Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 33 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Legality of spy software
EH-Net
May 25, 2013, 12:19:34 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Legality of spy software
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Legality of spy software (Read 41962 times)
0 Members and 1 Guest are viewing this topic.
BillV
Hero Member
Offline
Posts: 1892
Legality of spy software
«
on:
February 07, 2008, 07:39:21 AM »
First let me give you a quick background of where this question is coming from. We have a local radio station here that does this thing they call "War of the Roses." Basically, the idea is that they have a couple in a relationship (whether dating or married) where one of them believes the other is cheating. So the radio station calls the suspected cheater up on the phone and asks them where they want to send a dozen roses. Then they obviously either send it to their partner, or to the person their cheating with.
Well, apparently they've reached a new level with this idea. I'm driving to work this morning listening to the show, and they say that they've installed spy monitoring software onto a computer in order to watch the activities of the suspected cheater. It sounds like it works the same as most, and logs Internet activity, chats, emails, takes screenshots, etc.
My question of the whole thing would be the legal issues involved. Since they're monitoring activity as a third party, what permission do they need? Do they only need permission from the 1 person in the couple to spy on the other? Do you need a Private Investigator license or anything?
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Legality of spy software
«
Reply #1 on:
February 07, 2008, 09:10:28 AM »
Generally this would be considered acceptable if a person with an ownership aspect of the system agreed to it. That means if they live together and have an assumed shared ownership of the system then one of them could give permission to do so. Also, you need to remember that nobody in the scenario is a representative of the government so most privacy/wire tap/evidence/search laws would not apply. My two cents.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: Legality of spy software
«
Reply #2 on:
February 07, 2008, 10:44:59 AM »
True enough, I think pseud0's take on it is legal. I've installed spy software for clients before at their request on their own computers, and taught them how to monitor the results... I must say I kind of felt dirty though doing it even though it was technically totally fine. I don't know, I'm not a big fan of the feel of being a cog in the Orwellian machine, but then again it does pay and it's technically ethical in my case. Still, it does have a dirty feel, especially when you have to watch the person it takes down realize that their privacy has been violated, even if done so with good reasons.
Logged
"Bad.. Good? I'm the guy with the gun"
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Legality of spy software
«
Reply #3 on:
February 07, 2008, 11:21:08 AM »
One thing that these guys are going to need to consider, legality issues put aside, they might be held liable under civil laws. If the affected person decides that they have suffered emotional damage, that their job was affected, etc. then the radio station could be held liable.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
BillV
Hero Member
Offline
Posts: 1892
Re: Legality of spy software
«
Reply #4 on:
February 07, 2008, 12:15:09 PM »
Thanks for the replies. That makes sense. I guess when I was thinking about it this morning, it was more from the perspective of breaking into a computer and placing monitoring software on it (which would obviously be illegal). If 1 of them gives permission to do so, I guess it's the same as that person installing it themselves to monitor the other anyway. I had not taken into consideration civil liability though, good point.
edit: What about leaking of confidential information? Is all data fair game? Say for example the person opens work email or connects to a work system and now confidential company data has been breached. What then?
«
Last Edit: February 07, 2008, 12:26:02 PM by BillV
»
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Legality of spy software
«
Reply #5 on:
February 07, 2008, 12:34:54 PM »
You're splitting some hairs at that point. While a second person might have partial ownership of the system, you would argue that they don't have assumed ownership over all of the material on that system (ie. the work email account). If data from that account was leaked it would open up some very certain civil liability lawsuits, and depending on how much damage was done you could push for some criminal suits as well. Think of it this way, your wife might have assumed shared ownership of your desk, but if she searched through your drawers, found some vital work papers, and had them published online, your work would probably sue the hell out of her (and you) while pressing charges of various types.
«
Last Edit: February 07, 2008, 12:38:57 PM by pseud0
»
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
BillV
Hero Member
Offline
Posts: 1892
Re: Legality of spy software
«
Reply #6 on:
February 07, 2008, 12:41:13 PM »
Ok, fair enough. Thanks for the replies and info
Logged
geekyone
Full Member
Offline
Posts: 180
Re: Legality of spy software
«
Reply #7 on:
February 07, 2008, 02:35:24 PM »
I think from a legal standpoint a lot would depend on how well the unknowing party has separated their data from their significant others data. For example they both may own the computer but use separate user accounts that maybe password protected. I think that weighs in heavily when considering whether accessing data is legal or not.
Logged
CISSP, CEH, GPEN, GCIH, GCFA
bigwhiff
Newbie
Offline
Posts: 14
Re: Legality of spy software
«
Reply #8 on:
February 07, 2008, 04:59:59 PM »
At first looking at this I thought they might be breaking Federal Wire Tap laws. But after further investigation
http://www.securityfocus.com/news/9978
I found that the wiretap law was thrown out by this judge in a keylogger ruling.
So next would come down to ownership and who owned the system and provided access to it. If it is a non-martial relationship and the girlfriend granted access to the computer that belonged to the boyfriend I believe that then there would be laws being broken.
Logged
Jack Campbell
CCNP CCDP GCIH GHTQ C|EH
http://secauditor.wordpress.com
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Legality of spy software
«
Reply #9 on:
February 08, 2008, 11:11:35 AM »
For the ownership question, be aware that often the law does not distinguish between the legal owner and someone who as some level of presumed ownership. In the example of a boyfriend and girlfriend, if the computer belongs to the guy and he allows the girlfriend unlimited use, then she is going to have some level of presumed ownership. As a better example, if the cops wanted to search the house and asked permission from the girlfriend, the search would be legal. The courts have stated that she has the right to do so. The same concept would apply to the computer if she had regular access to it with permission from the owner. As for the wire tap laws, you have to take into account their narrow focus. In the example given here it is for interstate or international communications that affect commerce. As for the radio station example we are discussing, there might be other specific commerce laws that would apply (and maybe some FCC laws?) but I just wanted to make a point that most of the big laws everyone is familiar with probably wouldn't apply.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Legality of spy software
«
Reply #10 on:
February 08, 2008, 02:37:26 PM »
Various user accounts would not make a difference. So long as the spy ware is installed by an account with admin privileges, then it would run no matter what account is being used. As for the legality of the whole thing, it is perfectly acceptable for parents to use programs to monitor their kids’ activities. Should it be any different for spouses? Of course, this brings up the whole issue of trust on the part of the couple, but that is a different argument. Go ahead and spy on your spouse all you want, but be prepared for the consequences when he or she finds out.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
Mr. Roboto
Jr. Member
Offline
Posts: 67
Himitsu wo shiritai
Re: Legality of spy software
«
Reply #11 on:
February 22, 2008, 10:15:57 AM »
sgt_mjc has it right. It works just like parental controls for kids. You can do whatever/install whatever, but when your significant other finds out...
Not worth losing your marriage/relationship over a key logger or spyware.
Logged
A+, Security+, HDI Support Center Analyst, MCTS: Vista
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.