Digg this story   Add to del.icio.us   (page 1 of 3 ) next 
Get Off My Cloud
Mark Rasch, 2008-08-19

When the new iPhone 3G went for sale last week, I was sorely tempted to wait in line for one. (I didn't -- no patience.)

One of the features of Apple's device that appeals to me is the new MobileMe service, where you can "access and manage your email, contacts, calendar, photos, and files at me.com," according to Apple. More companies, among them Microsoft and Google, already allow people to store information and use common services online -- or "in the cloud" -- leading analysts to refer to the entire trend as "cloud computing."

This iteration of "cloud computing" puts your personal data on an accessible server held by a third party, which you replicate on multiple machines and access from virtually anywhere. Putting aside the security, data storage, data retention, data destruction and other pesky issues associated with doing business in the cloud, one fundamental issue remains: Your data is being hosted, stored and transmitted through a third party.  As far as the law is concerned then, that third party has control of your data and may therefore be subject to a subpoena for your data, often without your knowledge or ability to object.

On July 11, 2008, Steven Warshak, the president of a nutrition supplement company, learned the hard way (pdf) about the dangers of using web-based e-mail. On May 6, 2005, the government got such an order for the contents of his e-mails.

Generally, the Internet service provider is required to give the subscriber notice of the subpoena, but the statute allows the government to delay such notification for 90 days if the government just asks for it and the court finds that "there is reason to believe that notification of the existence of the court order may have an adverse result" like endangering the life or physical safety of an individual; flight from prosecution; destruction of or tampering with evidence; intimidation of potential witnesses; or otherwise seriously jeopardizing an investigation or unduly delaying a trial. Using this provision the government got an order allowing it to delay telling Warshak of its access for 90 days, until early July, 2006.

July came and went, as did August, September, October, November, December, January, February, March, April and May of 2007 before the government finally got around to telling Warshak that it had been reading his mail.

Warshak, like many others, used web-based or third party provided e-mail services like Yahoo! mail and NuVox communications. Thus, his inbox and outbox were literally out of his hands. If Warshak had used an internal e-mail service that he controlled and the government wanted to get access to the contents of his e-mail, they would have had to do it the old-fashioned way: obtain a search warrant supported by probable cause, issued by a neutral and detached magistrate, specifying the place to be searched and the items to be seized.  In fact, those are the precise words of the Fourth Amendment.

Now the government could have issued a grand jury subpoena to Warshak ordering him to pony up his e-mails Warshak then could have challenged the scope and breadth of the subpoena, argued that it called for production of irrelevant or privileged materials, challenged the jurisdiction of the grand jury to issue the subpoena, or raised a series of other defenses to the subpoena itself.

But the government didn't want Warshak to know it was investigating him and his company.  They wanted to be able to read his e-mails without him knowing about it.  So they used a statute called the Stored Communications Act, which allows the government to require an ISP to hand over the contents of your e-mails that have been in storage for more than 180 days even without a warrant, as long as it has a court order showing "reasonable grounds to believe that the contents of a wire or electronic communication, or the records or other information sought, are relevant and material to an ongoing criminal investigation."

Thus, in the case of e-mail messages stored and sent in the cloud, the government doesn't need a warrant, doesn't need probable cause, and doesn't need to provide the "owner" of the communications with notice. At least, not right away. Indeed, the government can request that the ISP "preserve" future communications that haven't even been conceived of yet, so that the government may demand them if the situation warrants.

Story continued on Page 2 



Mark D. Rasch is an attorney and technology expert in the areas of intellectual property protection, computer security, privacy and regulatory compliance. He formerly worked at the Department of Justice, where he was responsible for the prosecution of Robert Morris, the Cornell University graduate student responsible for the so-called Morris Worm and the investigations of the Hannover hackers featured in Clifford Stoll’s book, "The Cuckoo’s Egg."
    Digg this story   Add to del.icio.us   (page 1 of 3 ) next 
Comments Mode:
Get Off My Cloud 2008-08-19
Anonymous
Get Off My Cloud 2008-08-19
Anonymous
Get Off My Cloud 2008-08-19
Todd Knarr
Get Off My Cloud 2008-08-20
Bill
Get Off My Cloud 2008-08-20
MrGroove
Get Off My Cloud 2008-08-28
Anonymous
Get Off My Cloud 2008-09-03
Anonymous
Get Off My Cloud 2008-09-09
Anonymous (1 replies)
Re: Get Off My Cloud 2008-09-11
Anonymous (1 replies)
Re: Re: Get Off My Cloud 2008-09-17
Anonymous (1 replies)
Re: Re: Re: Get Off My Cloud 2008-09-19
Anonymous
Get Off My Cloud 2008-09-28
Dale


 

Privacy Statement
Copyright 2010, SecurityFocus