Judge Orders Google To Deactivate User's Gmail Account and Disclose Identity
mediapost.com
mediapost.com
Not that I agree with the ruling.
This judge's ruling is akin to allowing the bank to force the Postal Service to remove that person's PO Box account and burn all the mail inside of it in an attempt to destroy the confidential information. This is wrong on so many levels it's not funny.
1) The bank has no confirmation that the confidential information has has not been already removed from the PO Box.
2) The bank is destroying all of that person's other mail and preventing future mail from reaching that person in an attempt to correct their mistake (which is only related to a single piece of mail).
If the judge wanted to allow them access to the PO Box to remove the mail, then so be it. The current ruling makes no sense. As alex_c said, someone making important decisions about a matter (technology or otherwise) CANNOT use ignorance as an excuse. Some person that's never used a computer can be as technologically ignorant as they like, but someone that holds a position of responsibility is a different issue.
It's an absolutely terrible decision, but I think (hope?) it will be more akin to them changing the lock on your PO Box and not allowing you to access its contents until the situation is cleared up. Clearly not an acceptable decision, but it's better than permanently losing everything and can be appealed by the account's holder.
Plus, if the deactivation was a destruction of the person's data, that would put the bank at huge liability I would have to think. People have important emails and I don't think any jury would side with the bank. Imagine presenting that case to a jury. "The bank screwed up and to cover their ass, they destroyed all my email - all my personal and professional communications; important documents. . ."
It's funny then that Google -- with their free service -- has shown more compassion for this user's privacy rights than a paid service would have. (Note that I realize this 'compassion' is out of need to protect a brand, yadda yadda yadda)
And in any case, since Google has no 'contractual obligations' to its email users, do you think that it would be right and proper for the judge to order Google to shut down all free gmail addresses in the hopes that it would prevent problems for this bank? Afterall, it's a free service right? All of those users are idiots, right?
We took the document to the bank of course, they promised to "fix" her address, entirely unconcerned at the fact that they had just mailed out random personal information to a different customer. We're no longer with that bank.
To non-geeks loosing an email account isn't as big of a deal, so it's easy to see why a judge would not realize the significance.
That said it is obvious that no one wants their email account to be terminated, especially not those who use it for business, and if the court has that power to simply deactivate someone's account then something is very wrong with our judicial system.
"In 1998, Judge Ware was reprimanded by the Judicial Council of the Northern District Court of California for fabricating the story of being the brother of Virgil Ware[5], a 13 year old black boy shot by teenage racists in Alabama in 1963 on the same day as the 16th Street Baptist Church bombing. According to a story Judge Ware had told many audiences, he was riding his bike with his brother Virgil on the handlebars when Virgil was shot and killed by white racists.[6] The incident was a real one, however it happened to a different James Ware,"
I just hope that this doesn't set a precedent in future cases.
I would hope that Google would see it in their interests to appeal. Considering the judge's history, odds are an appeal would go through pretty well and Google gets to keep its reputation in tact for a relatively low cost.
There are other methods to help out the bank without setting this precedent.
http://en.wikipedia.org/wiki/James_Ware_(judge)#Noted_ruling...
Judges are supposed to be beyond doubt, if a judge has done something like that their career should be over.
If you fuck up and are re-elected, that's one thing. If you fuck up but have a lifetime appointment, well, I can't see the benefit to the people he represents to keep him on the bench.
What the fuck was a bank doing sending the confidential information of thousands to a GMail account in the first place?
The point is that there is an organisation. And some people are responsible for security.
And yes, it will cost.
The only plausible "excuse" would be that an employee decided to take a shortcut thinking that no harm would be done (and no one would know) and had a "oh f*ck!" realization when it went to the wrong address (and don't they wish they were using GMail with Undo!). This is still unacceptable. If it was a common and accepted practice, it's inexcusable.
Maybe the employees were so irritated with Microsoft outlook they have been using Gmail instead. But seriously if I were a member of that bank I would be withdrawing my money right away. If there security procedures are so lax that they send a confidential email such as that through Gmail then they aren't responsible enough to hold anyone's money.
Here's a story for ya', I won't use the bank's real name, but it rhymes with HSBC.
Anyway, a while back, I was logging into my online banking and the password no longer worked. So I called tech support to see what's up. They said, oh yeah, your password can't be more than 8 characters now. If it was more than that previously, it got truncated [not sure they actually used that word], so try the first 8 characters. So what does this tell you about the way they were/are storing my password?
123456 -> hash code 1
123 -> hash code 2 (which doesn't exist in their db)
Unless at some point they started rejecting long passwords just for being long, without checking them against the database. And this is just not plausible.
They store passwords the same way they've always stored PIN codes (where encrypting would be pointless): there's a ALPHA(8) field right next to the NUMERIC(4) field for your PIN. Those design decisions are from an era where adding an extra VARCHAR(64) to store a MD5 password times 100 million accounts cost real money. It was probably the right decision.
Rather than sneer at the older generation, try to see the constraints they worked within. It opens your mind to imagine what "right decisions" now will seem silly to later generations. Non-GC languages with threads kludged in? Program syntax limited to ASCII? Silicon? IPv4 & NATs?
Access to your accounts online should entail a system just for online access which is separate from and has a tightly controlled internal interface to the legacy bank system. I realize some banks may not have done it this way.
I spent my early career integrating with and sometimes replacing legacy mainframe systems. I have much respect for the old constraints programmers had. If a bank gets their online access wrong for anything written in the last 10 to 15 years its probably due to a decision to not architect the solution properly rather then a programmer being ignorant.
1. If I "accidentally" send an email to the bank I could get the court to kick the bank off the interwebs.
2. If I send a sensitive snail mail "accidentally" to the bank, can I get the court to lock down the bank's premises and order a search for my mail (and any copies of it)?
That is a good point if we assume that physical mail is the same as internet mail and if we assume that an email account is a location just like a physical location.
If I go buy 12 trillion dollars worth of ice cream and it melts, the government will pay me to do it again.
This time I will try and find a freezer, I promise!
Why, WHY?, would someone be held legally responsible for not replying to an email!? That is the most ridiculous and stupid thing I've ever heard in my life. The bank messed up, we all mess up, but isn't it within his legal right to publicly distribute that list if he wanted?
Obviously he didn't, but it's not his problem that they sent it to him!
Frustrating. Maybe I should move my email to my own servers.
Does this set a precedence for future "mistakes" by large companies to deactivate and identify accounts simply because they send compromising information?
Put another way, what if you wanted to "nuke" someones gmail account - do you simply need to send "confidential information" then ask for the court order?
It is certainly a far fetched and expensive plan, but the question is really about precedence this case has set.
I spoke to a lawyer friend about this entire thing:
"The judge should have conducted a "balancing test" in which he asked whose rights it was more important to protect: those of hundreds of people whose account information was in the hands of some schmuck, or those of the schmuck who won't be able to email that dirty joke to his Mom if his email is suspended. It seems that the rights of the hundreds of account holders are more important, but you can protect their rights without suspending the schmuck's email address (and that is where I agree with Mr. Morris). The court could have ordered him to turn over all of the data he inadvertently received and swear under oath that he did not retain any further copies and that he did not distribute the copies to anyone else. Once that is done, if it turns out that the sensitive information was compromised in any way, the account holders can hold the bank accountable AND the schmuck. If the schmuck is a decent guy -- and if an IT professional certifies that he purged all the data and that it was not otherwise disseminated to outsiders -- then the story should end there and there is no First Amendment violation."
I think this balance test makes way more sense than what happened in this case.
Also, I'm no legalologist, but I don't see how the rights of the bank's customers are being violated. Their agreement with the bank has been severely breached, but that's between them and the bank. Violating the schmuck's fundamental rights to correct someone else's mistake doesn't seem very balanced to me.
Would we have even heard about this?
At some point, you would have to respond to them.
- If it is the people/government are they getting their money's worth?
- If he's taking backhanders is it corruption?
- If it's neither of these what is the motivation for this sort of justice?
Perhaps I don't understand the make-up of the federal government in the US but it's presumably has to answer to the citizens.
Reasoning for de-activing the account: gmail account holder has not replied to follow up emails from the bank to destroy email and sensitive content. Therefore it is possible that the account is dormant and/or infrequently used. If that is the case, deactivation insures that the sensitive data is protected if the user happens to at this late date access their gmail account and lo and behold, surprise email from idiot bank. (This also applies if sensitive data is in the spam folder.)
Reasoning for disclosing identity: gmail account is active and frequently accessed, but the user (for whatever reason) has decided not to respond to the idiot bank. This raises the possibility that s/he has malicious intent of misusing the idiot bank's customers' information. Therefore lets find out who this person is in case the idiot bank's customers' information happens to show up elsewhere on the internet.
Obviously. (There is nothing in the earlier comment that in any way addresses the recipient's rights.)
Equally obvious is the fact that the bank in question certainly has to take every possible measure to limit the impact of their stupid mistake. Its possible (ianal) that they even have a legal obligation to do so.
Google could have responded by helping the bank recover and delete the file, as well as sending an unmissable notification to the Gmail user.
Wouldn't that be the definition of what we'd call Evil?
I think they did the correct and ethical thing by following their privacy policy.
Google did the right thing by showing the bank what it means to stick to a privacy policy.