Computer Law Review and Technology Journal
Abstract
Internet telecommuters work from home and access their employer's internal network over the Internet. This relatively new style of work has increased in popularity through the years, with an estimated 4.5 million workers Internet telecommuting in 1999. While employers enjoy compelling benefits such as reducing overhead costs, Internet telecommuting raises new security concerns for employers by exposing their internal networks to "backdoor attacks" that exploit the telecommuter's connection. The recent backdoor attack on Microsoft's source code illustrates the extent to which such attacks threaten confidential information. If such confidential information belongs to a client or third party, then the telecommuter's employer may face significant liability for damages. In such cases, employer liability will probably hinge on whether the employer provided adequate protection from such an attack.
This article considers whether, and to what extent, an employer should protect itself and others from security threats introduced by Internet telecommuting. It describes the factual setting and technology oftelecommuting over the Internet. It explains the mechanism of a backdoor attack, through which a hacker accesses the computer of a telecommuter as an avenue to invade the employer's computer system. The article also discusses the potential contract and tort liabilities that a company may face if, through such a backdoor attack, a hacker is able to obtain confidential client information stored on the company's system. Further, the article considers the possible duties and the standards of care that may be imposed in this relatively new area of potential legal liability.
Throughout the article, various risk-benefit analyses are provided using statistics from previous years and estimates of potential harm to client or customer information. These analyses focus on the probability of various attacks, the possible harm threatened by them, and the burdens to protect against them. If, however, the proposed methods are used as a basis for an actual risk-benefit analysis, then the analyst should substitute current statistics and should carefully tailor the analysis to the circumstances of the company at issue and the information at risk.
Recommended Citation
Mark J. Maier,
Backdoor Liability From Internet Telecommuters,
6
Computer L. Rev. & Tech. J.
27
(2001)
