Are interactive login banners worth having?
The general consensus is that they are, but what should the banner say?
Some things that are being considered (no particular order):
- ownership of the equipment
- no expectation of privacy
- Monitoring may be done
- authorized use only
- don't use words like "Welcome"
- in the local language if possible
- length of the banner: short and terse, long and wordy
- don't identify the use of the equipment
- vague or specific
From Prosecuting Computer Crimes, a publication of the United States Department of Justice:
Also, here are some sample NETWORK BANNER language as recommended by USDOJ and explanation for their functions, from Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations, also by the U.S. Department of Justice:
This is definitely a legal matter that shouldn't be so easily overlooked. More than likely, you SHOULD consult with your legal department (if you have one), or corresponding decision makers. Also, whatever is implemented in the banners, that being said for internal and external should probably not be redundant with already agreed Network Use Policies (probably don't want to constantly alert people about something they have already agreed on)
Speak to your legal people, it's not up to the techies to decide what goes into it, this is a policy matter, not a technical one. Depending which country you're in there will be government recommendations that will relate to local computer misuse laws.
It really depend on who is logging in, and why. If you are running a server to provide shell accounts, you probably want a pretty strong interactive login banner to remind people not to run spambots. On the other hand, if your servers are only accessed by fellow members of your Operations team, of which there are only 8, you probably don't need a banner. Really this boils down to a matter of policy, because the banner will not make a noticeable difference in behavior, and has no effect in many legal venues.
Here is what we use:
Just something like "usage of this resource is subject to the terms of our AUP" should be all you need; no need to write an essay on it. The legal and HR folks can then put their stuff into the AUP.
You'll want to ensure that everyone has a paper copy of the AUP before logging in though. IANAL but I would smell a rat if you were asking users to agree to something they hadn't even read yet.
My login banners simple say. "Everything is logged, so don't break shit" but im pretty much the only tech who ssh's into our servers.
In my mind it's another CYA item which you seem to not be able to get enough of these days.... Don't make a pre-login banner that includes any kind of "Welcome to..." statement.