Million-rand bill for ISPs

The bottomline is that should the Scorpions ever wish to get involved in this
morash, they will issue guidelines first. They will warn the ISP's first as to exactly
what they expect. My take is that the law will only be enforced against you if you
don't play ball with the police and help them track down a terrorist - deliberatly
stallng their investigation. And the same goes for all the other compliance laws.
It's just a stick that they will only use against evil people - not agains us poor sods
just trying to make an honest living. The ANC are not insane they are not going to
embark on a terror campain against the people who pay their taxes and don't give
the government much grief. Ofcourse the legal fraternity knows this and the
PAIA fiasco proves my point.
 
pookfuzz said:
I am still trying to figure out exactly who these bad guys are that they hope to catch. My general feeling is that bad guys are not going to care about the law and will use encryption anyway.

I gave much thought to this statement, and at face value, it does appear to be a problem. However, thinking deeper, the answer is obvious. Any encrypted traffic that cannot be "broken" is in itself illegal - and a crime. Just hunt down encrypted traffic and then follow the yellow brick road to the offender.

Makes me think of the gun laws (I am all for a gun-free society). The argument there is that only criminals will have guns and that makes the rest of us unsafe - bull. Someone with a gun (other than a law-enforcment officer) is automatically a criminal, and is arrested = safer.
 
captainwifi said:
The bottomline is that should the Scorpions ever wish to get involved in this
morash, they will issue guidelines first. They will warn the ISP's first as to exactly
what they expect. My take is that the law will only be enforced against you if you
don't play ball with the police and help them track down a terrorist - deliberatly
stallng their investigation. And the same goes for all the other compliance laws.
It's just a stick that they will only use against evil people - not agains us poor sods
just trying to make an honest living. The ANC are not insane they are not going to
embark on a terror campain against the people who pay their taxes and don't give
the government much grief. Ofcourse the legal fraternity knows this and the
PAIA fiasco proves my point.

Nice post - and every word true. Anyone who thinks we have the time or capacity to monitor every email between Pietie and his "piece-on-the-side" is deluded.
In addition, without relevant laws, it is far too easy for ISPs to fob off official requests with a "we are too busy to help you arrest that paedophile" type excuse.
 
And just imagine a 64kbits/s Digicrap link between an ISP like IS||UUNET and this national data spying centre - where all packets are inspected at the whim of some person employed to do that job - major contention on that link - if Telkodemonopoly actually had employees available to actually install it at the ISP's cost...

I am thinking about this, and wondering if there will be any "slowdown" on the link. Lets compare this to Telkoms "shaping":
With shaping, the traffic is inspected en-route. To do this, each packet is "stopped", inspected and sent on.
With the proposed monitoring, the inspection will be done at the ISP - so there is no reason the traffic coming from the line cannot be "split". One portion sent on, and the other inspected.
Any gurus out there that can comment on the feasibility of this?
 
Moederloos said:
I am thinking about this, and wondering if there will be any "slowdown" on the link. Lets compare this to Telkoms "shaping":
With shaping, the traffic is inspected en-route. To do this, each packet is "stopped", inspected and sent on.
With the proposed monitoring, the inspection will be done at the ISP - so there is no reason the traffic coming from the line cannot be "split". One portion sent on, and the other inspected.
Any gurus out there that can comment on the feasibility of this?

The point of the Data interception act is not to spy on everyone all the time... a court order is required to spy on one person, and the ISP must have the facility to intercept anyones traffic.

Google for altivore :-)
 
Moederloos said:
I gave much thought to this statement, and at face value, it does appear to be a problem. However, thinking deeper, the answer is obvious. Any encrypted traffic that cannot be "broken" is in itself illegal - and a crime. Just hunt down encrypted traffic and then follow the yellow brick road to the offender.

Makes me think of the gun laws (I am all for a gun-free society). The argument there is that only criminals will have guns and that makes the rest of us unsafe - bull. Someone with a gun (other than a law-enforcment officer) is automatically a criminal, and is arrested = safer.

I cannot really agree here. The 128 bit SSL link that is used for my internet banking is pretty hard to break as far as I know. The only successfull attacks I know about have been at the end points, rather than the SSL link and then also a couple of academic attacks using supercomputers or grids, which even the government will probably not have a bunch of lying around.

The same for the IPSec VPN I use to connect to work. Af far as I know this is even harder to break than the SSL link. My traffic on the VPN is pretty boring, but still includes things like my password everytime I get mail etc., so I would not really like that traffic to be readable by everybody.

I think you should then rather say that everybody that locks their houses when they go away are criminals. Using encryption is the same as locking one's house, i.e. an attempt to keep the criminals out, rather than as sign of being a criminal oneself.

P.S. I agree with you about guns.
 
Moederloos said:
With the proposed monitoring, the inspection will be done at the ISP - so there is no reason the traffic coming from the line cannot be "split". One portion sent on, and the other inspected.
Any gurus out there that can comment on the feasibility of this?

I know little of the hardware side, but from a pure IP perspective, it should be dead easy to identify packets from a certain source or destination address and keep a copy of them. I do it sometimes to debug programs.
 
gkm said:
I think you should then rather say that everybody that locks their houses when they go away are criminals. Using encryption is the same as locking one's house, i.e. an attempt to keep the criminals out, rather than as sign of being a criminal oneself.

Almost true... but the cops have battering rams to beat in the door if you wont open....data security is almost 99.999% uncrackable (if locked correctly) no matter what brute force they apply
 
RichardP said:
Almost true... but the cops have battering rams to beat in the door if you wont open....data security is almost 99.999% uncrackable (if locked correctly) no matter what brute force they apply

So, what do you suggest?
 
Securely Encrypt all your IM Communication

I would suggest government not treating *everyone* as a potential Criminal.

You can download simplite for MSN, Yahoo Messenger, Google Talk etc from here Secway Security
if you and your buddy both have it installed coms are 100% secure & encrypted.;)
 
Last edited:
*G* If ISPs are gonna store all data on their side which you're downloading on your side - imagine the size of the porn collection they'll build up over time :D
 
Dovi said:
*G* If ISPs are gonna store all data on their side which you're downloading on your side - imagine the size of the porn collection they'll build up over time :D

It is all part of the government's policy to encourage local content. I think 99% of international traffic into SA is porn. Imagine the international dark cable if all of this is available locally ... heh heh
 
The cryptography provision covers only providers, not users. The government appears to believe that such providers would have copies of users' private keys, or could provide assistance in decoding an encrypted message.

I suspect that those involved in drafting this law know nothing about cryptography. Only a lunatic would give the software provider a copy of their private key.

They also probably haven't considered something like gpg - how are they going to go after them for 'allowing' their product to be distributed in South Africa.

The law appears to try to hold producers of cryptography products liable, but the drafters seem to be blissfully unaware that buying cryptography products does not require them to be directly distributed in South Africa. Criminals need not even pay for their software. If they're true professionals they'll only use products where they have access to the source code and employ experts to comb through that code.

It comes down to a double edged sword - how do we protect the rights of individuals (both of privacy and safety) by not restricting some of those rights (or - how can we catch the bad guys, without infringeing on the good guy's right to privacy).

As we all know criminals would never resort to breaking a law prohibiting the use of encryption. When the police are honest they admit that decrypting a message seldom helps them much because criminals typically talk in code.

My feeling is that when it specifically comes to acts of terrorism, or the planning thereof, interception of private data & communications is useful in protecting the safety of many individuals that would otherwise fall victim to such an act of terrorism.

Then you're in favour of a police state. Governments will conveniently attach claims of imminent terrorism any time they wish to spy. The criteria for what is considered terrorism will be lowered until it allows spying on anyone, any time. This is the trend overseas.

Terrorism isn't new. It hasn't changed. It just happens to have turned out to be a very convenient excuse for increasing government power and intrusion. People are more than happy to sell freedom for the delusion of safety. Governments are gleefully seizing the opportunity to reduce freedom.

Someone with a gun (other than a law-enforcment officer) is automatically a criminal, and is arrested = safer

No, less safe. Criminals, strangely, don't walk down the street waving their gun about so they can get arrested. They have this odd tendency to attack people in the dark, in alleys, behind close doors. This country is already headed down the ridiculous road of the UK, where it is essentially illegal to protect yourself against a piece of scum that tries to rob you. It is every person's right to protect themselves when attacked. If someone tries to mug you or enters your home with intent to commit a crime you can and should employ any means necessary to deal with them. If they are maimed or killed that is just tough luck.

However the law does not make owning or using cryptography products or guns illegal.

The other favoured excuse for spying is stopping the drug trade. Governments talk big on this subject, but they have no chance of ever winning (short of a completely locked-down police state). The abject failure of the drug laws shows us that this activity will adapt and continue. Drug smugglers will continue laughing in the face of law enforcement.

Finally since this spying technology is allegedly for the good of all South Africans the cost should be carried by all South Africans, not just ISP users, therefore the government should pay the full cost of data interception and retrieval. Meanwhile good people will continue to work to make this equipment useless by giving us the means to make the data unreadable.
 
Top
Sign up to the MyBroadband newsletter
X