Skip to main content

Does Every Cloud Have a Silver Lining?

5 min read
TL;DR: Thunderstorms occur when divergent forces collide in clouds. It is becoming increasingly clear that cloud computing is in our extended forecast, but whether the imminent digital due process storm the cloud foreshadows will contain a silver privacy lining remains to be seen.

Today’s New York Times article outlining law enforcement officials’ attempts to expand their digital wiretapping authority, offers interesting insight into the law enforcement world of tomorrow. In the not too distant future, TV’s crime-process dramas may take on a very different feel. Gone will be the days of gun-toting detectives busting down doors, search warrant in hand. Instead, as our lives become increasingly digital, investigations will be conducted by keyboard-wielding lab techs submitting automated requests to service providers. Don’t be surprised if the next CSI spin-off is CSI: Inbox Inspectors Division.

But why does this shift matter? Simply put, in the cloud, there is no door for the police to kick in. While the law is clear in that your physical files and those computer files stored on your computer itself enjoy the protections of the fourth amendment, those stored in the cloud do not, and the standards of proof required differ dramatically.1

Skyline with logos of cloud service providers superimposed on the clouds cleverly

Consider this: you are the target of a criminal investigation and the police believe that six months ago you e-mailed an accomplice to discuss the crime. Depending on your email settings and which service you use (for example, if the “leave downloaded messages on server” option is checked), the police may need only offer “specific and articulable facts” that they suspect the email is related to the crime.2 That same email stored on your computer (for example, if the setting is not checked), would require a search warrant and showing of probable cause, and thus would be afforded significantly greater protections under the law.3

However, the typical “if you don’t want it public, don’t put it on the internet” argument doesn’t apply here. While that may be true for photos and updates posted to social networking sites, as more and more of our lives (and commercial dealings) are pushed to the cloud, we’re losing our abilities to have a digital private sphere.4

The good news is that it’s in service providers’ interest to instill confidence in the integrity of your data by disclosing when information is shared with authorities and by pushing for legal reform to better safeguard personal data stored in the cloud. The bad news, beyond more painfully tacky computer search scenes, is that before we know it, our perception of privacy may be forced to evolve.

Thunderstorms occur when divergent forces collide in clouds. It is becoming increasingly clear that cloud computing is in our extended forecast, but whether the imminent digital due process storm the cloud foreshadows will contain a silver privacy lining remains to be seen.

Photo credit: garyhayes

Footnotes#

  1. Compare Fed. R. Crim. P. 41(e)(2)(B) with 18 U.S.C.A. § 2703(d) (West).

  2. 18 U.S.C.A. § 2703(d) (West).

  3. See generally Obtaining Electronic Evidence, Federal Law Enforcement Training Center (July 2003).

  4. Take Google, as an example, who, to their credit, is a front-runner in the push toward digital due process, testifying on the Hill just last week. Without signing up for a Google account, through the use of cookies, Google can compile a relatively accurate profile of what sites you visit and how often you visit them, what products you purchase, and where you go. And if you sign-up for a near-ubiquitous Google account, you introduce the cloud to what others are saying about you, what you read, files stored on your computer, and even your medical history, not to mention with whom you communicate, what you’re doing, and where you are right now.

Originally published October 10, 2010 View revision history
Share

More to explore

Securing the Status Quo

30 min read

Federal agencies spend billions on IT security, yet rigid compliance frameworks create false safety while stifling innovation against real threats.

Analysis of Federal Executive .govs

3 min read

A scan of every federal executive .gov reveals that only 73% are live, Drupal dominates as a CMS, and 93% of live domains use no detectable CMS at all.

Intro to GitHub for non-technical roles

10 min read

GitHub isn't just for developers. A practical guide for non-technical roles to follow along, collaborate, and track work with confidence.

Why everything should have a URL

15 min read

When knowledge lives in people's heads and inboxes, it doesn't scale. Giving decisions and processes URLs makes context discoverable, async, and opt-in.

Ben Balter

I'm Ben Balter — I write here about engineering leadership, open source, and showing your work. I wrote Open & Async, the playbook for remote and distributed teams. My open source projects have hundreds of millions of downloads. I was the Director of Hubber Enablement at GitHub, where I helped thousands of GitHubbers do their best remote work. Before this role: Chief of Staff for Security, enterprise PM, and GitHub's first Government Evangelist. Before GitHub: attorney, Presidential Innovation Fellow, and member of the White House's first agile development team. More about the author →

Follow along: Bluesky LinkedIn

This page is open source Help improve this article on GitHub