musyokiones
Hillary Clinton’s Email Server
Max Langen
Florida International University
CGS 3095 Fall 2016
Abstract
Was Ms. Clinton’s use of a private email server before and during her
tenure as secretary of state ethical? What were her duties to protect
classified and secret information, and did she meet these? Does the
generally inadequate level of security on government servers, and the use
of private email accounts by prior secretaries of state, and other
government departments, change our analysis?
Max Langen
CGS 3095 – Fall 2016
1
Title of the Paper
1 INTRODUCTION
This paper investigates Ms. Clinton’s private email server and the data insecurity that she
authorized through its use. We will analyze her actions using the ACM code of ethics, and
conclude that her use of a private email server was unethical. Every other email written by any
colleague in every other department of the US government that dealt with classified information
was also written on a non-classified server. We conclude that the fact that not a single colleague
of Ms. Clinton’s acted ethically reduces but does not eliminate the unethical nature of Ms.
Clinton’s actions.
We will perform this analysis starting with a statement of the facts in section 2, followed
by comparison with specific relevant provisions of the ACM code of ethics in section 3, and
concluding in section 4 that Ms. Clinton’s use of private email servers, while possibly more
secure than government servers, and a 100% unanimous practice of government employees, was
unethical.
Max Langen
CGS 3095 – Fall 2016
2
2. Clinton Never Complied with Federal Data Procedures
Ms. Clinton never complied fully with the department of state’s procedures for data
protection. At all times while serving as secretary of state some or all of her emails were routed
through her blackberry and available on a private server1 with less than optimal security.2
Neither her Blackberry, nor her private email server, appear to have been hacked,
possibly because Mr. Trump was not yet at that time a candidate and his friend, Mr. Putin, had
not yet instructed Russian hackers to collect information for Mr/ Trump’s campaign.3
2.1 Government Data Procedures Offer Feeble Security
It is well know that the US government hires with an eye toward backstabbing, indolence,
and ignorance. Although this is an incorrect statement of the facts (public sector procedures
destroy the ability of government employees to deliver good work, but government employees
are not lazy4), the effect is that government servers are insecure. In fact, the CIA director’s
emails, kept following all government procedures, were hacked by a teenager.5
Considering the embarrassing or laughably low level of data protection used by the
federal government,6 Ms. Clinton may have implemented a significant improvement on the
level of security that the official and proper government servers offered. We cannot know this
because the government lies about whether it is hacked, and lies about its level of data security,7
making any comparison impossible.
1 O’Harrow
2 Wikipedia
3 CNBC
4 Frank & Lewis
5 Zetter
6 Henderson
7 Gallagher
Max Langen
CGS 3095 – Fall 2016
3
3. Comparison of Actions with ACM Code of Ethics
3.1 Ethical Actor
Our ethical actor is Ms. Hillary Clinton.
3.2 Action being Analyzed
Failure to keep all emails relating to her job as secretary of state for the United States on
the legally mandated government server.
3.3 Ethical Standard
This paper will analyze Ms. Clinton’s actions using the ACM ethical standard8
3.4 Specific Provision(s) of Ethical Standard
I will use the following provisions of the ACM:
1.3 Be honest and trustworthy. Honesty is an essential component of trust. Without trust an organization cannot function effectively. The honest computing professional will not make deliberately false or deceptive claims about a system or system design, but will instead provide full disclosure of all pertinent system limitations and problems. 1.8 Honor confidentiality. The principle of honesty extends to issues of confidentiality of information whenever one has made an explicit promise to honor confidentiality or, implicitly, when private information not directly related to the performance of one's duties becomes available. The ethical concern is to respect all obligations of confidentiality to employers, clients, and users unless discharged from such obligations by requirements of the law or other principles of this Code. 2.3 Know and respect existing laws pertaining to professional work. ACM members must obey existing local, state,province, national, and international laws unless there is a compelling ethical basis not to do so. Policies and procedures of the organizations in which one participates must also be obeyed. But compliance must be balanced with the recognition that sometimes existing laws and rules may be immoral or inappropriate and, therefore, must be challenged. Violation of a law or regulation may be ethical when that law or rule has inadequate moral basis or when it conflicts with another law judged to be more important. If one decides to violate a
8 ACM
Max Langen
CGS 3095 – Fall 2016
4
law or rule because it is viewed as unethical, or for any other reason, one must fully accept responsibility for one's actions and for the consequences. 2.6 Honor contracts, agreements, and assigned responsibilities. Honoring one's commitments is a matter of integrity and honesty. For the computer professional this includes ensuring that system elements perform as intended. Also, when one contracts for work with another party, one has an obligation to keep that party properly informed about progress toward completing that work.
3.5 Comparison of Actions with Specific Provisions: Ethical
Does our analysis change given that
The FBI found that all classified emails on Clinton’s server were drafted on “unclassified systems,” meaning that they were stored and sent from unclassified servers, violating the same policies as those on Clinton’s personal server.
9
We have to answer two questions First, if everyone else is doing it, does that make it
OK? This is not a sufficient excuse for unethical action. We might ask a second question,
however, which is if a law is not often or not ever complied with, is the law intended to be
followed, or has society established a custom of non-compliance, and in effect set the standard
lower?
Using this second form of the question, in which no classified email on Ms. Clinton’s
server was sent from a classified server (0% compliance with the law), we find that the custom of
confidentiality that Ms. Clinton is measured by is not the law, and under the custom a non-
classified server is acceptable. Under this analysis, Ms. Clinton’s use of a private server is
ethical.
Alternatively we may claim that Ms. Clinton’s use of a private server actually reduced
the chance of her emails being hacked. Under rule 1.8 she improves the confidentiality of her
emails by storing them on a more secure private server, and under 2.6 she serves the American
public by increasing the security of her emails.
9 Wikipedia
Max Langen
CGS 3095 – Fall 2016
5
We cannot correctly estimate whether her actions are ethical under this analysis, because,
while we know that her private server had inadequate security, but that no emails were taken
from it, we do not know anything about the security of the department of state servers, or
whether they were hacked during the same period. Assuming that the security of those servers
matches the generally low levels of government servers, we would find Ms. Clinton’s actions
ethical.
3.6 Comparison of Actions with Specific Provisions: Unethical
While we may be amused by the idea of a successful politician being either honest or
trustworthy, we nonetheless require, under 1.3, for Ms. Clinton’s actions to be honest and
trustworthy. In true Clinton style she has never given a direct or straight answer to any question
on this subject. This action fails a requirement of honesty and trustworthiness.
As secretary of state she was legally required to treat her emails as confidential
information to be kept under the unknown but presumed low data security of the department of
state. She made minimal attempts to comply with this law while serving as secretary of state,
and fails the ethical test of 2.3, to respect existing laws pertaining to her professional work as
secretary of state.
Max Langen
CGS 3095 – Fall 2016
6
4. CONCLUSIONS
An argument is made that Ms. Clinton complied with the custom of 100% of her
colleagues in keeping classified emails on non-classified servers, and increased data security of
her emails by storing them on a private server rather than the possibly insecure department of
state servers, and that for these two reasons her actions are ethical.
We are more persuaded by her failure to deal with the issue in an honest and trustworthy
way, and her failure to respect laws pertaining to her position as secretary of state, and find that
her actions are, on balance, unethical.
.
Max Langen
CGS 3095 – Fall 2016
7
REFERENCES
[1] https://en.wikipedia.org/wiki/Hillary_Clinton_email_controversy
[2] http://globalnews.ca/news/3035703/hillary-clinton-email-scandal-timeline/
[3] https://www.acm.org/about-acm/acm-code-of-ethics-and-professional-conduct
[4] https://courses.washington.edu/pbaf527m/govt%20employees%20final%20examp.pdf
[5] https://www.wired.com/2015/10/hacker-who-broke-into-cia-director-john-brennan-email-
tells-how-he-did-it/
[6] http://www.networkworld.com/article/3055446/security/us-government-data-security-is-
an-embarrassment.html
[7] https://www.washingtonpost.com/investigations/how-clintons-email-scandal-took-
root/2016/03/27/ee301168-e162-11e5-846c-10191d1fc4ec_story.html
[8] http://www.cnbc.com/2016/09/27/dnc-breach-was-likely-russia-not-400-pound-hacker-
law-enforcement-says.html
[9] http://arstechnica.com/security/2016/07/fdic-was-hacked-by-china-and-cio-covered-it-up/