If one has a weak password for one’s web-based personal information, is it reasonable to conclude that one has a reduced expectation of privacy with respect to that information?

(Here’s an English list (from 2006) of the 10 most common password and a list of the 500 worst ones, from the point of view of security.)

If someone uses “password” as his or her password, should he or she really be able to claim some privacy interest in the information behind it?

What about file sharing? If one has files or folders or most of one’s computer accessible to peer-to-peer sharing, does one still have some expectation of privacy in the contents somewhere?

Does it matter that unauthorized use of computer resources is illegal? In a prosecution for that offence, one cannot claim authority because of a weak password. After all, it is illegal to trespass on property if there’s a plain, non-threatening sign saying ‘do not trespass’ or ‘keep off’, even without a fence. (For that matter, many trespass laws bar trespass if the trespasser ought to have known the property was private, even without a sign or fence.) Is trespass a good analogy for privacy infringement?

Presumably one does not sacrifice one’s privacy by using P2P just because some uses of P2P may violate copyright (and some don’t).

Enough speculation: do you know of any case law or privacy officer decisions based on such reasoning? I don’t, but maybe I haven’t looked hard enough.

I know that the various governors of the legal profession (law societies, bar associations etc) tend to say that use of email generally or even unencrypted email does not waive any expectation of privacy, and, more important (perhaps), does not negate any privilege in the documents communicated by this method. Lawyers are advised to discuss communications security with their clients (and the subtle advisors warn that the clients may not be very knowledgeable about that topic, and one can’t hide behind that ignorance to establish a permission); but the general rule is that ordinary, unencrypted email is OK. VPNs and Extranets are generally considered OK too — which takes us back to the first question: does it matter how secure the password protection is for such networks?

Any relevant case law on the legal profession’s share of the question?

John D. Gregory is an Ontario lawyer called in 1977, with a special interest in what happens to the law when you take the paper away. He works in civil justice law reform at the Ministry of the Attorney General, but his Slawian opinions are not necessarily those of the Ministry.
[click on the author's name for more information]

up

3 Comments on “Privacy Expectations Despite Weak Passwords and File Sharing?”

  1. Wendy Reynolds says:

    Looks like the Government of Alberta got caught in exactly this situation http://tinyurl.com/y8fkbq8

  2. John G says:

    Well, in Alberta the person who came across the site for the forthcoming provincial budget seems to have found the template, live but not yet activated. Once the government started to put content on it, they changed the password from 'password' to something more secure.

    In any event, if there had been content and the person who went on the site did so by guessing the password, would he still not be liable for the offence of unauthorized access to a computer system? Does choosing a weak password, or not changing the default password, constitute authority to access the site? That seems to me a hard argument to make.

    Is it any different about the expection of privacy, or does a reduced expectation depend on an implied authority to know (or an 'ought to have known' principle)?

  3. Dave Paine says:

    What of the privacy of data entrusted to others? If you want to synchronize data between two computers then most software requires that it resides on the software suppliers' servers. If you use MS Mesh, for example, your data will leave Canada and reside in the US, and be therefore subject to the legal grasp of the US (there is software that does not have this drawback at http://www.broolz.co.uk, but most synchronization software operates in this way).

    And when several sources (e.g. http://www.pcworld.com/businesscenter/article/160041/nearly_twothirds_of_exemployees_steal_data_on_the_way_out.html) point to many employees being prepared to steal company data when they leave employment, it does make you wonder just where the privacy line is drawn.

SlawTips      

SlawTips Use join.me to Get on the Same Page Across the Web
Wednesday, February 8

When you need to collaborate on a document displayed on your screen, it’s great to have a colleague from down the hall come into your office and look over your … »»

Technology

SlawTips Top 10 Financial Errors: #8 Always Assume More Risk Than Needed
Friday, February 3

You should assess whether you can accept the financial risks associated with taking the matter, just as clients will assess whether they can (and will) pay your fee. Spend time at the beginning of the. […] »»

Practice

SlawTips Seeing New Federal Legislation
Wednesday, February 1

Today’s Tip is a simple reminder to view by “latest activity date”. The Parliament is back in session and those Slaw Tips readers for whom monitoring legislation is a regular … »»

Research

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Banks and Banking - Liability of banks to third parties - Negligence - General

    The plaintiffs were the former shareholders of a company that failed. They sued the defendant bank alleging that it breached its contract with the company and the plaintiffs and breached a duty ...

  • Actions - Cause of action - General principles - New or extended cause of action - Opening of floodgates

    The plaintiff and defendant worked at different branches of the same bank. The defendant’s common-law husband was the plaintiff’s ex-husband. Over a four year period, the defendant ...

  • Aliens - Definitions and general principles - Immigration consultants

    The Canadian Society of Immigration Consultants (CSIC) had been designated as the sole regulatory body of immigration consultants in Canada from 2004 until June 2011. On June 30, 2011, Bill C-35 came into force, which significantly amended ...

  • Criminal Law - Sexual offences, public morals and disorderly conduct - Public morals - Obscenity - Possession of child pornography

    The accused was convicted of making child pornography available and two counts of possession of child pornography (see [2010] Sask.R. Uned. 197). Subsequently, he was sentenced ...

  • Criminal Law - Procedure - Charge or directions - Jury or judge alone - Directions regarding pleas or evidence of witnesses, co-accused and accomplices

    Rowe was convicted by a jury of five offences. He appealed.

    The Ontario Court of Appeal allowed ...

  • Narcotic Control - Offences - Possession - General

    The accused wished to access marijuana for medicinal purposes but did not have an authorization to possess marijuana issued under the Marihuana Medical Access Regulations. He was notified that a package of marihuana addressed to him had been ...

  • Narcotic Control - General - Legislation - Exemptions - Medicinal marijuana

    McCrady, who had an application pending under the Marihuana Medical Access Regulations (MMAR) to possess and grow marijuana, was convicted of possession of marijuana (Controlled Drugs and Substances Act (CDSA), s. 4(1)). Hearn pleaded guilty ...

  • Criminal Law - Sentence - Trafficking in hashish or marijuana (incl. possession for purposes of trafficking)

    The accused pleaded guilty to one count of possession of marijuana for the purpose of trafficking. He was sentenced to 30 days’ imprisonment to be served intermittently and 11 months’ ...

  • Municipal Law - Powers of municipalities - Particular powers - Imposition and collection of taxes or fees 

    Catalyst Paper Corp. operated a paper mill in the District of North Cowichan. Catalyst objected to the tax rate that it paid compared to residential ratepayers. In 2009, the ...


law foundation icon

The re-development
of Slaw is assisted by
a grant from the
Law Foundation of Ontario

TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.

Switch to our mobile site