[unisog] Suspicious Files

McDonnell, Michael michael.mcdonnell at ualberta.ca
Tue Dec 9 19:09:08 GMT 2008


Hi Robert,

I would say that if you find *evidence* of a crime or a threat to human
safety, you are obligated (by ethics and in many cases by law) to report it.

I don't find this particular case suspicious, just unusual.  I have photos
of fire trucks and other emergency responders on my computer. I also have
photos of helicopters and buildings and popular landmarks.  Anyone fixing my
computer and reporting me for what they might judge to be an unusual mix
would be exercising poor judgment.

If the tech had found an overt communication that indicated a threat to
someone's safety, I wouldn't hesitate to report it.

I would also talk to the technician about the practice of privacy.  It's not
clear if the tech did or did not breach the user's privacy.  Just because a
user asks us to fix a computer doesn't mean that we have the right to poke
around through their private files.  If we *have* to, sure we do what we
have to... but not otherwise.  

--
Michael McDonnell, GCIA
Network Security Analyst
University of Alberta Libraries
Information Technology Services
michael.mcdonnell at ualberta.ca
 
> -----Original Message-----
> From: unisog-bounces at lists.dshield.org [mailto:unisog-
> bounces at lists.dshield.org] On Behalf Of Bob Henry
> Sent: Monday, December 08, 2008 12:19 PM
> To: unisog at lists.dshield.org
> Subject: [unisog] Suspicious Files
> 
> One of our Housing office computer techs sent me the following
> question and I'd like to know what members of this list think.  Has
> anyone bumped into this and what did you do?  I've forwarded the
> question to legal as well.
> 
> A student brought his computer to the Student Housing computer support
> people for repairs.  The computer wouldn't boot and the student told
> the Housing technicians they could format the drive if they needed to.
>  The technician managed to boot the computer from its existing
> configuration.  On the computer, the technician found many pictures of
> jet airplanes, interior and exterior pictures of Boise skyscrapers,
> pictures of the presidents planes, videos of planes crashing, pictures
> of airports, pictures of the walkways from the airport, a connection
> to American airlines flights.
> 
> What are our responsibilities for handling this information?  Can we
> present it to law enforcement or would we be violating the 4th
> amendment?
> 
> 
> --
> Robert Henry, CISSP, GCIH, GCFA
> Information Security Officer
> Office of Information Technology
> Boise State University
> 208-426-5701
> bhenry at boisestate.edu
> http://boisestate.edu/oit/iso
> _______________________________________________
> unisog mailing list
> unisog at lists.dshield.org
> https://lists.sans.org/mailman/listinfo/unisog

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3102 bytes
Desc: not available
Url : http://lists.sans.org/pipermail/unisog/attachments/20081209/2c7f7753/attachment.bin 


More information about the unisog mailing list