From: cert-advisory-request@CERT.ORG (CERT Advisory)
Newsgroups: comp.security.announce
Subject: CERT Advisory - Keystroke Logging Banner
Message-ID: <9212071919.AA27435@tictac.cert.org>
Date: 7 Dec 92 19:16:56 GMT
Distribution: inet
Organization: Computer Emergency Response Team : 412-268-7090
Lines: 100


CA-92:19                         CERT Advisory
                                December 7, 1992
                            Keystroke Logging Banner

-----------------------------------------------------------------------------

The CERT Coordination Center has received information from the United States
Department of Justice, General Litigation and Legal Advice Section, Criminal
Division, regarding keystroke monitoring by computer systems administrators,
as a method of protecting computer systems from unauthorized access.

The information that follows is based on the Justice Department's advice
to all federal agencies.  CERT strongly suggests adding a notice banner
such as the one included below to all systems.  Sites not covered by U.S.
law should consult their legal counsel.

-----------------------------------------------------------------------------

    The legality of such monitoring is governed by 18 U.S.C. section 2510
    et seq.  That statute was last amended in 1986, years before the words
    "virus" and "worm" became part of our everyday vocabulary.  Therefore,
    not surprisingly, the statute does not directly address the propriety
    of keystroke monitoring by system administrators.

    Attorneys for the Department have engaged in a review of the statute
    and its legislative history.  We believe that such keystroke monitoring
    of intruders may be defensible under the statute.  However, the statute
    does not expressly authorize such monitoring.  Moreover, no court has
    yet had an opportunity to rule on this issue.  If the courts were to
    decide that such monitoring is improper, it would potentially give rise
    to both criminal and civil liability for system administrators.
    Therefore, absent clear guidance from the courts, we believe it is
    advisable for system administrators who will be engaged in such
    monitoring to give notice to those who would be subject to monitoring
    that, by using the system, they are expressly consenting to such
    monitoring.  Since it is important that unauthorized intruders be given
    notice, some form of banner notice at the time of signing on to the
    system is required.  Simply providing written notice in advance to only
    authorized users will not be sufficient to place outside hackers on
    notice.

    An agency's banner should give clear and unequivocal notice to
    intruders that by signing onto the system they are expressly consenting
    to such monitoring.  The banner should also indicate to authorized
    users that they may be monitored during the effort to monitor the
    intruder (e.g., if a hacker is downloading a user's file, keystroke
    monitoring will intercept both the hacker's download command and the
    authorized user's file).  We also understand that system administrators
    may in some cases monitor authorized users in the course of routine
    system maintenance.  If this is the case, the banner should indicate
    this fact.  An example of an appropriate banner might be as follows:



       This system is for the use of authorized users only.
       Individuals using this computer system without authority, or in
       excess of their authority, are subject to having all of their
       activities on this system monitored and recorded by system
       personnel.

       In the course of monitoring individuals improperly using this
       system, or in the course of system maintenance, the activities
       of authorized users may also be monitored.

       Anyone using this system expressly consents to such monitoring
       and is advised that if such monitoring reveals possible
       evidence of criminal activity, system personnel may provide the
       evidence of such monitoring to law enforcement officials.



-----------------------------------------------------------------------------
Each site using this suggested banner should tailor it to their precise
needs.  Any questions should be directed to your organization's legal
counsel.

-----------------------------------------------------------------------------
The CERT Coordination Center wishes to thank Robert S. Mueller, III,
Scott Charney and Marty Stansell-Gamm from the United States Department
of Justice for their help in preparing this Advisory.

-----------------------------------------------------------------------------
If you believe that your system has been compromised, contact the CERT
Coordination Center or your representative in FIRST (Forum of Incident
Response and Security Teams).

Internet E-mail: cert@cert.org
Telephone: 412-268-7090 (24-hour hotline)
           CERT personnel answer 7:30 a.m.-6:00 p.m. EST(GMT-5)/EDT(GMT-4),
           on call for emergencies during other hours.

CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh, PA 15213-3890

Past advisories, information about FIRST representatives, and other
information related to computer security are available for anonymous FTP
from cert.org (192.88.209.5).
-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  1 09:16:01 1993

From: jeremy mcdermaid <st_mcdermaid@stdvax.cc.slcc.edu>
Subject:  Big Brother is watching!!
Message-ID: <751898936-0-14477@chop.isca.uiowa.edu>
Date: Fri, 29 Oct 1993 12:51:33 GMT

**I am posting this for a friend who is without usenet access. I agree with 
him fully, see if you don't too.

UNAUTHORIZED ACCESS IS UNWELCOMED...

This system is a for the use of AUTHORIZED USERS ONLY.  Individuals using 
computer system without authority, or in excess of their authority, are
subject to having all of their activities on this system monitored and
recorded by system personnel.

In the course of monitoring individuals improperly using this system, or 
in the course of system maintenance, the activities of authorized users
may also be monitored.

Anyone using this system expressly consents to such monitoring and is 
advised that if such monitoring reveals possible evidence of criminal
activity, system personnel may provide the evidence of such monitoring
to law enforcement officials.

Until further notice access to this NODE will have limited access hours:

        6:00am - 11:00pm

SYSTEM On-line ...
------------------------------------------------------------------------


****  The above text is the introductory screen for logging into the 
Student VAX provided by the Salt Lake Community College in West Vally, Utah.

     The reason why I am presenting this to you is because I believe the 
System Administrator is taking away our e-mail and private document
privacy.  The reference above to, "...or in the course of system
maintenance..."  can only be interpreted as, "SYSOP can read and/or 
distribute private e-mail at his discretion."   This, in my opinion, is
an outrage.  It's as if the postmaster had the right to open all your 
private mail and read it, distributing what HE deems suspicious or illegal
to police or other authorities.  The need for system security cannot be
that imperative, and I believe it violates my rights as a U.S. citizen to
privacy.

     The students at Salt Lake Community College pay money (in the form of
"student fees") to keep the system we work on up and running.  This means I
literally pay for a mailbox through the Student VAX computer.  I believe this
gives me the right to private e-mail, and privacy of files unless REAL
evidence is presented (to me first, as well as the "authorities") that I
personally am abusing the system access I'm given.  I think such a "right" 
is fundamental and not harmful to other system users.

     I realize also that e-mail across the Internet is not generally
considered "private," but my personal files should be private, as long as
I obey proper etiquette and do not "hack" at this system or other systems 
through the Student VAX computer or break any local/federal laws regarding
computer data such as is applicable.  But, that would constitute a good
reason in my eyes for inquiry into my activities.  Just like when the 
FBI applies for a wiretap or search-warrant, they have to have just cause
and present evidence for Judicial review before they can obtain such a
document/authority.  My point is that the police, judge, jury, prosecutor,
and dealer-of-punishment all happen to be the same person: SYSOP.
Everything I do on this system is subject to his scrutiny.  Let's say for 
instance that I was writing my resume to apply for his job, or that I get
a very juicy letter from my girlfriend, or I am part of a user-group for
closetted gay males.  He defined his rights above as being basically free
to read and investigate ANYTHING I happen to have on the Student VAX 
computer.  I think this concept of SYSOP as dictator is improper at best.

     The school owns the Student VAX, not the SYSOP.  The school would be
a sad and lonely place without students.  I think I should have the "right"
to have e-mail that is not subject to his omnipotent eye, nor do I have any
respect for a SYSOP that would so flagrantly abuse my privacy.

     I ask for a passive-resistance response from whomever reads this post.
I would like you to write my SYSOP and tell him what you think about this
policy of his.  I reccomend that you either send this post with whatever
comments you deem apropriate, or just sent him the following message :

"BIG BROTHER IS WATCHING YOU!"

     His e-mail address (which I cannot read, nor approve of) is:

       SYSTEM@STDVAX.cc.slcc.edu
and or U_HAWKINS@VAXI.cc.slcc.edu

   His name is Marv.

     I would appreciate any personal comments about my letter, and if you can,
carbon copies of the more interesting responses to my address below:

ST_KLOSIEWSK@STDVAX.cc.slcc.edu


     Thank you for your time.



-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  1 09:15:40 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: comp.org.eff.talk,alt.comp.acad-freedom.talk,alt.privacy,comp.admin.policy
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 8 Nov 1993 14:58:04 -0500
Message-ID: <2bm8cc$d6m@eff.org>

The policy virus spreads. Here is the Northwestern Univeristy login
message:

"This system is for the use of authorized users only.  Individuals
using this computer system without authority or in the excess of their
authority are subject to having all their activities on this system
monitored and recorded by system personnel.  In the course of
monitoring individuals improperly using this system or in the course
of system maintenance, the activities of authorized user may also be
monitored.  Anyone using this system expressly consents to such
monitoring and is advised that if such monitoring reveals possible
evidence of illegal activity or violation of University regulations
system personnel may provide the evidence of such monitoring to
University authorities and/or law enforcement officials."

-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  8 15:49:28 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: comp.org.eff.talk,alt.comp.acad-freedom.talk,alt.privacy,comp.admin.policy
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 8 Nov 1993 15:49:32 -0500
Message-ID: <2bmbcs$ec7@eff.org>

Here is a version from a unit of a state university that offers
database services related to agriculture:

    [XXX]Net is for authorized users only.  Everyone using [XXX]Net
    is subject to having their activities monitored and/or recorded.

The Director of the unit volunteered that they don't look at email
because they consider it confidential. But how do the users know that?
Also, directors change. Institutions often have short memories. When
the only written policy says that email *can* be searched, it is easy
to imagine a scenario where in a few years email will be routinely
read.

- Carl
-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  8 16:31:58 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: comp.org.eff.talk,alt.comp.acad-freedom.talk,alt.privacy,comp.admin.policy
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 8 Nov 1993 18:20:48 -0500
Message-ID: <2bmk8g$hdf@eff.org>

Here is a version from Weber State University in Ogden, Utah. I'm told
it appears everytime somone logs into either of the main campus Vaxes.
Note that it is explicit that suspicion is the only precondition to
monitoring. - Carl

=================
                   Weber State University

                    Authorized Use Only

  Unauthorized use is punishable by law (Utah Code 76-6-703)

*******************************************************************************
**       Individuals suspected of using this computer system without         **
**       authority, or in excess of their authority, may have their          **
**       activities on this system monitored and recorded by system          **
**       personnel.                                                          **
**                                                                           **
**       In the course of monitoring such individuals the activities         **
**       of authorized users may also be monitored.                          **
**                                                                           **
**       Anyone using this system expressly consents to such monitoring      **
**       and is advised that if such monitoring reveals possible             **
**       evidence of criminal activity, system personnel may, under the      **
**       express direction of University legal counsel, provide the          **
**       evidence of such monitoring to law enforcement officials.           **
*******************************************************************************

     PLEASE PRESS ENTER TO CONTINUE  >___<


============================================================================

-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  8 18:33:44 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: comp.org.eff.talk,alt.comp.acad-freedom.talk,alt.privacy,comp.admin.policy
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 8 Nov 1993 19:11:23 -0500
Message-ID: <2bmn7b$ia9@eff.org>

[After this one, I'll post these variations to the CERT recommended
policy only to alt.comp.acad-freedom.talk.]

From the login banner of the Stevens Institute of Technology (Hoboken,
NJ). The Institute is 123 years old and offers BS, MS, and Ph.D.
degrees:

==================================================
	Unauthorized use is not allowed; keystroke monitoring by 
	authorized personnel may be in effect when system security or 
	integrity is in question.  By using this system, you expressly 
	consent to such monitoring and any resultant legal actions.
==================================================

- Carl

-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov  8 19:13:56 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: alt.comp.acad-freedom.talk
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 10 Nov 1993 15:58:26 -0500
Message-ID: <2brkli$l0i@eff.org>


The U. of Michigan's login banner. (May be independent of CERT's
recommended policy.)

============
SunOS 4.1.3  - X11R5 - OSF Motif 1.2.2

-----------------------------------------------------------------------------

This is the Computer Aided Engineering Network information technology
environment at the University of Michigan College of Engineering.

You must be authorized to use these resources.  Unauthorized or criminal
use is prohibited.  Users agree to abide by the highest standards of
responsibility to their colleagues and are required to comply with all
University policies and with state and federal laws concerning appropriate
use of information technology.  Non-compliance is considered a serious
breach of community standards and may result in disciplinary or legal action.
To learn about or review these policy documents, run the "caenhelp" program
and choose the Accounts option.

Thank you for using U-M information technology resources responsibly.
Welcome!

============
-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov 10 15:59:53 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: alt.comp.acad-freedom.talk
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 10 Nov 1993 15:59:57 -0500
Message-ID: <2brkod$l1r@eff.org>

[A repost, to fewer newsgroups]

From enuxsa.eas.asu.edu at Arizona State University:

============
    Welcome to ENUXSA - A SPARCenter 2000 running Solaris 2.2 (SunOS 5.2)

             This system is for the use of authorized users only.
 
Individuals   using  this computer system without authority, or in  excess  of
their  authority, are  subject to  having  all  of their  activities  on  this
system monitored and  recorded  by  system   personnel.    In  the  course  of
monitoring   individuals  improperly   using this  system,  or in  the  course
of  system  maintenance,  the  activities  of authorized  users  may also   be
monitored.    Anyone   using this system expressly consents to such monitoring
and  is  advised   that   if   such   monitoring  reveals  possible   criminal
activity,   system  personnel  may  provide the evidence of such monitoring to
law  enforcement officials.

This machine is to be used for research, coursework, and related computational
activities associated with Arizona State  Univerity's College  of  Engineering
and Applied Sciences.  Use  of  this machine for activities  other than  those
stated may result in account elimination.

			     ***** NOTE *****
Unnecessary looping shell scripts will not be tolerated on this  machine.  The
shell script(s) will be terminated and the initiating account  will be locked.
The system manager will be the judge of a shell script's "neccessity."

============
-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov 10 16:01:23 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: alt.comp.acad-freedom.talk
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 10 Nov 1993 16:01:27 -0500
Message-ID: <2brkr7$l32@eff.org>

Worcester Polytechnic Institute, Worcester, MA, terminal server
login:

============
Individuals using this computer system without authority, or in excess of their
authority, are subject to having all of their activities on WPI systems moni-
tored and recorded by system personnel.

In the course of monitoring individuals improperly using WPI systems, or in the
course of system maintenance, the activities of authorized users may also be
monitored.

Anyone using WPI systems expressly consents to such monitoring and is advised
that if such monitoring reveals possible evidence of criminal activity, system
personnel may provide the evidence of such monitoring to law enforcement
officials.
============

-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov 10 16:13:48 1993

From: kadie@eff.org (Carl M. Kadie)
Newsgroups: alt.comp.acad-freedom.talk
Subject: Re: The CERT policy "virus" spreads (was Big Brother is watching!!)
Date: 11 Nov 1993 23:27:50 -0500
Message-ID: <2bv3c6$f6j@eff.org>

U. of South Florida College of Engineering, sign on screen:

=======================
College of Engineering                               University of South Florida
    ************************************************************************
         ***** WARNING! UNAUTHORIZED USE OF THIS SYSTEM IS ILLEGAL! *****
    This system is for the use of authorized users only.  Individuals
    using this computer system without authority, or in excess of their
    authority, are subject to having all of their activities on this system
    monitored and recorded by system personnel.

    In the course of monitoring individuals improperly using this system,
    or in the course of system maintenance, the activities of authorized
    users may also be monitored.

    Anyone using this system expressly consents to such monitoring and is
    advised that if such monitoring reveals possible evidence of criminal
    activity, system personnel may provide the evidence of such monitoring
    to law enforcement officials.

    Printers are for bona-fide course work only.  Use of college printers
    for personal business in not allowed.

           DIAL 974-5312 FOR A RECORDING OF CURRENT SYSTEM INFORMATION
      Refer any questions/problems to Bill Smith (mail smith) at 974-3790.
    ************************************************************************
    *                             HOT SCOOP!                               *
    ************************************************************************
    *   1.  Type 'gopher' for system wide information.                     *
    ************************************************************************
==================
-- 
Carl Kadie -- I do not represent EFF; this is just me.
 =kadie@eff.org, kadie@cs.uiuc.edu =

From caf-talk Caf Nov 11 23:29:56 1993

=============
Northern Arizona University:

This system is for the use of authorized users only. Individuals using this
computer system without authority, or in excess of their authority, are subject
to having all of their activities on this system monitored and recorded by
system personnel.  In the course of monitoring individuals improperly using
this system, or in the course of system maintenance, the activities of
authorized users may also be monitored.  Anyone using this system expressly
consents to such monitoring and is advised that if such monitoring reveals
possible evidence of criminal activity, system personnel may provide the
evidence of such monitoring to law enforcement officials.


=================
[From unix1.andrew.cmu.edu]

 This system is for the use of authorized users only. 
Unauthorized use may be monitored and recorded. 
In the course of such monitoring or through system 
maintenance, the activities of authorized users 
may be monitored.

 By using this system you expressly consent to such 
monitoring.

=====================
