Competition body wants hackers prosecuted

...back to the topic, i wonder when someone from mybb is going to say something on the matter though.
 
Moneyweb.co.za did an article analysing the censored bits yesterday. Wonder if they will be issued with a take down too? The fact of the matter is the info is in the public domain now can't see why it can't be reported on in the press...
 
...back to the topic, i wonder when someone from mybb is going to say something on the matter though.
Is it true about the involvement of the forum? They're implying that it started here. This isn't a new story, but I don't remember any instructions on the forum on how to crack or hack anything to do with the bank reports.
 
a) link was posted to public document in a thread

b) simple work around, which one hardly can call Cracking (no its not hacking as some would like to call it)

c) it was removed

d) it was uploaded to wikileaks

e) reposted in a thread

f) CC now thinks a hacker was involved and makes a case

g) well where we are now at.
 
here we go another cover-
pretorianews​

Hackers blow whistle on banks

Hackers have blown the whistle on banking fees - in a report banks hoped to keep buried.

The Competition Commission, the authors of the 590-page report, had originally blacked out certain sections, which banks claimed were confidential.

The commission has now opened a criminal case against Wikileaks, a website dedicated to exposing "unethical behaviour in governments or institutions".

The Technical Report of the Banking Enquiry, concluded in June last year, was the result of a 22-month inquiry into South African banking, particularly the big four: Absa, Standard Bank, Nedbank and FNB.

An intergovernmental task team is expected to be formed soon to look at recommendations by the Competition Commission to reform South African banks.

"This report is important as it might explain why banking fees are so extremely high," explained Wikileaks on its website.

Competition Commission spokesperson Jennifer Cohen said the decision to black out certain information in the report was at the behest of the banking institutions.

A letter by commissioner Shan Ramburuth to Wikileaks says that prior to the release of the report on December 12 2008, the banks had filed claims of confidentiality.

Their reasons for wanting certain information blacked out was that it was "trade, business or industrial information that belonged to them, had a particular economic value and was not generally available to or known by others. The Competition Commission accepted these claims and undertook not to disclose the information which had been so claimed," wrote Ramburuth.

The commission particularly takes banks to task for not catering for low-income earners.

Among the recommendations is a cap on penalty fees.

"Where detailed data has been provided, indications are that as much or even more revenue is earned by banks from rejected debit orders on these accounts than from the processing of successful debit orders," it found.

The commission felt that low-income earners suffered twice when hit with these penalties as most would not intentionally default on a payment but could arguably have many valid reasons for having insufficient funds to service debit orders.

These would include getting paid late. Low-income earners also did not have the comfort of "padding" their accounts to brace themselves for such an eventuality.

"It seems to us quite unacceptable that a bank should recover more than the cost incurred in processing the rejections."

Although banks indicated they would, on application, reverse penalties in a deserving case, the commission found it was unlikely that the vast majority of customers would have the confidence or the time to challenge the debit, opting to "suffer in silence" instead.

On December 16 2008, hackers managed to reveal the blacked-out information of the report, revealing them on Wikileaks.

"We'll be engaging with the commissioner on the matter through the formal channels established through the process," said Standard Bank spokesperson Ross Linstrom.
 
a) link was posted to public document in a thread

b) simple work around, which one hardly can call Cracking (no its not hacking as some would like to call it)

c) it was removed

d) it was uploaded to wikileaks

e) reposted in a thread

f) CC now thinks a hacker was involved and makes a case

g) well where we are now at.
Thanks. So in a worst case scenario, it looks like rpm might be giving a member's IP to the cops.:eek:
 
Moneyweb.co.za did an article analysing the censored bits yesterday. Wonder if they will be issued with a take down too? The fact of the matter is the info is in the public domain now can't see why it can't be reported on in the press...

I first read about the un-redacted bits a few sundays ago in Rapport.

If, they say that ECT Act applies to what happened here, then we are going to have a lot of journalists, and newspaper/forum/blog readers in jail because that law says:

Electronic Communications and Transactions Act. 2002
Chapter XIII - Cyber Crime
85. Definition


In this Chapter, unless the context indicates otherwise-

"access" includes the actions of a person who, after taking note of any data, becomes aware of the fact that he or she is not authorised to access that data and still continues to access that data.

Not sure if I should buy Noseweek this month! ;)

btw, the wikileaks document and what was on MyBroadband seems to be 2 separate issues

there may be a more obvious section of a certain law (that I choose not to mention) that applies here, but even there it's not so obvious exactly to whom it applies.
 
Last edited:
This is ridiculous.

a testiment to show that our country is run by and policed by mere monkeys
 
What images are you referring to?
The graphs, etc?
Those images are visible from the wikileaks unredacted version.

EDIT: Taking rwenzori's post below into account - I've only made it to PG 47 :p

I'm interested in which images. Are the ones you referred to like the ones on pp 271, 272? Or are there other "censored" ones I am missing?

I am talking about the handful of images marked with something like "oops, could not uncensor" - They are mainly found at the end of the report. I am not at home so I don't have a copy of it with me. I am also not downloading one now as it would be stupidly expensive on my GPRS connection.

Which could turn out to be an Internet Cafe...

Wikileaks will never provide that info to anyone. They don't have it anymore as they don't log it to begin with. The best the investigators can do is to ask Wikileaks to put them into contact with the source by acting as a proxy. Beyond that Wikileaks is a dead end.

https does not hide your identity. Only encrypts the communication.

Indeed. Wikileaks just uses https to ensure that you connect to their legit servers and that those communication channels are secure - it is kinda less anonymous than plain https. But they have their ways to create noise to keep their https users safe from prying eyes ;)
 
This is so funny, as I said in my first post, if they just kept their mouth shut about it, very few people would have know... Now its all over the news and tons of people are aware of it.

Mullets!
 
I am talking about the handful of images marked with something like "oops, could not uncensor" - They are mainly found at the end of the report. I am not at home so I don't have a copy of it with me. I am also not downloading one now as it would be stupidly expensive on my GPRS connection.

Thanks - one on p364. I suspect the originals just had black rectangle graphics inserted for these. I appreciate the reply.
 
Is it true about the involvement of the forum? They're implying that it started here. This isn't a new story, but I don't remember any instructions on the forum on how to crack or hack anything to do with the bank reports.

I actually do remember reading that thread the day it was posted. It was hardly "hacking"; the censorship was just extremely poorly implemented in the document, from a technical perspective so bad it was little more than a sign saying "please don't read these bits" (IIRC *approximately* overlay rectangles plus some very simple protection 'flags' set) ... I don't know who they have working there, but technically this is so stupid that it is about the real world equivalent of not locking your front door and then putting a sign on saying "please don't rob my house" - anyone who claims to know anything about security should know better. My impression from the news (I am speculating here) on this is that they are going to try get MyBB to hand over the IP addresses of those who posted the instructions (I imagine that should be easy), and once you have IP's it's in most cases quite easy to track down the user(s) (I very much doubt those users would've taken significant steps to cover their tracks IP-wise because, in my view, no reasonable person would've genuinely assumed that what they were doing was such terribly illegal "hackery").

This sounds a bit dodgy to me though because merely posting instructions on how to unprotect a document is not the same as actually unprotecting the document and uploading the unprotected document to a site like WikiLeaks - surely only the latter should be illegal? (The fact that it's illegal sounds like nonsense to me anyway, but that's a separate issue.) I suppose they can misuse the police and these dodgy-sounding communist-style laws to grab those peoples' computers and look for evidence of uploading to WikiLeaks, so if those users are smart they'll delete (proper 'Eraser' shredder-style delete) any evidence of having done that. The censorship was so badly done that anyone 'in the field' who is even somewhat intelligent could've figured it out independently, without the forum instructions, and sent the unprotected file to WikiLeaks - not necessarily the instruction writers; I honestly don't know if our judicial system is smart enough to grasp these things though.

"access" includes the actions of a person who, after taking note of any data, becomes aware of the fact that he or she is not authorised to access that data and still continues to access that data.

That indeed sounds chilling, especially w.r.t. journalism or any kind of information leaking e.g. whistleblowing.

It also implies they can put anyone in jail for merely reading this document. But why even bother to put the "hackers" in jail now, since the cat is already out the bag? To send a message to the public?
 
Last edited:
/me sees one thousand paranoid MyBB users format their computers this week :D
 
It is all well and good to complain - but are there any legal way for us to give the competition commission grief over their use of Fear/Uncertainty/Doubt? Or if this turns into a legal battle of the People vs. John Doe some way to support John Doe?

Whatever else - this will be case a precedent. If the competition commission succeeds in legally punishing anybody for their own mistakes then we will never hear the end of it.

So anybody got any ideas? Maybe the Promotion of Access to Information Act can be our friend? Maybe toying with the following part [ regarding protection of commercial information]:
36.
"(2) A record may “not be refused in terms of subsection (1) insofar as it consists of
information—
(a) already publicly available;"

If the leaked version is already publicly available already [and they can't deny that] - is it possible to request the unredacted version directly from them??? In Zulu?
 
Top
Sign up to the MyBroadband newsletter
X