Showing posts with label data privacy. Show all posts

Protecting your Privacy in a Divorce. Who has access to your mail, e-mail, etc.?

I recently read an article entitled Is Your Boyfriend Reading Your Facebook Messages?, which stated that in response to an online survey, more than 20% of men admitted to reading their partner's e-mail or messaging accounts, and another 20% said they hadn't yet but would if they were suspicious that their partner was up to something.

Of course, this raises significant concerns about the behavior of the 20% who have already invaded their partner's privacy, including concerns about trust in a relationship and the dangers of controlling behavior in relationships.

It is just as shocking, though, that just as many men responded that they hadn't invaded their partner's privacy yet, but would if they were suspicious. Or, at least it would be shocking if I wasn't a divorce attorney.

In fact, I often warn my clients that everything they say can and will be used against them in Court, and that includes things they say on facebook, twitter, and even potentially in their e-mail or snail mail. Many parties don't realize that besides the lack of privacy on sites like facebook, even their e-mail and letters are discoverable in a Divorce case and could become evidence. The only communications that are not admissible are those that are privileged, such as communications with your attorney.

Regardless of the fact that some communications are discoverable, that doesn't mean you should make access to your private life easy for your ex, or allow potential breaches of the attorney-client privilege. Here are some immediate steps you should take to ensure that your ex does not have access to your e-mail, mail or other accounts:

1. Immediately change all of your passwords for e-mail, facebook, banking and other accounts. Don't use the same passwords for any accounts and make your passwords complicated so that your ex cannot guess them. For reasons why you shouldn't choose easy passwords check out this article at LifeHacker. For tips on picking strong passwords check out this article at TechSoup. If you still have concerns about an account, close it and open a brand new account.

2. Obtain a P.O. Box. Obviously if you and your ex have not yet separated there is the potential for issues with your mail, but even if you have separated and our living apart, your mail is still often vulnerable to both accidental and purposeful interception. For example, if your ex places a mail forward on their name, any mail that is marked poorly (Mr. instead of Mrs. by accident) could be forward to your ex without you ever seeing it. In addition, federal laws against mail tampering are easily broken since none of us have locks on our mailboxes. And unfortunately, children often having prying eyes.

Considering that the cost of a P.O. box for a year is probably cheaper than one hour of your attorney's time, it's well worth the investment to avoid the potential problems of having your mail unsecure.

3. Encrypt Electronic Communications. At Kelsey & Trask, P.C. we use SSL encrypted e-mail, and we encrypt and password protect any documents we send to clients that have private or financial information. You should ask your counsel to do the same to ensure that even if your account or your computer are somehow accessed, the draft and final files that you have exchanged with your counsel are not easily accessed.

For more information about protecting your privacy as much as possible through the divorce process, contact Attorney Justin Kelsey at (508) 655-5980 and schedule a free one hour initial consultation.

Is it a Crime if my Spouse Reads my E-mail?

The short answer is that your spouse has probably not violated any law by reading your e-mail, even if it is against your wishes. The law of technology is constantly changing, though, and you may want to think twice before snooping in your spouse's email.

The current law varies from state to state and you might be subject to criminal charges as the law catches up with technology. In Massachusetts, the First Circuit Court of Appeals in 2004 ruled that e-mail snooping was not a violation of the wire-tapping statute, and therefore not a crime under that law. If combined with concerning communications, e-mail snooping may be enough to trigger the criminal harassment statute in Massachusetts, though this would depend more likely on the nature of the other communications.

There is a Federal Law, the Electronic Communication Protection Act (ECPA), that prohibits interception of an e-mail while it is being transmitted. However, ECPA does not prohibit snooping in your e-mail inbox or outbox (i.e. before or after the e-mail has been transmitted).

Although snooping is not considered "hacking" under the ECPA, it may be under some state laws. In Michigan, prosecutors are attempting to apply their anti-hacking statute to a case of a Husband accessing his Wife's account to gain information about an affair. Although, many experts are quoted in a Today story as questioning this application of a law intended for a different purpose, the case raises interesting questions about two issues: What expecation of privacy does a Wife have on a shared computer (especially where her passwords were written down next to the computer) and how has the "snooping" damaged the Wife?

The damage to the Wife is certainly different than the damage experienced by a victim of identity theft or other more typical security "hacks", but this doesn't mean she is not damaged as well. It may be the case that applying the anti-hacking statute to a domestic case is not a good fit, but it is time for the legislature to catch up with today's technologies and impose either civil or criminal sanctions on e-mail snooping. The fact that such behavior is very often associated with controlling and/or violent domestic relationships should be enough to warrant prohibition of these activities.

If you are considering this type of snooping, even if you live in a jurisdiction where it is not against the law, you should consider the possible backlash. A Family Court Judge could consider this threatening behavior or otherwise hold it against you and the backlash could be much more damaging than any information discovered (even if it was admissible).

If you are concerned about your e-mail being wrongfully accessed, read our previous post about protecting your privacy.

You can view the Today Story video below:

Visit msnbc.com for breaking news, world news, and news about the economy



Why are you on Facebook?

It seems like every day I read another article about how Facebook is Becoming a Prime Source for Divorce Case Evidence. Anyone who isn't aware of the risks by now is just not paying attention. But there does still seem to be a great amount of confusion over how private you can really make your Facebook page.

While you are free to adjust your privacy settings any way you want, a chain is only as strong as its weakest link. Any one of your "friends" can share any information that they can see. To think of it another way: consider whether the post you are about to make is something you would be okay with every one of your "friends" repeating out loud to one other person they know (as in "look what Justin just posted!"). Chances are somewhere in that chain is your mother, grandmother, ex, or even a potential employer.

Of course, doing this every time you post may make you wonder, why am I even on facebook if it's going to be this hard?

Well, maybe that's a good question to ask yourself:

Why are you on Facebook?

If you are on Facebook to connect with old friends, then you should think about whether what you are posting is ideal for that purpose.

If you are on Facebook to connect with potential employers, then obviously you may want to post a different caliber of information.

And if you are on Facebook to try and hook up with old lovers, then don't be surprised when it comes up at your divorce trial.

Goals and motivations are important in life and your virtual life should be an extension of your real life (not an escape). Live (and post) accordingly.

A Picture is Worth a Thousand Words, and the Date, and the Time, and your Exact GPS Location!

Warning: this blog is going to show you information that can be used for good or evil.

If you are taking pictures with your phone (and even some cameras) and then posting those pictures on the internet, you are sharing more than just the picture. You are probably also sharing the date and time the picture was taken, the type of phone you have, what software you are using, and scariest of all - the exact location where the picture was taken.

Do I have your attention now?

Let me show you how it works:

This morning I took the above picture with my IPhone. I edited the picture on my computer and posted it here. Even after editing the picture, however, the picture retains certain embedded information.

To see this additional information you don't have to be a super smart computer hacker. On a PC, simply right-click the picture and select properties:



Now click on the details tab and immediately you will see some information that I might not have intended to share, such as the date and time the photo was taken:



When you scroll down and view the other details you see that you can also discovery I took this photo with an Apple iPhone 4. And although I might want you to know that I have an iPhone 4 so you can be super jealous, I probably don't want you to know the next thing you can discover if you keep scrolling down:



As shown in the image above, the details saved in the embedded data of this picture include the GPS Latitude and Longitude where it was taken. How did they get there? iPhones, as a "convenient feature," geo-tag all photos with this information. When you post the picture online, these details will often still remain with the image. This means that someone with minimal computer skills can figure out exactly where you were when you took the picture.

If I take the GPS Latitude and Longitude displayed in the above image and enter them into the FCC's online converter I get the following decimal results: Lat 42.288166, Long 71.333667. If I then enter these figures into an online address converter, I am told that this picture was taken at: 150 E Central St, Natick, MA 01760, USA.

Although not exact this approximation is too close for comfort (the picture was actually taken at my office located at 154 E. Central St., Natick, MA 01760).

By posting this information I realize that I am showing potential stalkers how to get information on their victims. However, I am hopeful that the majority of our readers will benefit from this information by protecting themselves rather than using it against others.

There are numerous ways in which this information could be used by attorneys or litigants in divorce cases to prove the whereabouts of somebody if those issues are in question. And the potential issues this raises in cases involving Domestic Violence are painfully obvious.

So here is the valuable TIP: Be careful what you share online, and always make sure you consider not just the information you intend to share but what information you might also be sharing inadvertently. Most phones will allow you to disable the geo-tagging feature. If you have an iPhone you can disable this feature as described in this eHow article.

M.G.L. 93H and Data Privacy Basics

Massachusetts has enacted one of the strictest data-privacy laws in the country and is scheduled to go into effect on March 1, 2010. Any personal information that any business entity maintains or stores is subject to Massachusetts General Laws Chapter 93H, while M.G.L 93I governs the destruction of physical and electronic documents and data. Both M.G.L. 93H and M.G.L. 93I define “personal information” as a person’s last name and either his or her first name or first initial, combined with any one of the following: a social security number; driver’s license number or state-issued identification card number; financial account number, debit or credit card number, with or without any required security code, access code, personal identification number or password that would permit access to a resident’s financial account.

Guidance for business’ implementation of M.G.L. 93H can be found in 201 CMR 17.00, and creates an affirmative duty to every person that “owns, stores or maintains personal information about a resident of the Commonwealth” to “develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing . . . personal information.” In determining whether such comprehensive security program complies with M.G.L. 93H and accompanying 201 CMR 17.00, a court will consider:
(a) the size, scope and type of business of the person obligated to safeguard the personal information under such comprehensive information security program;
(b) the amount of resources available to such person;
(c) the amount of stored data;
(d) the need for security and confidentiality of both consumer and employee information.

Any business must have a written information security program (“WISP”) that establishes security policies for the firm’s computers and wireless system, and all personal information contained therein. All personal information stored on laptops or “other portable devices” must be encrypted. All records and files, including emails, containing personal information that is transmitted across public networks or wirelessly must be encrypted “[t]o the extent technically feasible.” The written security program must include plans for systems monitoring for unauthorized use, up-to-date firewall protection, and up-to-date system security software that is set up to receive regular security updates.

Authentication protocols must include a “reasonably secure method of assigning and selecting passwords.” 201 CMR 17.04(1)(b). Assigning random complex passwords to clients would be a preferable defensive strategy. Such passwords must be controlled “in a location and/or format that does not compromise the security of the data they protect.”

With that in mind, businesses should develop a policy which includes:
(a) Encryption of all emails that contain personal information.
(b) Encryption of all personal information stored on portable devices
(c) Installation of system security agent software that is set up to receive security updates
(d) Maintenance of firewall protection for all files on a system connected to the internet.
(e) Implement a termination/Disciplinary policy for misuse of personal information.
(f) Education/Training of employees on proper use of computer security system and importance of personal information security.

Attorney Trask of Kelsey & Trask, P.C. was a cryptologic materials manager in the U.S. Marines, and has experience planning and implementing encrypted communications (voice and data) networks. If you have any questions regarding M.G.L. 93H, contact us at (508) 655-5980 or click here.

VIP Followers

Info recommended by: Webpages of law

Popular entries