Look... I'm all for making better laws. But I'm curious... Exactly how do
you propose one would legislate around this type of behaviour beyond
changing contract law and the handling of confidentiality issues?

Frankly? I'm reasonably glad that the onus of proof, and the cost of legals
lies with the employer for attempting to demonstrate that an employee has
breached contract. It shouldn't be easy to proove that, and frankly, had
informationt hat I'd had access to linked, and a former employer attempted
action to indite me regarding it? I'd be pretty damn pissed if I had to
field the court costs and then proove that I ~hadn't~ done anything wrong?

The notion of changing the onus of proof or the burden of costs from the
accuser to the accused is completely untennable and more then a little
bloody scary really.

Perhaps include confidentiality clauses as a presumed implication of
employment. IE you are employed, therefore you are under confidentiality
constraints... But It'd take a lot of convincing before I'd support any
further measures.

But if there are examples of laws you think should be changed, I'd be
curious.
----- Original Message -----
From: "Toby Tremayne" <[EMAIL PROTECTED]>
To: "CFAussie Mailing List" <[EMAIL PROTECTED]>
Sent: Tuesday, March 04, 2003 12:41 PM
Subject: [cfaussie] RE: OT: A lesson learned


> I agree that the it laws in this country are a joke - the only thing
> we ever get any progress on is censorship or privacy invasion.
> However I must admit that usually the contracts I'ev signed in the
> past have covered this sort of thing.  They all have to do with taking
> company property home - including data etc, and stipulate I can never
> disclose - or cause to be disclosed - anything I learn / find / create
> while employed there.  And there's usually something in the contract
> that says if I have anything of theirs in my possession when/after I
> leave their employ, whether created by me or not, that i must destroy
> or return it.
>
> That kind of clause is certainly actionable - however only civily I
> believe, which means the onus is still on the employer to pay for
> legals and prove loss.
>
> One wonders when we'll ever get anyone in parliamen who understands /
> gives a monkeys about this kind of thing.
>
> Toby
>
>
>
>
> Tuesday, March 4, 2003, 1:27:38 PM, you wrote:
>
> stc> MessageIts not. Thats why it doesnt relate to IT law at all.
>
> stc> On the otherhand, we're dealing with information. Have you got any of
your email from former jobs? Was it company related? That'd be data theft.
The fact it was personally addressed to you is
> stc> very difficult to distinguish in law.
>
> stc> In the US individuals have been prosecuted for taking data from the
server, to their workstation, to work on their assigned task (successfully).
One of the speakers at sage a while back was a
> stc> convicted triple felon due to microsoft's lawyers going to work on
him when he left under less then positive circumstances.
>
> stc> The three felonies he went to jail for all involved doing his job in
line with company guidelines and with the cooperation of systems
administrators who granted him access and approved his
> stc> methods. Microsoft simply chose not to pursue charges with them.
>
> stc> How do you define that while employed you can act as an employee
performing technical duties that involve being in possession of intangible
information, without making sending the developer to
> stc> jail over half the payment disputes that arrise, but prevents your
employee from screwing you WHILE employed.
>
> stc> The answer is generally restraint of trade, and confidentiallity
clauses in employment contracts, IE when you quit, you shall not work for my
competitor for <X> months and you shall not under
> stc> any circumstances reveal information you obtain during the course of
your duties to anybody,ever,  except as required by  relevant law's.
>
> stc> Then the guy would have been screwed, he would have been twice in
breach of contract, and depending on the nature of the contract/etc -
screwed financially, or by a large black man named Bubba
> stc> in a very uncomfortable place (Not the back of a volkswagon either).
>
> stc> The fact that the IT industry is run like a collection of hedge
wizards bartering for arcane rites and services doesnt justify making life
impossible for those of us who do treat our jobs as
> stc> jobs, or expect to deal with businesses instead of slightly
progressed propellorheads who are still trying to work out what commercial
liability means.
>
> stc>   ----- Original Message -----
> stc>   From: Blake Foss
> stc>   To: CFAussie Mailing List
> stc>   Sent: Tuesday, March 04, 2003 12:05 PM
> stc>   Subject: [cfaussie] RE: OT: A lesson learned
>
>
> stc>   Maybe I just see it as being a little more black and white than
that. The guy in the article stole files and used them for his benefit.
These were not back-up files or reference files used
> stc> during the development of the project. The files were released to a
3rd party.
>
> stc>   How is this different from an employee working in a retail store
stealing furniture and passing them over to another person. Lines of code
should come under the same laws as a piece of
> stc> furniture.
>
> stc>   IT laws need to be addressed. I have some applications I have spent
a lot of time developing and working on, it would crush me if an employee
took them and used them for their own benefit, I
> stc> consider this stealing, the law sees this as being ok since they work
for me at the time.
>
> stc>   Blake
>
>
c>   -----------------------------------------------------------------------
------------
> stc>   Blake Foss
> stc>   Web Foot Forward
> stc>   p: 61 2 9340 4401
> stc>   f: 61 2 8080 8190
> stc>   m: 0410 747 620
> stc>   e: [EMAIL PROTECTED]
> stc>     -----Original Message-----
> stc>     From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
[EMAIL PROTECTED]
> stc>     Sent: Tuesday, 4 March 2003 12:40 PM
> stc>     To: CFAussie Mailing List
> stc>     Subject: [cfaussie] RE: OT: A lesson learned
>
>
> stc>     Why is that scary?
>
> stc>     Its not a violation of IT law, its should be a violation of
contract law or employment law. You can't sue an employee for fucking up,
wilfully or otherwise. He was STILL an employee with
> stc> authorization at the time of the incident.
>
> stc>     Miller said that the employee had given formal notice of his
intention to resign from the company but still had "about 10" days to go.
The relationship had been amicable, with the company
> stc> having no reason to suspect a breach was likely to be committed.
>
> stc>     If he could be prosecuted for data theft, so could and DBA who
took a backup copy onto his development laptop to workon, or anybody who
accesssed the work DB. US types HAVE been prosecuted
> stc> for accessing the database that its there job to maintain, treating
the transferance of data between their workstation and the server as data
theft.
>
> stc>     I'd suggest that our laws are significantly better. Next time I
have an argument with a client over payment, I don't want to be faced with
the counter charge of having 'stolen' their data
> stc> when I downloaded a copy of their access database to work on with
their full consent.
> stc>       ----- Original Message -----
> stc>       From: Blake Foss
> stc>       To: CFAussie Mailing List
> stc>       Sent: Tuesday, March 04, 2003 11:27 AM
> stc>       Subject: [cfaussie] RE: OT: A lesson learned
>
>
> stc>       This was an old posting, but I remembered it as seeming like
something really stupid in IT laws and shows how under funded and lazy the
Police are relating to electronic crime.
>
> stc>       Check out this article:
>
> stc>       http://www.itnews.com.au/storycontent.cfm?ID=9&Art_ID=11612
>
> stc>       Very scary and as they say in TV land, "Trust No-One".
>
> stc>       Blake
>
>
>
     -----------------------------------------------------------------------
------------
> stc>       Blake Foss
> stc>       Web Foot Forward
> stc>       p: 61 2 9340 4401
> stc>       f: 61 2 8080 8190
> stc>       m: 0410 747 620
> stc>       e: [EMAIL PROTECTED]
> stc>         -----Original Message-----
> stc>         From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Steve Soars
> stc>         Sent: Tuesday, 25 February 2003 12:49 PM
> stc>         To: CFAussie Mailing List
> stc>         Subject: [cfaussie] OT: A lesson learned
>
>
> stc>         Over the weekend a former employee of ours got into our
servers, copied files and made some small modifications, nothing major just
nuisance stuff - but enough to piss me off.
>
> stc>         Today after gathering all the log file data i decided to ring
the police.
>
> stc>         What the Computer Crimes Section told me was a bit of an eye
opener;
>
> stc>         Former staff members are allowed back inside your servers and
are able to copy and modify information at will - because they were once
allowed to.
> stc>         The only way they can be charged criminally is if they gain
access to your system via another means other than a known username and
password (it doesnt even matter if it wasnt their
> stc> username and password - any will do).
>
> stc>         The only way other than changing every password on your
system is to have a watertight employment contract, advising them that they
have no access rights to your system after their
> stc> period of employment ends, this contract must also outline the
ownership of the intellectual property they create whilst employed - this
must be signed by both parties. If they gain access to
> stc> the system outside of their employment then its a criminal act.
>
> stc>         We didnt have this in place, and our contract was full of
wholes when dealing with the ownership of the code he created for us.
>
> stc>         We can of course go after him via civil action - but he hasnt
got anything, so it would be a waste of time - i would have much preffered a
criminal conviction.
>
> stc>         A bitter lesson learned
>
> stc>         Does anyone have a contract of this nature that they would
like to share?
> stc>         Steve Soars
>
>
>
stc> -----------------------------------------------------------------------
-
>
> stc>         www.i-redlands.net
>
> stc>         Interactive Redlands
> stc>         Shop 2 Cleveland Town Square
> stc>         Cnr Queen & Bloomfield Sts
> stc>         Cleveland QLD 4163
>
> stc>         [p] 07 3821-5800
> stc>         [f] 07 3821-5811
>
> stc>         "what we do in life
> stc>         echoes an eternity"
>
>
>
stc> -----------------------------------------------------------------------
-
>
>
> stc>         ---
> stc>         You are currently subscribed to cfaussie as:
[EMAIL PROTECTED]
> stc>         To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> stc>         MX Downunder AsiaPac DevCon - http://mxdu.com/
> stc>       ---
> stc>       You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> stc>       To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> stc>       MX Downunder AsiaPac DevCon - http://mxdu.com/
> stc>     ---
> stc>     You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> stc>     To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> stc>     MX Downunder AsiaPac DevCon - http://mxdu.com/
> stc>   ---
> stc>   You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> stc>   To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> stc>   MX Downunder AsiaPac DevCon - http://mxdu.com/
>
> stc> ---
> stc> You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> stc> To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> stc> MX Downunder AsiaPac DevCon - http://mxdu.com/
>
>
>
>
>
>
>
>  ---------------------------------------
>
>              Life is poetry -
>                write it in your own words.
>
>  ---------------------------------------
>
> Toby Tremayne
> Technical Team Lead
> Code Poet and Zen Master of the Heavy Sleep
> Toll Solutions
> 154 Moray St
> Sth Melbourne
> VIC 3205
> +61 3 9697 2317
> 0416 048 090
> ICQ:  13107913
>
>
> ---
> You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
> To unsubscribe send a blank email to
[EMAIL PROTECTED]
>
> MX Downunder AsiaPac DevCon - http://mxdu.com/
>


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to