Government reading your eMail - REPRISED

mbs

Expert Member
Joined
Nov 19, 2003
Messages
2,245
Reaction score
8
Location
.
As the moderators have locked the topic, apologies for having opened a new one, but I do see the need to provide some clarity on the statements made by posters, particularly the allegation that I have lied to the forum...

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">mbs - sorry to say, but it's not all about you. So stop trying to make everything a personnel issue with me and look at the issue at hand. You lied to the forum about the law even being in existence and know you seem to know all about it? what's up? Maybe you aren't that qualified to be making such comments?<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
It's easy to take something out of context and qualify it with your own interpretations, including calling it a lie - politicians and other specimens of dubious character do it all the time, including those who have nothing else to do except pursue questionable motives. I repeat: no laws have been passed concerning this. 'Passing law' means the whole due process of law, which includes ascension (reiterative formulation and review), promulgation and proclamation. At this stage, the law has not been proclaimed, which means there is no effective date that it formally passes into law. If you look carefully at Nana's 4th slide, this is confirmed - see the dashed block marked 'current'. If you like, there are many local legal sites out there which you may reference, all of which will confirm this. Regarding my 'qualified to be making such comments', I trust this clears your mind of the hysterical and emotive fog it seems to be subject to - and yes, I have had legal training.

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">mbs - why will the government not tell us how many communications they intercepted last year? Why would that number be "classified" if they are legit?<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I have no idea - I'm not Government. By the same token, I do understand their stance, as any information of this nature must be proven to have a definite and positive impact on whatever the desired objective is, before it is divulged. The reasons for this are clear - if the extent and detail of lawful interception becomes public knowledge, by its very nature this will defeat the outcomes of lawful interception, as mechanisms could be deliberately designed and put in place to thwart the investigative objective.

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">There is also a section in the Act that sends you to jail if you won't give them the information they need to decrypt your encryption.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
And rightly so, too - if you are involved in nefarious activities, you should be worried. If not, chances are you would not be an investigative target in the first place, and have no reason to be concerned.

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"> BTTB, mbs and Karnaugh,
you responses are based on previous prejudices - not so healthy.
TheRabbi post imho is an important one.
One should study the ACT and also study independant overseas comments to obtain a more objective viewpoint.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
There are no prejudices involved here - merely clear statements of fact, which provide evidentiary support for the stances adopted. On the other hand, statements based on that which can be construed as nothing else except hysterical ranting, do not lend themselves to an objective understanding of the issues to hand. I include in this category statements made by individuals who have no understanding of the local context, those who seek to popularise their viewpoints by colouring them with emotive garbage, and those who attempt to massage their public image through filibustering.

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">Please delete my thread and username and password. I have better things to do with my time than waste it giving an idiot like you valuable information.
I'm out of here!
Ps. Delete the whole thread and not just the bits you don't like - You possibly also work for the gov. the way you have edited my posts.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
It should be clear that this petulant response is indicative of the quality and substance of the original post - it certainly is to me, hence this will be my last posting on this thread.
 
Folks, it is important to understand that there has to be an "eavesdropping" capability in all forms of communications. Our phones can be tapped, both cell phones and land lines.

We don't send credit card numbers via email because they could be "harvested" by crooks to commit fraud. On that basis alone anything sent by email should not be regarded as confidential. If you want to keep it confidential then you encrypt it.

Frankly, if I was sending a lot of encrypted mesages and someone in law enforcement wanted to know what was going on, I'd invite them to come round to my flat and read all my emails on my laptop. But they'd have to get a search warrant first.

These are parts of any state that enforces the rule of law.

My only worry about this "interception software" is that it is not secure, and could be hijacked by hackers to create further chaos. And judging by the technical competence of some ISPs I think this may be a real problem. And who knows how (in)competent the "legal" eavesdroppers are?

If you're worried that the security of your business could be compromised by the information being intercepted by HACKERS, then you should also consider the eavesdroppers as hackers because the security of their operation is a completely unknown factor.

If your business is that sensitive to eavesdropping, then you'd probably have a whole bunch of security in place already, and the eavesdropping legislation is likely to be the least of your worries.

While I am all for privacy (hell, I run privacy.4mg.com) I don't think that getting alarmist about it is going to help. The constitutional right not to have your communications infringed is there, and can be enforced by the courts if things get out of hand.

One last thing: our emails are more likely to be intercepted offshore than in South Africa. The "war on terror" has made sure of that. But how anyone expects to cope with the volume of data out there is another story.

<hr noshade size="1">
Donn Edwards

Why is ADSL like a Cheeseburger? Find out at http://privacy.4mg.com

“Free-market advocates often warn that the only thing worse than a state-controlled monopoly is a privatised one.”
 
I have done some work concerning the capture and analysis of specific IP traffic for official purposes. In general the investigating authority uses their own stand-alone equipment. The ISP is required to make the traffic available. Obviously with changes to regulation it may become a requirement for ISP's to keep data for later analysis and review ... In my opinion such databases would be ear marked as "critical" databases by government (see ECT act) and probably have to comply with specific security measures.

There is always a risk that "hackers" could gain access to the facilities used by government for such interception or monitoring. This risk can however be managed through security best practices employed by both government and ISP.

I personally feel that the proposed laws are a good thing(tm)... I'd rather have SOME regulation concerning the interception and monitoring of my personal information.

It seems that statements these days need to be extensively qualified on this forum: These views are my own and probably in NO way coincides with official policy or anything else for that matter
 
The question is whether the necessary checks and balances are there to protect the public against state sponsored victimization. I also take precautions when sending email that contains private information but one cannot be too careful in my opinion. It does however take only a slightly paranoid government to start infringing on the boundaries of what can be said to be acceptable levels of intrusion.

These boundaries should be clearly defined and constantly guarded by independent authorities whose sole purpose is to keep watch on government for the sake of the public interest. Some things are too valuable to trust in the hands of government.


### What we need in South Africa is cheap 24/7, always on Internet for under R300 a month. ###
 
Personally I see nothing wrong with it - it's the people who are up to illegal activity who are the ones who need to worry. And those are the ones who will make the most noise about it mind you.

<font color="navy"><font size="1"><b>Where others have progress, we have Telkom.</b>
Hellkom website - www.hellkom.co.za</font id="size1"></font id="navy">
 
email the word"BOMB" and "PRESIDENT" and see if they come knocking.
If they do,u know they read youre mail.[8D]
 
LOL

I doubt they will come to you just for using the word. The use of the words may electronically flag the email and it will be marked for attention by an agent or something. If the words did not come in the right context they will be ignored. You might very well have written something like, “Hey babe, that new outfit is the BOMB! Can we play PRESIDENT and the intern tonight?” to your girlfriend or wife…

Cheers
Antowan


<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by SK33T</i>
<br />email the word"BOMB" and "PRESIDENT" and see if they come knocking.
If they do,u know they read youre mail.[8D]

<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

### What we need in South Africa is cheap 24/7, always on Internet for under R300 a month. ###
 
Just remember:
1. email is not secure or private. It was never designed to be. That's why you don't email your credit card number to anyone.

2. PGP is your friend. I would happily encrypt all my messages with the government's "snooping" public key in it as well, only they don't know what a PGP key is yet [:D].

<b>I've just had a brainwave</b>: why don't we all just BCC every email we ever get (incoming and outgoing) to [email protected] ?
It would be much cheaper[}:)]
 
donn: to put a spanner in the works with encrypting .. the US ... (That's where most of the encrypting tech comes from) is trying to implement the Big Brother key ..

The way it would work that every time you generated a private key for yourself a copy would be sent to the government key repository and it would stay there (under lock & key :)) untill it was needed. And the government would ONLY have access to it if you were a suspected terrorist or criminal .. and with the US Pariot act anybody who does not have 'God save America' tatooed on their genetilia would be a terrorist ... so your email would not be safe ... this key sending would be enforced by the US government only allowing companies that have been cleared by the FBI to write this sort of software ...

But on the bright side the whole of the eastern block is full of clever computer pple (I'm from there) and they don't particularly care about US policies ...

And if you REALLY paranoid and u have some programming knowledge you could encrypt the mails yourself ....

I do that for emails I send and receive from my GF, but that's only since there is some snot nose kid sitting on the mail sweeper at the office reading things he shouldn't be ...

That's my 2c's worth (ie: 4,000,000,000 Zim dollars)



We are Telkom - Resistance is Futile - You will be Assimilated
 
Current ECT legislation already makes provision for such a "skeleton key" architecture. The requirement is that any provider of cryptographic services in this country "should" by law be able to provide either a key or a method to decrypt the messages encrypted with their products.

For me the workaround is easy ... use OSS software ..
 
OOh .. I didn't know it applied to here as well ... I thought it was only US ... I guess I'll have to go back to using my Sangoma to send messages to my weed providers ...

We are Telkom - Resistance is Futile - You will be Assimilated
 
I saw that bit about "provider of cryptographic services " but I can't see how it will work with PGP. The "provider" of services is not the same as the "user" of services, and if they want the name and address of the provider it's on their web site. If you look on www.doc.gov.za there is a form you can fill in if you're a "provider", but all it asks for is name, address and so on.

Also, I use the international version of PGP, so I'm not sure how the Patriot Act would work there. All the "snooping" agencies need to do is provide a public key we can include. I'm not prepared to give them my private key (because it's private) and it would allow "them" to impersonate me. The OSS equivalent to PGP (I forget the name) would presumably leave out any of the "give your key away" nonsense.

Of course there is always WinZip 9, which allows you to encrypt stuff using the AES encryption method. Unlike the usual ZIP password which can "easily" be cracked, depending on its length, the AES one is not as simple.

The one part of encryption that is still public is WHO you are sending messages to. So if you are getting mails from someone who is under surveillance, the fact of you getting the mails may tell the investigators something. If they need to follow it up they're going to require a search warrant anyway.
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by donn</i>The one part of encryption that is still public is WHO you are sending messages to. So if you are getting mails from someone who is under surveillance, the fact of you getting the mails may tell the investigators something. If they need to follow it up they're going to require a search warrant anyway.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I have many dodgy friends so I think I will uninstall Outlook today still [:)]

<font color="navy"><font size="1"><b>Where others have progress, we have Telkom.</b>
Hellkom website - www.hellkom.co.za</font id="size1"></font id="navy">
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by MaD</i>
<br />Personally I see nothing wrong with it - it's the people who are up to illegal activity who are the ones who need to worry. And those are the ones who will make the most noise about it mind you.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
Hmm .. you'd think we in South Africa would know better than most that this argument is incorrect. Seemingly we learned nothing from our own recent history. Little more than 10 years ago you could well have been jailed for e-mailing "Apartheid should be stopped" to a friend - would that have meant you must have been "up to illegal activity"? Seemingly we also haven't learned from current events in close neighbouring countries. These things are all so close to us, this is not "just paranoia". It's only too easy for a government to come into power that changes the definition of "illegal activity" to suit their own morally corrupt ideological principles. Don't for a moment assume that there aren't Mugabe-like elements within our own government ranks that would gladly try to create the sequel "Apartheid II - The Revenge". And if it happens here, you'll be crying for the ability to be able to communicate privately. If our old government had had the ability to intercept literally any communications of the freedom struggle fighters, we wouldn't be living in a free country right now.

Having said that though, I'm not against electronic eavesdropping in principle. Especially here where crime is rife, and literally hundreds of organized international crime syndicates are operating, extensive eavesdropping capabilities would be very useful. I'm just saying that the issue must be approached extremely cautiously, and that it is very naive to assume that "it should only bother you if you're doing something wrong" (were the SAn freedom fights "doing something wrong"? Are the MDC next door "doing something wrong"?), especially in the complex political environment of Southern Africa. I support this type of surveillance only conditionally - the process MUST be transparent, and there must be accountability. In other words, the government *must* have to answer to *someone* about who it is eavesdropping, and why. No "secret wiretaps". I don't mean they should tell the public who they're listening to, but perhaps at least be some sort of judiciary review, permission (given proper motivation) should need to be obtained for every wiretap, and so on. In other words, we don't want/need a PATRIOT act equivalent. Governments should never be granted any power the appropriate use of which cannot be fully accounted for, no matter how good a reason they may seem to have.
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by Ditch</i>
Having said that though, I'm not against electronic eavesdropping in principle. Especially here where crime is rife, and literally hundreds of organized international crime syndicates are operating, extensive eavesdropping capabilities would be very useful. I'm just saying that the issue must be approached extremely cautiously, and that it is very naive to assume that "it should only bother you if you're doing something wrong" (were the SAn freedom fights "doing something wrong"? Are the MDC next door "doing something wrong"?), especially in the complex political environment of Southern Africa. I support this type of surveillance only conditionally - the process MUST be transparent, and there must be accountability. In other words, the government *must* have to answer to *someone* about who it is eavesdropping, and why. No "secret wiretaps". I don't mean they should tell the public who they're listening to, but perhaps at least be some sort of judiciary review, permission (given proper motivation) should need to be obtained for every wiretap, and so on. In other words, we don't want/need a PATRIOT act equivalent. Governments should never be granted any power the appropriate use of which cannot be fully accounted for, no matter how good a reason they may seem to have.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
And that is <u>precisely</u> what the proposed statutory and regulatory mechanisms and the whole consultative process are all about - if all would read carefully without emotive garbage clouding the issue, regrettably as was not the case with certain postings on the previous thread, this thread really becomes a non-issue...
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by MaD</i>
<br />Personally I see nothing wrong with it - it's the people who are up to illegal activity who are the ones who need to worry. And those are the ones who will make the most noise about it mind you.

<font color="navy"><font size="1"><b>Where others have progress, we have Telkom.</b>
Hellkom website - www.hellkom.co.za</font id="size1"></font id="navy">
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

I cringe when I read things like that.

Your theory works fine if the people in power never abuse their power.

Unfortunately people in power ALWAYS abuse their power. Hence the only (minimal) protection against them the sheeple can get it is if they, the sheeple, limit these peoples' power.

There is no other way ...

Reading the original Greek works describing the theory AND PRACTICAL EXPERIANCES of democracy should be compulsory reading in our schools.

-Information anarchist-
www.sentechhatesfreespeech.org.za
I support:
www.telkom.fokkensuig.co.za
www.poopband.co.za
www.hellkom.co.za
Read about MaD of hellkom being sued for R5million by Telkom:
http://www.myadsl.co.za/forum/topic.asp?TOPIC_ID=4316
 
the transparency and accountability of govt (and private) interception and monitoring is crucial - under the new Regulation Act there are certain safeguards and checks but ultimately only time will tell

my issue with all the new regulation from govt is that i do not think they have thought it through very carefully with regard to ISPs - ISPs are perceived worldwide as the key to regulating the Internet


in SA
1. ISPs are so widely defined as to include schools, universities and perhaps even businesses
2. ISPs are defined differently under the new Interception Act, ECT Act and the forthcoming Film and Publications Amendment Act and required to register separately with different authorities under each
3. the costs of getting an interception capability and maintaining it is generally to be borne by ISPs - this cost, including the cost of storing some info for up to 5 years, is going to be passed on to endusers
4. new proposed codes of conduct for ISPs thru Industry Representative Bodies put further obligations on ISPs (see the Notice on the DoC homepage)

ISPs - whoever and whatever they may be - are going to have a tough time on the regulatory front and with new competition coming in and i think we may see many smaller players disappearing
 
Government doesn't think further than they can throw themselves, and instead of them paying for the provisioning of a service THEY want, we have to pay for it. It's a stupid idea and a waste of money, not to mention will A) take away from the profitability of the ISP and B) increase the cost of providing internet access. If someone involved in criminal behaviour knows how to use the Net they will know about encryption, PGP, anonymizer etc. etc., Gov has no idea of how many headaches they will have, and how many they will be giving to ISP's. Gov should pay for everything involved in setting up this completely useless monitoring initiative.

It's like a landlord telling people they rent a house to that they must install spy cameras everywhere and they have to buy the cameras, install and maintain them, provide a means for him to see what's happening from where he is at the time, at their own cost and they have to be happy with it because it's for their own good. Are these policymakers on drugs? If they are they should stay away from the cheap stuff they using now.

<font color="navy"><font size="1"><b>Where others have progress, we have Telkom.</b> Hellkom website - www.hellkom.co.za</font id="size1"></font id="navy">
 
&gt;&gt;&gt;&gt;

From: "Donn Edwards"
To: "Edmund Baloyi" &lt;[email protected]&gt;; "Jayesh Nana" &lt;[email protected]&gt;
Sent: Monday, September 20, 2004 11:17 AM
Subject: [despammed] Lawful Interception Act - Presentation at iWeek


Dear Edmund and Jayesh

I wasn't able to attend the iWeek seminars, and have looked at your
presentation.

I have two questions:

1. Do you have a copy of the notes or any other material relating to this
topic that you can send me?

All I have been able to find is
http://www.info.gov.za/acts/2002/a70-02/index.html
The text of the act and
http://www.ispa.org.za/iweek/presentations/Jayesh.Nana.ppt
the presentation
Any further information would be most helpful.

2. If I send files or messages using PGP encryption, is there a PUBLIC key
that I can include that would allow the relevant "interception" agency to
read these messages without me having to disclose my PRIVATE key to anyone?
I have nothing to hide, and wish to prove it by including such a public key,
but I will not comply even with a court order to disclose my private key,
since it would then allow someone else to impersonate me, which would amount
to identity theft.

I assume that you know what PGP is ;) My public key is at
http://www.worship.co.za/blackandwhiteinc/DonnEdwardsPublicKey.asc

Best wishes
Donn Edwards

&lt;&lt;&lt;&lt;

I'll let you know if I get any response. I'm led to beleive that the cost of this surveillance stuff will be paid for by the NIS.


<hr noshade size="1">
Donn Edwards
<div align="right">Just because they <b>say</b> it's broadband doesn't make it so</div id="right">
 
Top
Sign up to the MyBroadband newsletter
X