24:45.770 --> 24:54.610] And the owner, or the, sorry, the authorized user of the laptop lost their authorization to use it before they had quit, before the employer even knew. [24:55.970 --> 24:58.410] And they, they got him up in civil charges. [24:58.710 --> 25:01.250] Uh, it's kind of scary, because it's, I don't know what this means. [25:01.330 --> 25:02.610] It's completely in flux. [25:03.230 --> 25:05.670] Uh, it'll probably take ten years for all this to wash out. [25:05.950 --> 25:08.850] So, right now, um, it's kind of scary. [25:09.510 --> 25:14.850] The big case going on right now changes that whole interception problem I talked about. [25:15.670 --> 25:22.170] Um, Councilman is a first circuit that's, uh, basically New England minus Vermont plus Puerto Rico. [25:23.130 --> 25:26.310] Um, yeah, they, they kind of drew these circuits strangely. [25:26.310 --> 25:31.390] Um, but, guy who's kind of a scumbag. [25:31.850 --> 25:41.570] Um, he offers free web access, I'm sorry, free, uh, web email packages to people that do business with him. [25:41.650 --> 25:42.830] He sells rare books. [25:43.050 --> 25:50.570] What he does, though, is he says, well, I'm a provider under, uh, uh, Stored Communications Act and Wiretap Act. [25:51.190 --> 25:57.770] What I'm gonna do is, I'm gonna sniff, and he writes, has code written that sniffs out any stuff going to Amazon. [25:58.270 --> 25:59.050] In or out. [25:59.830 --> 26:04.670] So he can then hold that email and then make a better offer for whatever book they're buying. [26:05.270 --> 26:08.570] Kind of a, you know, like one of those, like, hey, that was the, that was cool in the dot com era. [26:08.710 --> 26:13.030] But you think it's kind of creepy when, yeah, I want to buy this rare book and I get a better price. [26:13.470 --> 26:17.570] Like, you know, a dollar less from the guy who's offering me email. [26:17.990 --> 26:19.270] How do you know I wanted that book? [26:19.270 --> 26:22.690] Um, so they go and complain to the feds. [26:22.790 --> 26:26.170] The feds come in and say, well, we're charging you with, uh, interception. [26:26.850 --> 26:30.830] He's thinking, I'm safe because I grabbed it from my own system. [26:31.950 --> 26:36.250] And the, uh, effectively the feds get a conviction anyway. [26:36.430 --> 26:40.450] And it kind of threw everyone watching this because it's, no, it's Stored Communications. [26:40.630 --> 26:41.570] That's not Wiretap. [26:42.310 --> 26:54.930] Bounced around the courts, uh, a, uh, the appellate, the appellate, uh, sorry, the appellate court said, no, it's, um, it's, it's, it's, we're gonna hold to Steve Jackson. [26:54.930 --> 27:00.890] And then they have where all the, where all the judges in the circuit can sit and rehear the, hear the case. [27:01.030 --> 27:05.770] And they said, no, you got the email before the intended recipient did. [27:05.930 --> 27:06.870] It's now interception. [27:07.470 --> 27:08.350] Changed everything. [27:08.770 --> 27:10.310] Uh, it has not yet been followed. [27:10.310 --> 27:13.210] So, the Steve Jackson case is still good law. [27:13.670 --> 27:14.950] Everywhere but New England. [27:15.330 --> 27:17.550] Um, no other circuits have followed it yet. [27:17.730 --> 27:19.790] But it, it kind of makes this interesting split. [27:20.050 --> 27:24.690] So, you know, if you're gonna do this stuff, do it somewhere else. [27:26.870 --> 27:30.450] Um, and the, made some provider protection so much more limited. [27:30.630 --> 27:31.670] But we don't know where it is yet. [27:31.710 --> 27:34.210] I've read that, I've read that opinion maybe five or six times. [27:34.450 --> 27:36.730] I don't know how a provider's safe. [27:37.990 --> 27:41.350] Um, so, what does this, what does this all boil down to? [27:41.790 --> 27:44.730] Um, if you're a provider, you can intercept some communications. [27:45.090 --> 27:52.190] You're generally safe if you're doing it for a legitimate reason to protect your own systems, your networks, your users. [27:54.110 --> 27:59.770] Stuff that's in storage has less protection than stuff that is being transmitted. [27:59.910 --> 28:03.550] There's a greater interest in on the wire communications. [28:03.830 --> 28:06.390] I'm, it just seems to be how the law plays out. [28:06.390 --> 28:09.810] Um, councilman's still first good, still good law. [28:10.090 --> 28:11.330] Only in the first circuit. [28:11.890 --> 28:13.430] Uh, hasn't been followed anywhere else. [28:13.990 --> 28:16.070] Now, how do you protect yourselves? [28:18.940 --> 28:21.600] Um, get the consent of your users. [28:21.720 --> 28:22.660] Get it in writing. [28:23.000 --> 28:26.440] Um, either in a terms of service or a separate addendum. [28:27.360 --> 28:34.810] Um, if you are an employee and you, you have a reason, get permission from your employer. [28:35.460 --> 28:36.260] In writing. [28:36.620 --> 28:39.040] Because you want to be able to wave that around if someone complains. [28:39.720 --> 28:43.720] Um, better yet, have it written into your job description if you have one. [28:43.960 --> 28:47.620] Because it's, it's, it's a nice piece of evidence to say, no, I'm allowed to be here. [28:47.810 --> 28:48.180] Really. [28:49.020 --> 28:58.200] Because there could be convictions of someone who say works on a help desk who says, well, I, you know, uh, you know, I decided to just, you know, I bought this new, I got this new, you know, packet sniffer. [28:58.330 --> 28:59.160] I want to test it out. [28:59.380 --> 29:06.520] In fact, that was a line I got from the prosecuting attorney and councilman which said, you have a legitimate reason we're not going to prosecute. [29:06.680 --> 29:10.310] But if you just want to play with ethereal, uh, we'll come after you. [29:10.880 --> 29:14.220] At that point, I was like, oh, well, I guess I won't be doing that anymore. [29:14.720 --> 29:27.810] Um, and if you are a provider, if you're an employer, have a sniffer policy that says you may, when you may use this, who may use it, when may you use it. [29:27.810 --> 29:30.310] So that way, everything's really nice and clear. [29:30.540 --> 29:40.940] So that way, if, if, God forbid, you get prosecuted or you get sued for it, you can point to that and say, we followed our own rules, therefore, we're, we're on the clean side. [29:42.720 --> 29:45.050] I kind of rushed through that because we were running a little bit late. [29:45.160 --> 29:45.740] Are there any questions? [29:47.740 --> 29:48.140] Yeah. [29:56.720 --> 29:59.140] And, uh, I'm sorry, and, uh, what's the other computer? [30:03.890 --> 30:09.770] Um, if you're not, if you're not capturing, anyone else's packets, you should be okay. [30:10.110 --> 30:17.730] The problem is, is that if you think on, on a, like a hub network, not a switch network, you may grab packets that aren't yours. [30:18.330 --> 30:20.730] So, you're then up for that. [30:23.580 --> 30:24.220] Yeah. [30:24.980 --> 30:25.620] Okay. [30:30.530 --> 30:33.730] Um, it's still an electronic communication. [30:34.030 --> 30:52.370] They've modified, um, it's in the modification of the PATRIOT Act, I believe, where they say, they expressly mention, they, they talk about, uh, VOIP, about that whole, uh, you may not use this, you know, it's a violation to annoy, taunt, blah, blah, blah, [30:52.450 --> 30:52.570] blah. [30:52.790 --> 31:00.050] That seems to be a holdover to say, if you're convicted for phone harassment, that you can't say, well, it's, it's not phone, it's VoIP. [31:00.610 --> 31:04.710] Um, so it seems to be that any electronic communications covered by all this stuff. [31:05.950 --> 31:06.350] Okay? [31:13.040 --> 31:13.440] Um... [31:13.440 --> 31:14.400] Can you repeat the question? [31:15.060 --> 31:15.460] Yeah. [31:15.760 --> 31:16.020] Could you... [31:16.020 --> 31:16.680] Can you repeat the question? [31:27.230 --> 31:27.630] Yeah. [31:27.630 --> 31:28.290] Could you... [31:28.290 --> 31:29.190] Quick question. [31:29.310 --> 31:29.430] Okay. [31:29.530 --> 31:29.790] Sit here. [31:29.990 --> 31:30.290] And if you're... [31:30.290 --> 31:30.810] No, I'm sorry. [31:30.950 --> 31:33.730] Can you, can you use the microphone so that everybody can hear? [31:34.170 --> 31:34.770] Thank you. [31:35.470 --> 31:35.870] Uh... [31:35.870 --> 31:36.390] Two more. [31:42.560 --> 31:42.960] Hi. [31:43.140 --> 31:47.080] The, uh, question is if you're a managed security vendor, uh, and you get permission from the company. [31:47.160 --> 31:49.280] The company's liable, not you as the managed security vendor. [31:49.280 --> 31:53.820] Okay, so you're a third party, you're an agent of the company. [31:54.040 --> 31:54.120] Yeah. [31:54.280 --> 31:56.740] They hire you to come in and say, please sniff our packets. [31:57.440 --> 31:57.780] Okay. [31:59.220 --> 32:01.020] But they're not allowed to do it. [32:01.380 --> 32:03.420] Uh, I'm not sure. [32:03.540 --> 32:12.840] I think you, you've got some defenses, but even having defenses coming into this is means that you might be up for some litigation in a civil sense. [32:13.080 --> 32:18.360] Um, I think the feds would be less interested cause you're, it's harder to prove the criminal case than it would be the civil case. [32:18.760 --> 32:24.820] Um, I think you would want to have some, as much documentation that says, we're doing this for a legitimate reason. [32:25.060 --> 32:25.300] Yeah. [32:29.170 --> 32:29.650] Yeah. [32:29.650 --> 32:30.150] Anyone else? [32:31.150 --> 32:31.630] Yeah. [32:34.030 --> 32:42.150] Um, you mentioned allowing a party that has signed your terms of services to allow a third party access to your website or network. [32:42.150 --> 32:42.610] Uh-huh. [32:42.790 --> 32:46.430] Let's say that you had a terms of service they had to agree to every time they logged on. [32:46.590 --> 32:47.510] Would that... [32:47.510 --> 32:48.370] I'm sorry. [32:48.670 --> 32:49.590] I didn't hear that. [32:49.790 --> 33:04.270] If you had a terms of services that party B agreed to and had to re-agree to every time they logged on and they allowed party C into their website by giving them the password, would that also bind party C to those terms of services? [33:04.830 --> 33:05.970] Yes, it could. [33:06.450 --> 33:17.590] But, um, if you, if it's sort of the, the click wrap, you know, our, you know, the click wrap, our, our, our, uh, browse, browse wrap license, it seems to be binding. [33:17.970 --> 33:39.310] However, it would still not, if, if, if, if B, say B's an authorized user, B gives C B's password and logon, C is still bound by the contract, but they're not violating the stored communications act, even though you, A, as the provider, like, I don't want C here. [33:39.630 --> 33:39.790] You know? [33:40.350 --> 33:43.710] So it's kind of a, it's kind of, it seems to be in flux right now. [33:44.150 --> 33:49.330] Um, I think if you had a really aggressive prosecutor, you might be able to get something. [33:49.690 --> 33:59.270] Um, but you realize in your terms of service, you're also protecting yourself if you're A, by saying, if you, you know, you may not give your password so you have an action against B and C. [33:59.570 --> 34:02.770] C for coming in unauthorized, B for handing out the password. [34:02.770 --> 34:03.350] Yeah. [34:03.350 --> 34:03.770] Thank you. [34:07.190 --> 34:07.390] Yeah. [34:07.610 --> 34:12.430] Um, if you encrypt the contents of your packets, does that have any influence on the expectation of privacy? [34:12.730 --> 34:13.670] Good question. [34:14.030 --> 34:21.270] Uh, there is a case out of, out of the, the, out of, I think it's the Southern District of Florida. [34:21.850 --> 34:25.170] Uh, only case I've seen on this was a couple drug dealers. [34:25.170 --> 34:28.810] They were using, um, they were using encryption over radio. [34:29.090 --> 34:30.490] They weren't sent, it wasn't packetized. [34:30.490 --> 34:32.930] This was just a, um, like a, a voice scrambler. [34:33.850 --> 34:43.610] The court said, well, you listened in and because you encrypted it, it said that you, your subjective expectation of privacy was reduced. [34:43.610 --> 34:45.750] So then they allowed that in. [34:46.010 --> 34:49.230] It wasn't a, uh, it wasn't a wiretap act. [34:49.450 --> 34:51.790] It was, uh, just a straight Fourth Amendment case. [34:52.530 --> 34:53.930] So I think you're right. [34:54.030 --> 34:56.730] I think it does reduce your expectation of privacy. [34:56.870 --> 34:57.790] Kind of ironic that. [34:59.530 --> 35:03.790] Has, has it been held up that, um, memory contents are stored communications? [35:04.050 --> 35:04.570] Has that been in? [35:04.710 --> 35:08.950] If it's incidental, if, because it seems to not protect systems per se. [35:09.130 --> 35:10.670] It seems to protect communications. [35:11.410 --> 35:14.190] Um, I don't know how far that goes. [35:14.330 --> 35:18.910] There haven't been any cases where it's like purely machine to machine communication, not human initiated. [35:19.110 --> 35:20.570] But it's, due to the routers. [35:21.070 --> 35:30.450] Um, if it's, if it's, if it seems to be electronic communication that's in storage, however incidental, then it would be protected under Stored Communications Act. [35:31.070 --> 35:39.970] Um, if, if they, if they intercept it, but it's encrypted, and they haven't been able to, you know, bring it into the clear yet, can they still prosecute on that? [35:41.190 --> 35:43.090] Well, wait a minute, let me see. [35:43.390 --> 35:44.990] You're, who's, who's doing the encrypt? [35:44.990 --> 35:45.810] They intercept it. [35:45.930 --> 35:47.590] You, you send in an encrypted communication. [35:48.150 --> 35:50.230] They intercept it, but they can't crack it. [35:50.370 --> 35:52.050] Can they still prosecute you at that point? [35:52.250 --> 35:54.970] Because they've collected evidence, even though they can't see it in the clear yet. [35:55.150 --> 35:56.550] But it, what's the evidence? [35:56.550 --> 35:59.510] You don't have, I mean, if it's not cracked, it can't be presented. [35:59.710 --> 36:05.950] It's just like, oh, we have, you know, and you could, you know, a skilled defense attorney can say, yeah, that's, that's, you know, 18 gigs of porn. [36:06.190 --> 36:06.850] Not illegal. [36:07.050 --> 36:07.390] Thank you. [36:07.610 --> 36:10.470] But I'm saying they could still continue in an investigation and keep on collecting. [36:10.470 --> 36:11.650] Oh, yes, yes, yes. [36:11.810 --> 36:12.130] They could. [36:12.370 --> 36:13.470] Well, they couldn't prosecute. [36:13.590 --> 36:16.670] They would arrest you and indict you and then wait until they cracked it. [36:18.090 --> 36:30.290] If you own a network with a VPN connection and an unauthorized user VPNs into that connection that isn't bound by any sort of terms of service, even though it's your network, are you allowed to packet sniff their traffic on your network? [36:31.470 --> 36:32.210] Who are you? [36:32.270 --> 36:32.910] You're a provider? [36:33.690 --> 36:46.230] You own a LAN, but you offer VPN service, say, to employees or something, but someone other than an employee who shouldn't have access, gains access, and you try and packet sniff their traffic over the VPN. [36:46.650 --> 37:02.270] I think you're protected under the whole defense of your own network rule that says that, well, you're an unauthorized user, therefore I'm doing this to make sure that my systems are not being used to fraud, you know, for fraud, abuse, and to defend other systems. [37:02.270 --> 37:06.090] Because, you know, your LAN theoretically is connected to the rest of the Internet. [37:06.930 --> 37:15.150] So, you could then say, no, you know, I'm allowed to look at the content of these packets because I'm protecting my own self. [37:15.630 --> 37:15.930] Okay. [37:18.090 --> 37:31.110] So, let's say you're a university, and you're a conservative university, and you don't want to have the students for sensible drug policy on your campus anymore, so you decide to sniff their traffic to look for crimes to get a reason to kick them off. [37:31.110 --> 37:40.230] You're not going to go criminal with it, you're not going to go to the police with it, but you actually just, like, tcpdump their entire connection for months at a time just to kick them off your campus. [37:40.410 --> 37:41.790] And this comes down from the higher-ups. [37:43.170 --> 37:44.010] Anything with that? [37:44.170 --> 37:45.190] Because it is a private network. [37:45.370 --> 37:47.210] Actually, it's a state... let's say it's a state university. [37:47.210 --> 37:47.490] Okay. [37:47.750 --> 37:52.210] State university then implies Fourth Amendment due process and... [37:52.850 --> 38:00.750] I'm sorry, implies Fourteenth Amendment due process, also implies then the Fourth Amendment, that it's unreasonable search. [38:00.930 --> 38:10.370] However, given that it's a university, somewhere in the terms of service there may be a, we're allowed to sniff whatever we want whenever we want. [38:11.490 --> 38:14.910] If there wasn't that, I think you would have a case. [38:17.890 --> 38:20.170] How does this all apply to Wi-Fi and free space? [38:21.210 --> 38:24.670] Wi-Fi, it's still electronic communications. [38:25.130 --> 38:32.790] So sniffing a wireless... sniffing a wireless connection would be the same as sniffing a wired connection. [38:32.790 --> 38:40.850] There is some part in the wiretap that says stuff that is broadcast with the intent of being generally received. [38:41.230 --> 38:51.890] And that seems to more imply radio, like FM, AM, shortwave, that there's no, you know, I'm 91.7 college radio, I'm broadcasting, you listen in. [38:52.010 --> 38:53.550] It's like, well, that's kind of the intention. [38:54.210 --> 39:04.110] But if it's, if it's a, if it's electronic communication that you're not arguing, you know, is, is for widespread consumption, you would then have some protection. [39:06.170 --> 39:06.790] Yeah. [39:21.270 --> 39:23.460] This is, this is wireless? [39:23.460 --> 39:24.000] Yes. [39:24.930 --> 39:34.810] There is that, that seems to be that exception that says you're allowed to sniff content to find out sources of interference for your network. [39:35.600 --> 39:45.330] I think that you'd still have to, you'd have to limit that because it's, you can't sniff 18 gigs of packets to figure out, huh, something's interfering with this. [39:45.600 --> 39:48.980] I think there's some, you know, some reasonableness to that. [39:49.230 --> 39:52.580] I don't know yet, but that's how I, that's how I would defend it. [39:56.500 --> 39:57.260] Any others? [39:58.500 --> 39:59.020] Yeah. [40:05.410 --> 40:05.930] Yeah. [40:06.110 --> 40:06.530] Could you use the mic? [40:07.510 --> 40:08.030] I'm... [40:08.030 --> 40:17.710] If your organization has a clearly stated acceptable use policy, is it all right to run an analyzer like Snort to find violations of that policy? [40:18.490 --> 40:25.750] If you, what you want to do is in your AUP or terms of service, you want to have, we can look at traffic. [40:26.930 --> 40:28.270] You want to have that protection. [40:28.410 --> 40:36.470] You want to have it clearly written because it's, looking for violations of the terms of service is different than what we're looking at. [40:36.670 --> 40:38.750] I'm not sure if I'm, I'm being clear on that. [40:38.850 --> 40:44.850] You want to have, we are allowed to look at your, if your use of our network presumes we're allowed to look at your stuff. [40:44.850 --> 40:46.530] You want to have that line in there. [40:47.310 --> 40:51.210] More than just, we're looking for violations of abuse. [40:51.350 --> 40:54.710] Because the abuse seems to be, it seems to be more narrowly defined. [40:54.830 --> 41:05.690] It seems to be fraudulent, abusive, like if someone's mangling your network by, you know, doing a packet storm. [41:06.530 --> 41:08.190] That would be, that would be acceptable. [41:08.470 --> 41:12.170] If it's, you know, like the, the, for the college, the conservative college. [41:12.850 --> 41:20.190] It's a, it might be a violation of the terms of service to, you know, advocate for, for a free drug society. [41:21.890 --> 41:25.990] But it might not be still allowable to violate your privacy rights. [41:25.990 --> 41:32.190] What if you have something like peer-to-peer is, is banned on your network. [41:32.930 --> 41:37.570] So you would have to say that you have, you proactively monitor for it. [41:38.730 --> 41:42.850] I think you could argue that it's, you're preventing abuse or fraud with that. [41:43.050 --> 41:47.370] And shrug your shoulders and say, look, I think it might be, you might be doing fraudulent use. [41:47.850 --> 41:51.190] So it, it would be okay then to monitor the network. [41:51.490 --> 41:53.130] I think, I think so. [41:53.130 --> 41:56.930] I, I, I urge though, that if, you know, you get it in writing. [41:57.130 --> 42:00.350] So that way you've got a far better defense to say, we told you we could do it. [42:00.470 --> 42:01.910] Therefore your use waived it. [42:02.290 --> 42:05.030] Versus then this sort of like, we're looking for abuse. [42:05.150 --> 42:07.630] Cause that allows someone to argue, well, is it abuse? [42:09.110 --> 42:09.590] All right. [42:09.710 --> 42:09.910] Thanks. [42:10.170 --> 42:10.450] Okay. [42:14.680 --> 42:19.160] Uh, if you are served a FISA warrant, can you retain the services of a lawyer? [42:19.820 --> 42:21.860] It seems that there's a recent case. [42:21.860 --> 42:27.560] It seems to allow you to because it's, it's, it's a violation of due process. [42:27.860 --> 42:30.940] You, however, can only talk to that lawyer. [42:31.160 --> 42:43.040] You can't, you can't call up user that's being, that has, you know, if, if you're, if you're an ISP and we want to look at your user A, you can't call up A and say, A, you should hire a lawyer. [42:43.040 --> 42:48.420] You can hire a lawyer to figure out how you comply with the order, but I don't think you can inform anyone else. [42:48.720 --> 42:48.980] Okay. [42:49.720 --> 42:50.460] But I don't know. [42:50.740 --> 42:51.720] FISA's kind of weird. [42:57.860 --> 43:01.880] Sorry, uh, recently, uh, Bell Simpatico in Canada changed their, uh, policy. [43:02.280 --> 43:03.660] Their acceptable use policy. [43:03.840 --> 43:06.280] Say, basically, we can tap anyone all the time. [43:06.560 --> 43:09.460] Uh, I don't know if you heard about that, but, uh, do you know why? [43:09.460 --> 43:12.860] Because the law hasn't really changed in Canada, but they changed the policy. [43:14.440 --> 43:14.880] So... [43:14.880 --> 43:19.200] Uh, I don't, you know, what I don't know about Canadian law, I think it approaches everything. [43:21.000 --> 43:21.440] Um... [43:21.440 --> 43:30.180] So, I believe, though, that it seems to be that other nations' laws seem to be, other than Europe, seem to be mirroring U.S. law. [43:30.920 --> 43:36.660] Um, there are a couple European EC directives that came down that, that are much, much stronger on privacy. [43:36.660 --> 43:41.960] I'm starting to think if I needed to host any servers, they're getting hosted somewhere there. [43:46.910 --> 43:47.670] Anything else? [43:49.390 --> 43:49.870] Cool. [43:50.090 --> 43:50.630] Thank you very much. [44:24.850 --> 44:26.270] Just a quick announcement. [44:26.510 --> 44:32.090] There's been a schedule change today at, uh, 10 o'clock. [44:32.430 --> 44:34.570] No, 8 o'clock military time. [44:34.770 --> 44:39.350] Uh, the Kevin Mitnick unplugged and the Off The... Off The Hook have been swapped. [44:39.350 --> 44:48.890] So, uh, the Kevin Mitnick unplugged is going to be on Saturday and off the hook is going to be today. [45:18.800 --> 45:19.520] Yeah? [45:19.520 --> 45:19.620] Yeah? [45:33.840 --> 45:34.480] Yeah, [45:45.600 --> 45:46.520] we've done... [45:47.640 --> 45:48.750] ...tech people. [45:49.230 --> 45:51.120] Do you have a laptop? [45:51.900 --> 45:54.300] I do have a laptop, but I have a laptop. [46:12.580 --> 46:18.880] I can't tell you anymore, I have a laptop. [46:21.280 --> 46:24.640] I wanted to have a laptop. [46:28.000 --> 46:29.440] Do a little dance. [46:30.360 --> 46:30.580] I'm back. [46:44.680 --> 46:46.040] Don't ask me. [46:47.320 --> 46:48.920] I'm out. [46:51.920 --> 46:54.960] Tomorrow, I kiss another one.