Re: Logon Banners

From: Chris Ricker (kaboom@gatech.edu)
Date: 03/23/02


Date: Sat, 23 Mar 2002 00:04:08 -0700 (MST)
From: Chris Ricker <kaboom@gatech.edu>
To: leon <leon@inyc.com>

On Sat, 23 Mar 2002, leon wrote:

> There is a thread going on, on the sf-basics list about logon banners and
> legalities. The general consecutions seems to be one of two groups of
> thought; 1) If you put welcome in your logon on banner this could make
> you legally responsible if you are attacked (meaning the attacker can say,
> "well it said welcome".) 2) This is an urban legend and not really true.
>
> My question is can anyone provide links showing that there have been court
> cases decided upon this? I found a reference in one of my cisco design
> books but it does not provide links or any other cross-reference.

You don't make it clear which country's court cases you're interested in,
but
<http://www.attrition.org/security/advisory/auscert/AA-93.03.Suggested.Login.Banner>
references a case in New Zealand.

<http://www.fcw.com/fcw/articles/2000/0814/cov-law-08-14-00.asp>
offers similar information about US court cases which have hinged on banner
statements (though the issues involved in those cases were monitoring of
users vs. prohibitions against unreasonable search and seizure, not
welcoming / not welcoming external crackers).

CERT Advisory 92:19 (I think -- my handwriting's a little blurred ;-) covers
much the same ground (again, US law about banner statements vs unreasonable
search and seizure).

The latter are actually more relevant than warnings to outside crackers,
since most security breaches are internal....

At any rate, if you want specific court cases, you'll probably want to take
this over to LACC (lacc@suburbia.net), where the people who actually know
that sort of thing hang out. It's primarily US-centric (even though it's
hosted in Australia), so hopefully that's what you're after.... See
<http://www.cultural.com/web/security/mailing.lists/lacc.html> for all the
gory details. I'm not sure if it's still active -- I've not read it in a
few years.

later,
chris

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Fistful of 5-4 SCOTUS decisions ...
    ... ruled a school didn't violate a student's free speech rights when the principal ordered a banner with this phrase taken down. ... Look for more of this kind of insane drugpanic crap as more Bush appointees slither onto the Court. ... If free speech means anything, it means being able to broadcast opinions on political issues right up to election day. ...
    (rec.sport.football.college)
  • Re: Honeynet
    ... :will *help* when you are being sued for monitoring. ... one could hypothesize that a court might rule that the ... presence of such a banner indicated that the admins "had reason to ... reason to believe that the intruders would -see- the banners at all, ...
    (comp.security.misc)
  • Fistful of 5-4 SCOTUS decisions ...
    ... ruled a school didn't violate a student's free speech rights when the principal ordered a banner with this phrase taken down. ... "Justice Samuel Alito, writing for the conservative majority, said the endangered species law takes a back seat to the clean water law when it comes to the EPA handing authority to a state to issue water pollution permits. ... "The Supreme Court ruled Monday that ordinary taxpayers cannot challenge a White House initiative that helps religious charities get a share of federal money. ... If free speech means anything, it means being able to broadcast opinions on political issues right up to election day. ...
    (rec.sport.football.college)