On mySimon: The North Face Mountain Sneakers for Men
BNET Business Network:
BNET
TechRepublic
ZDNet

June 28th, 2007

Laptop insecurities

Posted by Paul Murphy @ 12:15 am

Categories: Development, Enterprise Policy, Linux, Security, Sun

Tags: Agent, Laptop Computer, Paul Murphy

Last Thursday’s issue of an Information Week newsletter I get included an editorial comment by CMP editor Barbara Krasnoff about the problem that data on laptops can be examined by airport security and other government agents on the pretence of looking for prohibited classes of pornography or other materials.

As she puts it:

What do you have on your laptop that you might not want anyone else to see?

Is there, for example, a record of your doctor visits and which medications you take? Some music downloaded from the Web that may or may not be copyright-compliant? How about the spreadsheet listing your employees, how much they make, and who may become part of your company’s projected layoffs? Or the e-mail you sent to your senator complaining about the treatment you recently receiving from airport security personnel?

How would you like all that to be read by customs agents the next time you come back from, say, London?

A recent InformationWeek article described how former Anaheim, Calif., junior high school math teacher Michael Timothy Arnold’s laptop, CDs, and memory stick were examined by border agents at the Los Angeles International Airport when he came back from the Philippines in 2005. A lower court found that the contents of electronic devices are even more personal than, say, a diary, and that agents must have reasonable suspicion before examining the contents. The government disagreed and is appealing. At least two organizations — the Electronic Frontier Foundation and the Association of Corporate Travel Executives — believe the ruling was correct and have filed an amicus brief with the court.

That’s a consequence of carrying the information with you - and completely avoidable only by not doing so.

On the same day that the newsletter arrived, the news broke that someone had managed to gain access to the email folders on up to 1,500 PCs in the Office of the U.S. Secretary of Defence - an embarrassment that was unembarrassedly dismissed as essentially business as usual by the people responsible for letting it happen.

Fundamentally that was an inevitable consequence of the technology they use, and completely avoidable only by abandoning it.

What these two news items have in common is that they represent the collision of unopposable forces with immovable objects: officialdom will feather its own careers and pry into your business, and if that means using Wintel in sensitive environments or forcing travellers to hand over laptops and passwords, than that’s exactly what they’ll do.

But you don’t have to get crunched: adopt centralised Unix computing with decentralised management and you can abandon the laptop to history while reducing the pool of potential attackers to those with significant skill, patience, and resources.

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 27 Talkback(s)
Solutions
Boot level encryption by Compusec. Freeware
Encryption in hidden partitions or files by truecrypt. Open source.

Type in your password.
Let the agent look at your "private files".
Your ... (Read the rest)
Posted by: The_Curmudgeon Posted on: 06/29/07 You are currently: a Guest | | Terms of Use
Well Don Quiote ....  ShadeTree | 06/28/07
Encryption  Erik Engbrecht | 06/28/07
A warrant? what are you - an American  murph_zZDNet Moderator | 06/28/07
Yeah...  Erik Engbrecht | 06/28/07
There are plenty of choices  Linux User 147560 | 06/28/07
Perhaps....  bportlock | 06/28/07
I do #5 myself  Michael Kelly | 06/28/07
Agreed - however there are two main issues:  murph_zZDNet Moderator | 06/28/07
You are also sending data over a line that ...  ShadeTree | 06/28/07
actually, no  murph_zZDNet Moderator | 06/28/07
You can apply the same level of encryption ...  ShadeTree | 06/28/07
Wasn't your example about a US citizen ....  ShadeTree | 06/28/07
Guys ...  p_msac@... | 06/28/07
It would be actually good ...  p_msac@... | 06/28/07
In most countries, including Canada  murph_zZDNet Moderator | 06/28/07
I am not an expert in legal systems but ...  p_msac@... | 06/28/07
republican sensibilities  christopher@... | 06/28/07
You must have missed the 2006 elections.  ShadeTree | 06/28/07
The Bill of Rights  mdemuth | 06/28/07
Hmm...  rapson | 06/28/07
yes I am saying that!!!  christopher@... | 06/28/07
Maybe if you understood how our government works ....  ShadeTree | 06/28/07
Creationism and Democracy  Erik Engbrecht | 06/28/07
And in the end may just be right.  ShadeTree | 06/28/07
re: Hmm...  M.R. Kennedy | 06/28/07
Well...  rapson | 06/28/07
Solutions  The_Curmudgeon | 06/29/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here