Harvard Secretly Searched Deans' Email
theodp writes "Taking a page from HP's playbook, Harvard University administrators secretly searched the emails of 16 deans last fall, looking for a leak to reporters about a case of cheating. The deans were not warned about the email access and only one was told of the search afterward. Dean and CS prof Michael Smith said in an email Sunday that Harvard will not comment on personnel matters or provide additional information about the board cases that were concluded during the fall term. Smith's office and the Harvard general counsel's office authorized the search, according to a Boston Globe report. Smith's Harvard bio notes that his entrepreneurial experience included co-founding and selling Liquid Machines, where Smith coincidentally invented a software technique designed to keep unauthorized people from reading electronic documents."
It was always made clear to me that my work email could be monitored for any reason. Dean or janitor, you are an employee.
Tomorrow is another day...
re: "...Smith coincidentally invented a software technique designed to keep unauthorized people from reading electronic documents." [emphasis mine]
.
Since the Deans and Faculty members are technically employees of the Harvard Corporation / Harvard University, then there was no unauthorized access, since I am sure that Harvard reserves the right to peruse and otherwise scrounge through the work product of its employees. Whether it can do that to its students, though, may be another matter.
.
Anyone here have direct access to a Harvard Faculty / Administration Employment Manual or Employee Agreement or Contract? That's the only way to be sure: look at the actual contract.
Here is Harry Lewis thoughts on the matter...
http://harry-lewis.blogspot.com/2013/03/email-privacy-at-harvard.html
For those not familiar, Harry Lewis was not only the Dean of Harvard College for a number of years, he is also a Professor of Computer Science.
When you work for someone you need to assume that your email is read, your website are logged, your SSL traffic decrypted and your computer inventoried. It is also a fairly safe assumption that login, logoff times, screenshots and keyboard strokes as well as mouse movements are all routinely captured.
Depending on your place of employment many of these big brother activities are demanded by law (SEC etc). It's not a question of whether or not you like or the IT department likes it, because neither of you do. It's a question of someone /way/ up your food chain has made the decision to perform that level of monitoring. If your going to get mad, get mad at the VP, the legal team, the SEC, or other person typically at the VP level that had the power to demand the level of logging to begin with.
To illustrate my point on how these things are often driven by and watched from the top you need only look at Yahoo. Their new CEO looked at the VPN logs when she saw the parking lot emptier than she thought it should be. She concluded people were slacking off and not really working and ended telecommuting for everyone at Yahoo. This was a data driven decision based on the logs that Yahoo's servers kept and their CEO reviewed.
I'm not justifying this, I'm not defending this, I'm simply explaining how these things work in the real world.
Harvard has a problem because of THIS:
Harvard University Information Security
FAS Policy Regarding the Privacy of Faculty Electronic Materials
The Faculty of Arts and Sciences (FAS) provides the members of its faculty with computers, access to a computer network and computing services for business purposes, and it is expected that these resources will be used in an appropriate and professional manner. The FAS considers faculty email messages and other electronic documents stored on Harvard-owned computers to be confidential, and will not access them, except in the following circumstances.
First, IT staff may need access to faculty electronic records in order to ensure proper functioning of our computer infrastructure. In performing these services, IT staff members are required to handle private information in a professional and appropriate manner, in accordance with the Harvard Personnel Manual for Administrative and Professional Staff. The failure to do so constitutes grounds for disciplinary action.
Second, in extraordinary circumstances such as legal proceedings and internal Harvard investigations, faculty records may be accessed and copied by the administration. Such review requires the approval of the Dean of the FAS and the Office of the General Counsel. The faculty member is entitled to prior written notice that his or her records will be reviewed, unless circumstances make prior notification impossible, in which case the faculty member will be notified at the earliest possible opportunity.
They were not notified according to this policy.
Could get messy.
When are people going to learn that they have no privacy on their employer's computer systems? Geeks and IT folks seem to have the biggest problem with this. If you really need that privacy, go out to your car on your lunch hour and use your smartphone. At the end of the day, it's your employer's power, bandwidth, space, and equipment. If they want to monitor their systems, they have every right to do so. Now obviously, some monitoring is a huge gray area when it comes to moral and ethical issues. So why not simply side step the issue by using your own person accounts, devices, and access?
Here we have a story about how students, generally of wealth and privilege, being caught cheating, and being handed less severe sentences then are handed out by low ranking local state schools. Adding to that, the school's biggest concern now seems to be to get whomever had the audacity to air Harvard's dirty laundry.
Slashdot reaction? Silly noobs, e-mail is insecure. Employers have the right to search company e-mail.
Hey guys, how about concern about what these people are teaching the kids who, let's face it, will be future congresscritters and other leaders. Hey, it's OK to cheat, just don't get caught, or else you'll get a slap on the wrist. Oh, and be sure to exact revenge on whoever lets the plebs know.