During the most recent American election, nuances of a diabolical and dangerous nature began to emerge at a terrifyingly regular pace. No, I’m not talking about the platform or extra-curricular activities of the candidate opposing your views, but of the notions, practices, and assumptions of our own cyber security, and protection of our personal privacy. Whether you are appalled by or defend the inspirations of these observations, the principles of personal information security are just as relevant as to those directly impacted.
- Professional Email is not Private Communication
When I heard the outcry regarding the email disclosures as an invasion of privacy, I imagined roomfuls of lawyers chuckling their merry lawyerly chuckles. Despite the provisions of the Constitutional Fourth Amendment, most companies will have policies that remove any assumption of personal privacy in corporate email. In fact, security awareness should dissuade users from using email for personal communication and ensure they understand that their email is a business document, potentially even a business record. Due to provisions in the US Code such as Title 5 Section 552 (the Freedom of Information Act), this is most true in the public sector, but just as relevant for employees in the private sector. For example, the Internal Revenue Service notes in their policy that, “Email messages are official documents and should reflect this perspective. Email communications can be offered as evidence in court and can be legally binding.”
As a vehicle for private communications, email is perhaps the least secure and worst choice available; in contrast, SMS messages and telephone calls are typically not recorded or stored by the organization as records and therefore equally unavailable to the nefarious. Even if accessible, an employer would need to engage law enforcement to gain access. To learn more, check your company’s policies regarding assumptions of privacy and of computer and network usage. These policies typically manifest as a signed Code of Conduct or Acceptable Use of Computer Technology agreement which removes any reasonable expectation of privacy in electronic communication.
- Someone is Always Watching
With all due respect to John Wooden, the true test of a person’s character is what they do when they think no one is watching…or listening. The disclosure of recorded material is at the discretion of the increasingly indiscrete recorder, inclusive of their ability and desires to maintain the confidentiality. Perhaps a more appropriate quote comes from Benjamin Franklin, three can keep a secret if two of them are dead… and that first person had sufficiently employed a commercial-grade degausser, burned their RAM chips in their microwave, and then prayed for (and subsequently achieved) divine intervention, all before their recording went viral on the Internet. Even then, it’s a toss-up. The things we do that we believe are in private are increasingly memorialized with and without consent, by the electronic recordings of video surveillance cameras, remote conferencing, and selfies.
Provisions in the US Code, Title 18, sections 2510, 2511, and 2512 (collectively, the Electronic Communications Privacy Act) restrict surreptitious recording and fall under regulations for wiretapping; however, due to latitudes given by the US Patriot Act, such recordings may occur without evidence or probable cause. However, as noted by the American Civil Liberties Union, a person may have the right to make recordings (of you) when lawfully in a public space, or visiting a private space; these decisions are largely out of the control of the one recorded. Personal privacy has become very public; self-control is perhaps the most effective way to protect yourself, but there are ways to get your privacy back, not just from recordings. For example, the Privacy Rights Clearing House offers recovery assistance, educational publications, and advocacy for consumer-friendly policies.
- Trust but Verify
As the fact-checking tallies whirred the different candidate’s performance, the various social media outlets hemorrhaged misstatements and attestations from events that couldn’t possibly have witnessed. The current events entertainment networks (it’s tough for me to call them ‘network news’) dripped inaccuracies and misquotes, and the shock jocks gleefully chronicled as fact whatever rumor, speculation, or hearsay that supported their agenda.
“When the legend becomes fact, print the legend” isn’t just the catch-phrase from John Ford’s The Man Who Shot Liberty Valance, it’s the mantra for social media sharing. Fake news on the Interwebs is rampant, and it is important to double or even triple check information that you share or that you capture from these outlets, especially if it seems too good to be true. As noted by Buzzfeed, hyper-partisanism on social media sources are consistently feeding their followers false or misleading information. Be responsible sharing, and use basic research principles before publishing: use only validated sources, avoid sources with agendas or commercial interests, and use a known, legitimate verification service. My personal favorite site for “fact-checking” is Snopes.
— Scott vonFischer